DerScanner
DerScanner (DerSecur) provides a unified application security testing platform combining SAST, DAST, SCA, and MAST with on-premise AI triage and code fix capabilities. It serves security and development teams across 53+ countries, supporting 43 programming languages including legacy stacks.
- Company typePrivate
- Founded2011
- HeadquartersHaifa, Israel
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What DerScanner does
DerScanner (legal entity DerSecur) is an Israel-based application security testing company founded in 2011 that provides a unified platform combining Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and Mobile Application Security Testing (MAST). The company serves security teams, development teams, and DevSecOps teams across enterprise and regulated industries including defense, finance, healthcare, and government. Operating in over 53 countries with a team of 70+ researchers and analysts, DerScanner distinguishes itself through support for 43 programming languages including rare legacy stacks such as Delphi, COBOL, ABAP, Perl, PL/SQL, and Scala.
The platform's core technology integrates four scanning modalities with proprietary AI agents (DerTriage and DerCodeFix) that run fully on-premise including in air-gapped environments. DerTriage evaluates exploitability and impact of SAST findings to suppress false positives by up to 90%, while DerCodeFix generates context-aware code fix suggestions preserving business logic and coding style. The platform supports binary analysis for compiled applications without source code access, generates Software Bills of Materials (SBOMs) in CycloneDX format across 12+ language ecosystems, and includes a proprietary package health scoring system built on 8 security metrics. The company holds MITRE CWE-compatibility certification, is recommended by NIST, and maps findings to PCI DSS, HIPAA, ISO 27001, GDPR, EU CRA, NIS2, DORA, and SOC 2 Type II standards. Native integrations cover major CI/CD platforms (Jenkins, GitHub Actions, GitLab CI, Azure DevOps, TeamCity) and IDEs (VS Code, JetBrains, IntelliJ, Eclipse, Visual Studio).
DerScanner monetizes through annual or multi-year subscription licenses for its platform, with modular pricing for SAST, DAST, SCA, MAST, and binary analysis as base tiers, plus optional AI add-ons (DerTriage and DerCodeFix). Professional services cover on-premises deployment assistance and implementation support. Licensing starts from a few hundred dollars and is customized through a survey-based process that scopes to languages, team size, and required scope. Distribution combines direct enterprise field sales with a global channel partner network including Athena Dynamics (Singapore), Moonsoft (Finland), ATSOL (Azerbaijan), Better Now (Brazil), and Garini Technologies Corporation (Malaysia), supplemented by a flagship technology partnership with Embarcadero Technologies for Delphi security. The company has reported 98% customer retention and 2 trillion+ lines of code scanned cumulatively across customer deployments.
DerScanner firmographics
Firmographics- Name
- DerScanner
- Legal name
- DerSecur
- Website
- https://www.derscanner.com
- Company type
- Private
- Founded year
- 2011
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- DerScanner (DerSecur) provides a unified application security testing platform combining SAST, DAST, SCA, and MAST with on-premise AI triage and code fix capabilities. It serves security and development teams across 53+ countries, supporting 43 programming languages including legacy stacks.
- Ownership category
- akta.pro rank
DerScanner industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industry
- Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
Keywords
Where DerScanner is headquartered
LocationHeadquarters
- HQ city
- Haifa
- HQ country
- Israel
- HQ region
- Middle East
Offices2 records
Markets served
DerScanner business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Others
Revenue model
- Software License Subscriptions: Annual or multi-year subscription licenses for DerScanner platform. Licensing is scoped to customer needs based on languages, teams, and scope. Licensing starts from a few hundred dollars and is customized through a survey-based process.
- Optional AI Add-ons: DerTriage and DerCodeFix AI modules are optional add-ons to the base license, allowing customers to customize their subscription based on desired features.
- Professional Services: On-premises deployment assistance and implementation support provided by DerScanner team.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Custom enterprise license with flexible scoping |
| Subscription | Annual | Static Application Security Testing (SAST) - Base |
| Subscription | Annual | Dynamic Application Security Testing (DAST) - Base |
| Subscription | Annual | Software Composition Analysis (SCA) - Base |
| Subscription | Annual | SDLC Integrations - Base |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels8 records
DerScanner product offering
Product offeringCore offering
DerScanner sells a full-cycle application security testing platform that combines SAST, DAST, SCA, and MAST in a single product to scan source code, binaries, web applications, APIs, mobile apps, and open-source dependencies. It includes on-premise AI agents (DerTriage and DerCodeFix) that suppress false positives by up to 90% and generate context-aware code fix suggestions, supports 43 programming languages including rare legacy stacks (Delphi, COBOL, ABAP, Perl), and can be deployed on-premise, in the cloud, or in fully air-gapped environments. The platform also generates CycloneDX SBOMs, scores open-source package health, and maps findings to OWASP, CWE, PCI DSS, HIPAA, GDPR, EU CRA, NIS2, and DORA for audit-ready reporting.
