Powered by VamiSec · LLM-native AppSec · Hosted in Germany

From commit to compliance, in one secure SDLC platform.

VamiAppSec runs your secure CI/CD development lifecycle end-to-end — SAST, SCA, SBOM, dependency, secrets and LLM-powered DAST — tracks every finding in the integrated DefectDojo or your own ticket system, and maps it to OWASP standards and to product-security regulations such as CRA, MDR, RED, IEC 62443, UNECE R155 and ISO/SAE 21434. Powered by our local Qwen3.8 LLM, hosted in VamiSec's own data centers in Germany.

7scan types, one pipeline
OWASPASVS · ISVS · MASVS · AISVS
CI/CDGitLab · GitHub · Azure DevOps
Qwen3.8own data centers · Germany
Scanners orchestrated natively
Semgrep Gitleaks Checkov Syft Grype Trivy ZAP by Checkmarx Nuclei VamiDAST
Findings tracked in DefectDojo — or Jira, Azure Boards, ServiceNow
02 · Compliance

Product-security requirements, mapped to your pipeline.

CRA, MDR, RED, IEC 62443, UNECE R155 and ISO/SAE 21434 are examples — not an exhaustive list. They all ask for the same thing in different words: a secure development lifecycle, a complete bill of materials and vulnerability handling you can prove. VamiAppSec turns every pipeline run into that evidence — for these and any comparable regime.

Examples — the list is not exhaustive

EU · Regulation (EU) 2024/2847

Cyber Resilience Act (CRA)

Annex I sets essential requirements: secure-by-design properties (Part I) and vulnerability handling (Part II) — SBOM, coordinated disclosure, timely security updates. Since 11 Sep 2026, actively exploited vulnerabilities must be reported to ENISA and the CSIRT (Art. 14); full application on 11 Dec 2027.

What VamiAppSec delivers
SBOM per release (CycloneDX / SPDX) Actively-exploited-vulnerability watch VEX / VDR exports 24 h / 72 h / 14-day report drafts
EU · Regulation (EU) 2017/745

Medical Device Regulation (MDR)

GSPR 17.2 demands software developed to the state of the art: lifecycle, risk management, information security, verification and validation. Notified bodies expect SOUP/SBOM inventories, vulnerability monitoring and traceable evidence (MDCG 2019-16, IEC 81001-5-1).

What VamiAppSec delivers
SOUP / SBOM inventory Lifecycle evidence per release Continuous CVE watch on released SBOMs Post-market vulnerability trail
EU · Directive 2014/53/EU · DR (EU) 2022/30

Radio Equipment Directive (RED)

Since 1 Aug 2025, connected radio equipment must protect the network (Art. 3(3)(d)), personal data (e) and against fraud (f). EN 18031-1/-2/-3 are the harmonised route — and expect secure update mechanisms, no default credentials and protected secrets.

What VamiAppSec delivers
Secrets scanning — no hard-coded credentials Update-mechanism & crypto review SBOM for connected devices Evidence for EN 18031 documentation
IEC · 62443-4-1 & 62443-4-2

IEC 62443 secure product lifecycle

62443-4-1 defines eight practices for a secure development lifecycle — from security management (SM) to security update management (SUM). 62443-4-2 adds technical component requirements at security levels 1–4.

What VamiAppSec delivers
SVV — verification & validation testing DM — defect management in DefectDojo SUM — patch & update evidence SI — secure implementation checks
UNECE · UN Regulation No. 155 (& 156)

UNECE R155 CSMS

Vehicle type approval requires a certified Cyber Security Management System across development, production and post-production — with threat mitigation per Annex 5. R156 adds a Software Update Management System.

What VamiAppSec delivers
CSMS evidence trail per release Annex 5 threat & mitigation mapping Post-production vulnerability monitoring R156 software-update evidence
ISO/SAE · 21434:2021

ISO/SAE 21434 cybersecurity engineering

The road-vehicle engineering standard behind R155: TARA, cybersecurity concept, product development, verification & validation, continual vulnerability management and distributed (supplier) activities.

