Your Security Posture Is Now Part of Your Product
Enterprise buyers audit your development process before they sign, and from September 2026 the Cyber Resilience Act adds an obligation of its own. Whitespots gives you the reports to pass those reviews — and removes one sub-processor from every DPA you send.
Security reviews that close
The questions that stall enterprise deals are about process and sub-processors. Both get shorter when the scanner runs on your own infrastructure.
Dependencies checked on every commit
Dependency scanning is on by default and runs outside your CI/CD pipelines, so known vulnerabilities surface without slowing builds.
Flat cost as headcount grows
When every developer adds to the bill, coverage becomes a budget decision. Flat, per-organisation pricing lets you cover everything.
One fewer name in your DPA
A SaaS scanner is a sub-processor your customers must approve. Self-hosted removes the row entirely.
What Software Companies Run Into
Growth changes the security problem twice: first from "we should scan" to "we cannot read the results", then from an engineering concern to a revenue one.
The deal is blocked on a questionnaire
A single unanswerable question about where code is processed or who your fourth parties are can hold a contract for a quarter.
Microservices outpace the security team
Services multiply faster than headcount. A central triage queue stops working somewhere around the fiftieth repository.
Developers ignore a second console
Findings that live in a dashboard nobody opens are findings that do not get fixed, whatever the dashboard reports.
New obligations on the calendar
Selling software into the EU now carries reporting duties on a fixed date, and reporting depends on records you either kept or did not.
What the Frameworks Actually Require
The obligations and expectations that reach a software vendor's development process.
Article 14 · reporting obligations
From 11 September 2026, manufacturers report actively exploited vulnerabilities and severe incidents affecting product security to the relevant CSIRT and ENISA, within short deadlines.
How Whitespots helps
Every change is scanned, and each finding records when it first appeared and when it was fixed, so a report can go out inside the window instead of after it.
Annex I · vulnerability handling requirements
From 11 December 2027: identify and document components including a software bill of materials, address vulnerabilities without delay, apply regular tests, and publicly disclose fixed vulnerabilities. Penalties apply from the same date.
How Whitespots helps
Every commit tested, dependencies scanned, and a remediation record kept per finding.
Digital providers · risk-management measures
Where a cloud or managed service provider is in scope, measures must include vulnerability handling and disclosure, secure development, and supply-chain security.
How Whitespots helps
Every change scanned, with automatic validation and deduplication, quality gates in development and dependency coverage for the supply chain. Notifications and SLAs keep response on schedule.
SSDF · SP 800-218
Secure software development practices that federal agencies can reference when validating supplier security: protect the software, produce well-secured software, and respond to vulnerabilities.
How Whitespots helps
Practice-level evidence — what was scanned, what was found, what was fixed and when — rather than an attestation with nothing behind it.
Annex A, as listed in BSI's mapping table
Management of technical vulnerabilities, secure development lifecycle, secure coding, and security testing in development and acceptance.
How Whitespots helps
Each control has a corresponding artefact in the platform, which is what an auditor samples rather than the policy text.
Change management and vendor management
Evidence that code changes are reviewed and tested before release, and a maintained list of sub-processors with access to customer data.
How Whitespots helps
Quality gates stop pull requests with findings before they merge, and process reports show that every change was checked. Self-hosting keeps the platform off your sub-processor list.
References reflect published text as of August 2026 and describe obligations rather than a certification we grant. CRA dates are as published: reporting obligations from 11 September 2026, remaining obligations and penalties from 11 December 2027. Scope depends on whether your product is a product with digital elements placed on the EU market — confirm with counsel.
What Whitespots Gives a Software Company
Aimed at the two costs that actually bite: deals that stall on security review, and a queue that grows faster than the team.
One fewer sub-processor in every enterprise deal
-
Shorter security reviews No sub-processor to name in a customer DPA.
-
Zero outbound data No code, findings, logs or usage data leave your servers.
-
Leave whenever you want Exit is a database export, not a vendor negotiation.
One record answers the questionnaire, the ISO audit and the CRA
-
Every decision traceable Per-finding trail: scanner, first seen, severity, decision, owner.
-
Vulnerable code blocked before merge Quality gates on pull requests.
-
Reports for every audience Exportable for customers, auditors and authorities.
The backlog becomes the teams' work, not the security team's
-
Right owner, automatically Mapped to repository and service owners.
-
One flaw is one finding Deduplicated, with false positives suppressed for good.
-
Deadlines you can prove you met SLAs per severity for verification, assignment and resolution.
Findings get fixed in the editor, not counted on a dashboard
-
Developers see the issue on the exact line Findings in the IDE, with remediation guidance.
-
Caught in the pull request Checks run as code is written, not in a pre-release scramble.
-
No pipeline rewrite Onboarding through a VCS webhook.
Where It Lands
What a software company's security function is usually asked to produce.
- Scenario
An enterprise prospect sends a security review
With Whitespots platformSub-processor and data-location sections answered in one line each.
- Scenario
A customer asks for a software bill of materials
With Whitespots platformGenerated by the platform, while dependency scans show which components have known vulnerabilities.
- Scenario
An exploited vulnerability triggers a reporting duty
With Whitespots platformWhere the issue is, when it was first found and whether it is fixed — available immediately.
- Scenario
Engineering doubles in a year
With Whitespots platformCost stays flat and ownership routes to teams rather than to a central queue.
What SaaS & Technology Teams Ask First
We are a SaaS company. Why would we self-host our security tooling?
Because your customers audit your supply chain. Every SaaS tool with access to your source code is a fourth party to them, and one they can object to. Self-hosting removes the row from the DPA and the question from the review, which is a sales outcome rather than a security one.
What exactly changes on 11 September 2026?
The Cyber Resilience Act's reporting obligations start: manufacturers of products with digital elements report actively exploited vulnerabilities and severe incidents within short deadlines. The remaining obligations, including the Annex I vulnerability-handling requirements, and the penalty regime apply from 11 December 2027. Confirm your product's scope with counsel.
Does the platform produce an SBOM we can hand to a customer?
Yes. The platform can generate an SBOM whenever you need one. It also scans dependencies on every commit and tracks the vulnerabilities found in them.
How does this compare to the SaaS scanners we already evaluated?
Most SaaS scanners have equivalents, commercial or open source, and the platform can run them. You keep the detection you need, while your code and findings stay inside your infrastructure at a flat price. Feature-by-feature comparisons with the usual alternatives are on the comparison pages.
Our team is small and our repo count is not. Is this too much to run?
Onboarding is a VCS webhook per organisation, with no agents and no pipeline changes. Built-in validation and deduplication rules triage standard cases automatically, so the team only reviews what is specific to your code.
Stop Losing Quarters to Security Questionnaires
Start with a free external scan of your product's public surface, or talk to us about a self-hosted deployment before the next enterprise review.