Product overview
DerScanner is a full-cycle application security testing platform that unifies SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), SCA (Software Composition Analysis), and MAST (Mobile Application Security Testing) in one integrated platform. The core platform is complemented by AI-powered modules including DerTriage (AI triage assistant) and DerCodeFix (AI code fix generator) which run fully on-premise to reduce false positives by up to 90%. A dedicated Delphi Security module provides specialized SAST, SCA, SBOM, and Code Quality analysis for Delphi and Object Pascal applications, built in partnership with Embarcadero Technologies. The platform supports 43 programming languages including legacy stacks (Delphi, COBOL, ABAP, Perl, PL/SQL, Scala), offers binary analysis for compiled code without source access, and generates audit-ready compliance reports mapped to OWASP, CWE, PCI DSS, HIPAA, and GDPR. All components integrate into CI/CD pipelines via native plugins for Jenkins, GitHub Actions, GitLab CI, Azure DevOps, and TeamCity, as well as IDE plugins for VS Code, JetBrains, IntelliJ IDEA, Eclipse, and Visual Studio.
Differentiator
Problem solved
Functional benefit
Products and services
- Static Application Security Testing (SAST) Static analysis of source code and binaries across 43 programming languages including legacy stacks (Delphi, COBOL, ABAP, Perl, PL/SQL, Scala). Detects injection flaws, hardcoded credentials, insecure patterns, and code quality issues before compilation. Available as a standalone product or bundled within the DerScanner Platform.
- Dynamic Application Security Testing (DAST) Black-box dynamic testing of running web applications and REST APIs. Simulates real attacks using standard, aggressive, and active attack modes with AJAX spider to find authentication flaws, injections, and misconfigurations at runtime without requiring source code access. Findings correlate with SAST through IAST.
- Software Composition Analysis (SCA) Software composition analysis for open-source dependencies. Identifies open-source components, detects CVEs and license risks, generates SBOMs in CycloneDX format, and produces a proprietary package health score. Combines with SAST via hybrid reachability analysis to confirm CVE exploitability and detect supply chain threats including typosquatting, MavenGate, and starjacking.
- Mobile Application Security Testing (MAST) Security testing for Android and iOS applications covering Java, Kotlin, Swift, Objective-C, Scala, and Dart source code as well as compiled APK and IPA binaries. Detects insecure storage, improper permissions, and other vulnerabilities, with findings mapped to OWASP Mobile Top 10 and OWASP MASVS.
- Binary Analysis Security scanning of compiled applications and third-party libraries without source code access. Supports JAR/WAR/EAR/AAR for Java, Scala, and Kotlin ecosystems and EXE/DLL for Windows C/C++ applications, as well as APK and IPA binaries. Enables scanning of legacy and third-party components where source is unavailable.
- On-premise Agentic AI (DerTriage and DerCodeFix) Two on-premise AI agents sold together as the Agentic AI add-on. DerTriage is an AI triage assistant that evaluates exploitability and impact of SAST findings to suppress false positives by up to 90%. DerCodeFix is an AI code-fix generator that produces context-aware remediation suggestions aligned to the language, framework, and exact code location. Both operate fully offline including in air-gapped environments with no external API calls and no training-data exposure.
- Delphi Security Specialized SAST, SCA, SBOM generation, and Code Quality analysis built specifically for Delphi and Object Pascal applications, delivered through a technology partnership with Embarcadero Technologies. Includes full support for Delphi 13 and earlier versions and is regularly featured in Embarcadero webinars, blog posts, and recommended resources.
Quantifiable outcome
- False positive reduction of up to 90% through AI-powered triage (DerTriage)
- +4 more outcomes
Companies that use DerScanner
Customer profileNamed customers3 records
Segments6 records
Ideal customer profiles3 records
DerScanner technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration15 records
AI capability6 records
Feature10 records
DerScanner partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core, flagship and foundational.
- Garini Technologies CorporationcorePartnership for CYDES 2025 cybersecurity exhibition in Malaysia. Showcased DerScanner's AI-driven application security platform at Malaysia's premier cybersecurity event attended by 8,000 trade visitors from 27 countries.
- Embarcadero TechnologiesflagshipOfficial Technology Partner of Embarcadero Technologies. DerScanner is built specifically for Delphi and Object Pascal security testing with early access to RAD Studio releases. Products include SAST, SCA, SBOM, and Code Quality analysis for Delphi. Solutions are regularly featured in Embarcadero webinars, blog posts, and recommended resources.
- Athena DynamicscorePartner in Singapore. CEO Ken Soh states that partnering with DerScanner has revolutionized their business with consistent client engagement leading to regular renewals and new feature opportunities, stabilizing revenue and deepening client relationships.
- MoonsoftcorePartner in Finland. CEO Juha Piispa used DerScanner to scan Delphi legacy code with fast, user-friendly, and effective results exceeding expectations even with challenging older codebases.