What VamiAppSec delivers
Findings linked to TARA assets V&V evidence for cybersecurity cases Continual vulnerability management Supplier SBOM transparency
…and more

The same evidence serves every framework that asks for a secure SDLC, an SBOM and vulnerability handling.

NIS2 DORA EU AI Act · Art. 15 ISO/IEC 27001 SOC 2 IEC 81001-5-1 EN 18031 ETSI EN 303 645 BSI TR-03183 FDA § 524B GB 44495 OWASP SAMM

VamiAppSec doesn't certify your product — your notified body, technical service or auditor does. It gives them what they ask for: machine-generated, per-release evidence — SBOMs, scan results, gate decisions and vulnerability-handling records.

03 · SBOM & CRA reporting

Know what you ship. Know when it's exploited.

Since 11 September 2026, CRA Article 14 obliges manufacturers to report actively exploited vulnerabilities in their products — including products already on the market. You can only report what you can see: VamiAppSec generates an SBOM for every release and watches every shipped component for active exploitation, around the clock.

01

Generate an SBOM for every release

Syft builds CycloneDX and SPDX SBOMs in the pipeline — direct and transitive dependencies, versioned and stored with every release you ship.

SyftCycloneDXSPDX
02

Monitor for active exploitation

Every released SBOM is matched continuously against NVD, OSV and GitHub advisories — and against exploitation signals from CISA KEV and ENISA's EU Vulnerability Database (EUVD), prioritised with EPSS.

CISA KEVENISA EUVDNVDOSVGitHub AdvisoriesEPSS
03

Assess reachability & draft VEX

Qwen3.8 checks whether the vulnerable code path is reachable in your product and drafts the VEX status — affected, not affected, fixed or under investigation. Your PSIRT decides.

Qwen3.8DefectDojo
04

Start the reporting clock

When a shipped component is actively exploited, VamiAppSec starts the Art. 14 clock and pre-fills early warning, notification and final report — ready for submission via ENISA's Single Reporting Platform.

CRA Art. 14 · reporting clock for actively exploited vulnerabilities
24 hEarly warning
72 hVulnerability notification
14 dFinal report, once a fix or mitigation is available

Deadlines run from the moment you become aware. Reports go simultaneously to the coordinating CSIRT and ENISA via the Single Reporting Platform.

04 · Secure SDLC

Every stage of your CI/CD, secured.

One pipeline, six stages, seven scan types. VamiAppSec plugs into the CI/CD you already run — GitLab, GitHub or Azure DevOps — and puts a gate wherever a regulation expects one.

01 Plan

Requirements & policy

  • OWASP ASVS / ISVS / MASVS requirements
  • Policy-as-code gates
  • Threat-model inputs
OWASP
02 Code

Shift left

  • SAST — Semgrep + LLM review
  • Secrets scanning — Gitleaks
  • Pre-commit hooks & IDE SARIF
SemgrepGitleaks
03 Build

Supply chain

  • SCA & dependency scanning — Grype / Trivy
  • SBOM — Syft (CycloneDX / SPDX)
  • IaC & container — Checkov / Trivy
SyftGrypeTrivyCheckov
04 Test

Runtime

  • LLM-DAST — VamiDAST on Qwen3.8
  • DAST — ZAP
  • API testing — Nuclei
VamiDASTZAP by CheckmarxNuclei
05 Release

Quality gate

  • Block on critical / soft-fail on regressions
  • Signed SBOM, VEX & VDR per release
  • Per-release evidence bundle
CycloneDXSPDX
06 Operate

Defect tracking

  • DefectDojo — tracking, not scanning
  • Sync to Jira · Azure Boards · ServiceNow
  • Exploited-vulnerability watch on released SBOMs
DefectDojoJiraAzure BoardsServiceNow
Gates where regulations expect them · PR gate for SAST and secrets · build gate for SCA and SBOM completeness · test gate for exploitable DAST findings · release gate for policy, VEX and evidence.

Runs where your code lives — tracks where your team works.

