Industry SaaS, software vendors & platforms

Your Security Posture Is Now Part of Your Product

Enterprise buyers audit your development process before they sign, and from September 2026 the Cyber Resilience Act adds an obligation of its own. Whitespots gives you the reports to pass those reviews — and removes one sub-processor from every DPA you send.

Security reviews that close

The questions that stall enterprise deals are about process and sub-processors. Both get shorter when the scanner runs on your own infrastructure.

Dependencies checked on every commit

Dependency scanning is on by default and runs outside your CI/CD pipelines, so known vulnerabilities surface without slowing builds.

Flat cost as headcount grows

When every developer adds to the bill, coverage becomes a budget decision. Flat, per-organisation pricing lets you cover everything.

One fewer name in your DPA

A SaaS scanner is a sub-processor your customers must approve. Self-hosted removes the row entirely.

Key challenges

What Software Companies Run Into

Growth changes the security problem twice: first from "we should scan" to "we cannot read the results", then from an engineering concern to a revenue one.

The deal is blocked on a questionnaire

A single unanswerable question about where code is processed or who your fourth parties are can hold a contract for a quarter.

Microservices outpace the security team

Services multiply faster than headcount. A central triage queue stops working somewhere around the fiftieth repository.

Developers ignore a second console

Findings that live in a dashboard nobody opens are findings that do not get fixed, whatever the dashboard reports.

New obligations on the calendar

Selling software into the EU now carries reporting duties on a fixed date, and reporting depends on records you either kept or did not.

Clause map

What the Frameworks Actually Require

The obligations and expectations that reach a software vendor's development process.

Cyber Resilience Act European Union

Article 14 · reporting obligations

From 11 September 2026, manufacturers report actively exploited vulnerabilities and severe incidents affecting product security to the relevant CSIRT and ENISA, within short deadlines.

How Whitespots helps

Every change is scanned, and each finding records when it first appeared and when it was fixed, so a report can go out inside the window instead of after it.

Cyber Resilience Act European Union

Annex I · vulnerability handling requirements

From 11 December 2027: identify and document components including a software bill of materials, address vulnerabilities without delay, apply regular tests, and publicly disclose fixed vulnerabilities. Penalties apply from the same date.

How Whitespots helps

Every commit tested, dependencies scanned, and a remediation record kept per finding.

NIS2 European Union

Digital providers · risk-management measures

Where a cloud or managed service provider is in scope, measures must include vulnerability handling and disclosure, secure development, and supply-chain security.

How Whitespots helps

Every change scanned, with automatic validation and deduplication, quality gates in development and dependency coverage for the supply chain. Notifications and SLAs keep response on schedule.

NIST United States

SSDF · SP 800-218

Secure software development practices that federal agencies can reference when validating supplier security: protect the software, produce well-secured software, and respond to vulnerabilities.

How Whitespots helps

Practice-level evidence — what was scanned, what was found, what was fixed and when — rather than an attestation with nothing behind it.

ISO/IEC 27001:2022 International

Annex A, as listed in BSI's mapping table

Management of technical vulnerabilities, secure development lifecycle, secure coding, and security testing in development and acceptance.

How Whitespots helps

Each control has a corresponding artefact in the platform, which is what an auditor samples rather than the policy text.

SOC 2 · enterprise reviews Customer contracts

Change management and vendor management

Evidence that code changes are reviewed and tested before release, and a maintained list of sub-processors with access to customer data.

How Whitespots helps

Quality gates stop pull requests with findings before they merge, and process reports show that every change was checked. Self-hosting keeps the platform off your sub-processor list.

References reflect published text as of August 2026 and describe obligations rather than a certification we grant. CRA dates are as published: reporting obligations from 11 September 2026, remaining obligations and penalties from 11 December 2027. Scope depends on whether your product is a product with digital elements placed on the EU market — confirm with counsel.

Platform

What Whitespots Gives a Software Company

Aimed at the two costs that actually bite: deals that stall on security review, and a queue that grows faster than the team.

Self-hosted 01

One fewer sub-processor in every enterprise deal

  • Shorter security reviews No sub-processor to name in a customer DPA.

  • Zero outbound data No code, findings, logs or usage data leave your servers.

  • Leave whenever you want Exit is a database export, not a vendor negotiation.

See deployment options →
Buyer evidence 02

One record answers the questionnaire, the ISO audit and the CRA

  • Every decision traceable Per-finding trail: scanner, first seen, severity, decision, owner.

  • Vulnerable code blocked before merge Quality gates on pull requests.

  • Reports for every audience Exportable for customers, auditors and authorities.

How it works →
Ownership 03

The backlog becomes the teams' work, not the security team's

  • Right owner, automatically Mapped to repository and service owners.

  • One flaw is one finding Deduplicated, with false positives suppressed for good.

  • Deadlines you can prove you met SLAs per severity for verification, assignment and resolution.

Explore the platform →
Developer workflow 04

Findings get fixed in the editor, not counted on a dashboard

  • Developers see the issue on the exact line Findings in the IDE, with remediation guidance.

  • Caught in the pull request Checks run as code is written, not in a pre-release scramble.

  • No pipeline rewrite Onboarding through a VCS webhook.

See the IDE integration →
Outcomes

Where It Lands

What a software company's security function is usually asked to produce.

  • Scenario

    An enterprise prospect sends a security review

    With Whitespots platform

    Sub-processor and data-location sections answered in one line each.

  • Scenario

    A customer asks for a software bill of materials

    With Whitespots platform

    Generated by the platform, while dependency scans show which components have known vulnerabilities.

  • Scenario

    An exploited vulnerability triggers a reporting duty

    With Whitespots platform

    Where the issue is, when it was first found and whether it is fixed — available immediately.

  • Scenario

    Engineering doubles in a year

    With Whitespots platform

    Cost stays flat and ownership routes to teams rather than to a central queue.

FAQ

What SaaS & Technology Teams Ask First

We are a SaaS company. Why would we self-host our security tooling?

Because your customers audit your supply chain. Every SaaS tool with access to your source code is a fourth party to them, and one they can object to. Self-hosting removes the row from the DPA and the question from the review, which is a sales outcome rather than a security one.

What exactly changes on 11 September 2026?

The Cyber Resilience Act's reporting obligations start: manufacturers of products with digital elements report actively exploited vulnerabilities and severe incidents within short deadlines. The remaining obligations, including the Annex I vulnerability-handling requirements, and the penalty regime apply from 11 December 2027. Confirm your product's scope with counsel.

Does the platform produce an SBOM we can hand to a customer?

Yes. The platform can generate an SBOM whenever you need one. It also scans dependencies on every commit and tracks the vulnerabilities found in them.

How does this compare to the SaaS scanners we already evaluated?

Most SaaS scanners have equivalents, commercial or open source, and the platform can run them. You keep the detection you need, while your code and findings stay inside your infrastructure at a flat price. Feature-by-feature comparisons with the usual alternatives are on the comparison pages.

Our team is small and our repo count is not. Is this too much to run?

Onboarding is a VCS webhook per organisation, with no agents and no pipeline changes. Built-in validation and deduplication rules triage standard cases automatically, so the team only reviews what is specific to your code.

Stop Losing Quarters to Security Questionnaires

Start with a free external scan of your product's public surface, or talk to us about a self-hosted deployment before the next enterprise review.