- ATSOLcorePartner in Azerbaijan. CEO Alexander Tvaradze reports that DerScanner's ability to support 36 languages with strong static and binary analysis makes it the go-to solution for clients wanting to double-check their security.
- Better NowcorePartner in Brazil focused on reliability engineering for critical digital operations. CTO Raphael Milani reports that integrating DerScanner catches and fixes vulnerabilities early across the SDLC, giving clients predictability over what reaches production.
- Research Institute for Fundamental and Applied Computer SciencefoundationalCode analysis technologies were originally developed at this research institute and are now used worldwide through DerScanner commercial product.
Scale indicators6 records
Recent moves7 records
Expansion highlights6 records
DerScanner competitors and assessment
Company assessmentDirect peers
- Checkmarx: Established enterprise AppSec platform offering SAST, DAST, SCA, and API security; directly competes with DerScanner in the same enterprise procurement cycles and was positioned alongside it in the Forrester SAST Landscape.
- Veracode: Broadcom-owned AppSec platform combining SAST, DAST, and SCA with strong enterprise and regulated-industry presence; competes head-to-head with DerScanner's unified platform approach and Forrester-recognized SCA/SAST capabilities.
- Snyk: Developer-first security platform spanning SAST, SCA, container, and IaC scanning; competes with DerScanner for security and DevSecOps team budgets, especially in SCA and CI/CD-integrated use cases.
- Sonar (SonarSource): Code quality and security platform (SonarQube/SonarCloud) covering static analysis across many languages; overlaps with DerScanner's SAST and Code Quality Analysis offerings for developer teams.
- Semgrep: Developer-focused SAST platform with code, supply chain, and secrets scanning; competes in the same modern CI/CD-integrated AppSec category where DerScanner pitches shift-left security.
- Invicti (Netsparker): DAST-first AppSec platform with SAST and SCA extensions; directly comparable to DerScanner's DAST capability, especially for web application and API dynamic testing.
- Mend (formerly WhiteSource): SCA-focused vendor covering open-source vulnerability, license, and SBOM management; closely comparable to DerScanner's SCA product, including package health scoring and SBOM generation.
- Contrast Security: IAST and runtime AppSec platform with SAST/SCA additions; overlaps with DerScanner's IAST correlation and runtime application protection angle for enterprise DevSecOps buyers.
Broad incumbents
- GitHub Advanced Security: Native AppSec offering inside GitHub covering Code Scanning (SAST), Dependabot (SCA), and secret scanning; competes as a bundled incumbent inside the dominant developer platform and pressures standalone AppSec vendors.
- OpenText Fortify: Enterprise-grade SAST and DAST platform from OpenText with broad language coverage; competes with DerScanner in large regulated and on-premise AppSec deployments.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
DerScanner social profiles
Digital presenceDerScanner compliance and trust
Trust signalCompliance9 records
DerScanner financial estimates
Financial estimateRevenue estimate
Valuation estimate
DerScanner leadership team
Management profileNumber of profiles
Profiles2 records
DerScanner subsidiaries and ownership
Company hierarchySubsidiaries1 record
DerScanner funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
DerScanner M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about DerScanner
What does DerScanner do?
DerScanner sells a full-cycle application security testing platform that combines SAST, DAST, SCA, and MAST in a single product to scan source code, binaries, web applications, APIs, mobile apps, and open-source dependencies. It includes on-premise AI agents (DerTriage and DerCodeFix) that suppress false positives by up to 90% and generate context-aware code fix suggestions, supports 43 programming languages including rare legacy stacks (Delphi, COBOL, ABAP, Perl), and can be deployed on-premise, in the cloud, or in fully air-gapped environments. The platform also generates CycloneDX SBOMs, scores open-source package health, and maps findings to OWASP, CWE, PCI DSS, HIPAA, GDPR, EU CRA, NIS2, and DORA for audit-ready reporting.
Is DerScanner a public or private company?
DerScanner is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was DerScanner founded?
DerScanner was founded in 2011. It employs 11 to 50 people.
Where is DerScanner based?
DerScanner is headquartered in Haifa, Israel, in the Middle East region.
How does DerScanner make money?
Three revenue lines are on record. Software License Subscriptions are the primary driver. The others are optional AI Add-ons and professional Services.
Who are DerScanner's main competitors?
Direct peers on record are Checkmarx, Veracode, Snyk, Sonar (SonarSource), Semgrep, Invicti (Netsparker), Mend (formerly WhiteSource) and Contrast Security. Broad incumbents are GitHub Advanced Security and OpenText Fortify.
Does DerScanner have an API?
Yes. DerScanner provides a Command Line Interface (CLI) and Open API for integrations with repositories, VCS hostings, development environments, bug tracking, and CI/CD servers. Developer documentation is at docs.derscanner.com.
What industry is DerScanner in?
DerScanner's product category is Application Security Testing. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of HDADACAG, Code & Repository Security (Git Security, Code Integrity). Its NAICS code is 5415 and its SIC code is 7372.