Source control & CI/CD

GitLab

CI/CD templates, MR approvals, security-dashboard feed.

GitHub

Actions workflow, PR checks, SARIF code scanning.

Azure DevOps

Pipelines task, PR policies, Repos integration.

BitbucketJenkinsGiteaForgejo+ SARIF · CycloneDX / SPDX · REST API
Defect tracking & ticket systems
Built in

DefectDojo

The system of record for every finding — not a scanner. Engagements per product, SLAs, deduplication, risk acceptance and a full audit trail.

Integration

Jira

Findings pushed as Jira issues to the owning team — status and resolution kept in sync with DefectDojo.

Integration

Azure DevOps Boards

Findings become work items next to your backlog — linked to the PR and the pipeline run that found them.

Integration

ServiceNow

Findings routed into ServiceNow — e.g. Vulnerability Response or ITSM tickets — for enterprise remediation workflows.

05 · OWASP standards

Every OWASP standard, built into the scan.

VamiAppSec maps every finding to OWASP verification standards and testing guides — so an assessment shows coverage per requirement and level, not just a list of bugs. Built for compliance-oriented assessments that auditors, notified bodies and customers recognise.

ASVS
Application Security Verification Standard

SAST, DAST and review findings mapped to ASVS 5.0 requirements — with coverage per chapter and verification level L1–L3.

Web apps & APIsCRA Annex I · ISO 27001
ISVS
IoT Security Verification Standard

Requirements for connected devices — ecosystem, user-space apps, software platform, communication and hardware platform — as the checklist for firmware and device assessments.

IoT & embeddedRED / EN 18031 · IEC 62443-4-2
MASVS
Mobile Application Security Verification Standard

The OWASP MAS baseline for iOS and Android — storage, crypto, auth, network, platform, code, resilience and privacy — mapped from mobile static and dynamic tests.

Mobile appsMDR companion apps · CRA
MASTG
Mobile Application Security Testing Guide (formerly MSTG)

The test cases behind MASVS — every mobile finding references the MASTG test that verifies it, so assessors can reproduce it.

Mobile testingMASVS evidence
WSTG
Web Security Testing Guide

The methodology behind our dynamic tests — VamiDAST, ZAP and Nuclei results carry WSTG test IDs for traceable, repeatable web assessments.

Web testingASVS evidence · pentest reports
AISVS
Artificial Intelligence Security Verification Standard

Verification requirements for AI and LLM systems — model supply chain, prompt-injection defences, output handling and data protection — for teams shipping AI features.

AI & LLM systemsEU AI Act Art. 15 · CRA
Also covered: OWASP Top 10 · API Security Top 10 · Top 10 for LLM Applications · SCVS · SAMM · CycloneDX
06 · The platform

Every scan type your product needs, in one backlog.

SAST, SCA, SBOM, dependency, secrets and LLM-powered DAST — orchestrated, deduplicated, enriched by our local LLM and tracked in DefectDojo or the ticket system you already use.

— SAST

Static application security testing

Semgrep rules plus semantic review by our local Qwen3.8 for business-logic flaws — on every commit, with SARIF in the IDE and the PR, mapped to OWASP ASVS.

SemgrepQwen3.8
— SCA & dependency scanning

Know every dependency

Grype and Trivy match your direct and transitive dependencies against NVD, OSV, EPSS and KEV — with VEX statements so downstream consumers see what is actually affected.

GrypeTrivy
— SBOM & exploit watch

SBOM per release, watched 24/7

Syft generates CycloneDX and SPDX SBOMs at build time; every shipped SBOM is monitored for actively exploited vulnerabilities (CISA KEV, ENISA EUVD) — the trigger for CRA Art. 14 reporting.

SyftCycloneDXSPDX
— Secrets scanning

No credentials in Git

Gitleaks in pre-commit and CI catches API keys, tokens and certificates before they ship — with age, exposure and rotation guidance for every hit.

