Thousands of alerts, a handful that matter: Introducing CipherCell!
Security scanners produce noise. xG-portfolio team CipherCell turns that noise into a short list of things that could actually get you breached, and then into evidence you can hand an auditor.
The problem
Point the usual scanners at a single codebase and the findings pile up fast. Very few of them are the ones an attacker could really use, and there's no reliable way to tell which ones are. So software teams sort the list by hand, which is slow and expensive because of the required man-power. They then fix what's left, track what changed, and assemble the audit evidence, all of it manual and all of it repeated every cycle.
What CipherCell does
This is where CipherCell comes in: it’s not another scanner; it analyses the stack itself and makes the scanners a team already runs worth reading. It combines techniques like SAST, SCA and DAST into one picture, then checks whether each finding is actually reachable in the code.
The analysis is deterministic. AI extends that core where it adds value, annotating and ranking what survives. Dynamic verification, currently in development, will go one step further and test whether a vulnerability is genuinely exploitable rather than merely present.
The platform works for any company shipping software, with additional telecom-specific modules sitting on top of the core.
Everything runs on the customer's own infrastructure, and it can be air-gapped if needed. That means the source code and findings never leave the building, which matters in telecommunications and any other critical infrastructure where sending your codebase to a vendor's cloud is a problem.
The results double as audit material: traceable findings and continuously managed SBOM information feed into CRA, NIS2, SOC 2 and ISO 27001 processes, so compliance evidence accumulates as a by-product instead of becoming its own project every cycle.
Part of the platform is open source. In a market like telecommunications where security tooling is almost entirely proprietary, that's a deliberate choice: a core anyone can inspect doesn't ask you to trust it, it lets you check.
Why telecom
O-RAN represents a shift away from closed, often hardware-based systems towards open, software-based ones running on standard hardware. That shift puts software security front and centre.
Generic scanners still test one component at a time and look straight past the operating system and virtualisation layers underneath. But the risks now live in the seams, in what happens between components at runtime and in the stack those components sit on.
That gap is what CipherCell is being built for, and it's where the team's research expertise lies. Security judged across the whole deployment, from RAN to transport to core, plus everything those functions run on.
The team
CipherCell comes out of the University of Passau. They've been part of the xG-Incubator since April 2026. We're glad to have them in the portfolio and look forward to supporting Dr. Felix Klement, Dr. Florian Frank, Alexander Braml, Marc Schlotzhauer, Erik Foris, Philipp Mayr and the wider team as they secure the next generation of mobile networks.
Website
Dr. Felix Klement