Gitleaks
— LLM-powered DAST

VamiDAST — dynamic testing with a local LLM

VamiDAST tests the running build from the outside, with Qwen3.8 planning test paths, generating payloads and separating real findings from noise — alongside ZAP and Nuclei, every result mapped to OWASP WSTG.

VamiDASTZAP by CheckmarxNuclei
— Defect tracking

DefectDojo built in — your tracker welcome

DefectDojo is the integrated system of record for every finding — not a scanner: engagements, SLAs, deduplication, risk acceptance. Findings sync to Jira, Azure DevOps Boards or ServiceNow.

DefectDojoJiraAzure BoardsServiceNow
— LLM enrichment · Qwen3.8 local

Context from our own LLM

Each finding gets a plain-language explanation, an exploitability assessment and a stack-aware fix — generated by Qwen3.8 in VamiSec's own data centers in Germany, never by a third-country API.

Qwen3.8
— DevSecOps

CI/CD & quality gates

Block merges on critical findings, soft-fail on regressions, attach SARIF to PRs. Native GitLab, GitHub and Azure DevOps — plus Bitbucket and Jenkins.

GitLabGitHubAzure DevOps
— Reporting & evidence

Reports for every audience

Developer fix-lists, executive risk briefings, OWASP coverage reports — and audit exports mapped to CRA, IEC 62443, MDR, R155, ISO 27001, NIS2 and more.

OWASP
07 · How it works

From raw findings to actionable security intelligence.

Four layers, one continuous pipeline. Every scan produces normalized, deduplicated, AI-enriched output ready for triage.

i
Step 01

Scan

Run seven scan types across code, dependencies, IaC, containers and the running build — including LLM-powered DAST — in parallel.

ii
Step 02

Aggregate

Every finding is mapped into one unified schema — CWE, CVSS, OWASP requirement, file, line, fingerprint — and tracked in DefectDojo.

iii
Step 03

Enrich

Qwen3.8, running in our German data centers, adds context: exploitability, business impact, and a fix written for your stack.

iv
Step 04

Track & report

Quality gates, tickets in DefectDojo, Jira, Azure Boards or ServiceNow, compliance evidence — and an API for everything else.

08 · Sovereign AI

Your code never leaves Germany.

Every LLM task — triage, remediation and VamiDAST's dynamic testing — runs on Qwen3.8, an open-weight model we operate ourselves in VamiSec's own data centers in Sankt Augustin, Germany. No hyperscaler, no third-country API, no training on your data.

Qwen3.8Hosted in Germany · VamiSec data centers
  • Qwen3.8, self-operatedAn open-weight model from the latest Qwen generation, served on GPUs we own and run — no per-token calls to an external AI provider.
  • Our own data centers in GermanyHosted in VamiSec's own data centers in Sankt Augustin — EU jurisdiction, GDPR by design, operated by our own team.
  • Air-gap optionRegulated product teams can run the full stack — scanners, DefectDojo and the LLM — on their own infrastructure.
  • Auditable promptsEvery LLM call is logged with model version, prompt and output — evidence-grade traceability for your assessor.
Qwen3.8
open-weight LLM, operated by VamiSec
DE
VamiSec's own data centers · Sankt Augustin
0
third-country transfers of your code
Air-gap
option: run the full stack on your own GPUs
09 · Why VamiAppSec

Five fragmented dashboards. One source of truth.

Most AppSec teams don't have a tooling problem — they have a translation problem. VamiAppSec collapses the layers between scanner output, developer action and the evidence your auditor asks for.

  • Reduce tool sprawlReplace seven scanner dashboards and a spreadsheet with one DefectDojo-backed workspace — the scanners run in the background.
  • Faster triageDeduplication, fingerprinting and AI summaries cut median triage time in half.
  • Closer dev / sec collaborationFindings arrive in PRs with the fix already drafted — not a CSV in someone's inbox.
  • Compliance as a by-productSBOMs, gate decisions and vulnerability-handling records are generated by the pipeline — not assembled the week before the audit.
−54%
median triage time vs. raw scanner output
7
scan types orchestrated through a single API
93%
duplicate findings collapsed by fingerprinting
∞
scaling — pipeline runs entirely on your infra
10 · Architecture

Four layers. One feedback loop.

The platform is built as a transparent pipeline — every stage is observable, replayable, and auditable.

L1 · Scanners Detection surface
Semgrep · SAST Gitleaks · Secrets Grype / Trivy · SCA Syft · SBOM Checkov · IaC VamiDAST · LLM-DAST ZAP / Nuclei · DAST
L2 · Aggregator Normalize & dedupe
Unified schema → Fingerprint → CWE / CVSS map → OWASP mapping → Stable IDs
L3 · LLM Engine · Qwen3.8 Enrich with context
Exploitability scoring Plain-language summary Stack-aware fix SOP grounding Mentor mode Control mapping (CRA / 62443) VamiSec data centers · DE
L4 · Tracking & reporting Track & deliver
DefectDojo Jira Azure Boards ServiceNow SARIF / IDE PR comments Compliance evidence CycloneDX / SPDX REST API
Quality-gate feedback loop · Triage decisions, false-positives and fix outcomes flow back into the LLM context for future runs.
11 · Use cases

Where teams put VamiAppSec to work.

One platform — six operating modes. From shift-left in the IDE to the evidence file at type approval.

01

Secure CI/CD pipelines

Run on every PR. Block merges on critical findings, soft-fail on regressions, attach SARIF for the IDE.

GitLabGitHubAzure DevOps
02

Vulnerability triage

Cluster duplicates, surface exploitability, route by code-owner, and let the local LLM draft the remediation note — tracked to closure in DefectDojo, Jira, Azure Boards or ServiceNow.

DedupDefectDojoJiraServiceNow
03

CRA & product-security programs

Stand up Annex I vulnerability handling in weeks: SBOM per release, actively-exploited-vulnerability watch, VEX/VDR and 24 h / 72 h / 14-day report drafts.

CRAMDRRED
04

Automotive & industrial

CSMS and IEC 62443-4-1 evidence from the same pipeline — findings linked to TARA assets, defects managed to closure, updates documented.

R155ISO/SAE 21434IEC 62443
05

OWASP-based assessments

Compliance-oriented assessments against ASVS, ISVS, MASVS, WSTG, MASTG or AISVS — with coverage per requirement for web, IoT, mobile and AI products.

ASVSISVSMASVSAISVS
06

Audit-ready evidence

Exportable reports and a full audit trail per finding — for notified bodies, technical services and ISO 27001 / NIS2 auditors alike.

CRAIEC 62443ISO 27001
12 · Get started

Ready to ship products that pass the next audit?

30-minute walkthrough. We connect to a sample repo, run the full pipeline from SAST to LLM-powered DAST, and show you the DefectDojo board, an OWASP ASVS coverage report and the CRA SBOM export.

No credit card · Self-hosted & SaaS · Germany · Live in 24h
— Brand identity

The VamiAppSec logo system.

The approved V+A symbol carries a small magnifier — a quiet nod to the platform's core function: scanning, triaging, and securing application code at scale.

Lockup · dark
Lockup · light
— Design system

Style guide summary.

· Palette

Approved logo · forest-teal & aqua

Five tones, sampled directly from the approved VamiAppSec logo. Deep teal for the V's body, mid teal for the wordmark, aqua highlight for AI/LLM accents and CTAs.

· Typography

Geist · Fraunces · JetBrains Mono

Geist for UI & body — engineered, neutral, modern.

Fraunces italic for editorial accents.

JetBrains Mono uppercase for tags, labels and technical metadata.

· UI direction

Quiet, technical, premium

  • The V+A symbol always sits left of the wordmark.
  • Minimum clear-space around the symbol equals the height of the lowercase "a".
  • Aqua bright (#5EEAD4) is reserved for AI/LLM moments, primary CTAs, and active states.
  • Borders sit at 10–18% accent opacity; full saturation only on CTAs.
  • Mockups always show real data — never lorem ipsum.