Case Study · T-Mobile / Slovak Telekom

100% of apps & repos continuously verified
Zero manual setup.

KvantumCI brought 79 applications, 264 repositories, and 3 GitLab instances under continuous DevSecOps compliance. Automatically, from a single inventory.

79/79 Eligible apps onboarded
264/264 Eligible repos scanned
3 GitLab instances
Zero Manual setup required

“Gaps our setup missed. Ready to implement fixes. One clear SBOM. One scorecard. Always audit-ready. All from day 1.”

Jan Koldinský, Cybersecurity Expert @ T-Mobile

From spreadsheets to a live posture dashboard.

Outcome tracking

Before

0% of apps under continuous verification

Outcome

100% coverage — 79 apps, 264 repos, fully automated

Before

Quarterly manual reports, stale on delivery

Outcome

Live posture dashboard, results on demand

Before

3 GitLab instances, no shared view, no comparable score

Outcome

One inventory, one standardised scorecard across all instances.

Before

Exposed secrets and dependency blind spots — undetected

Outcome

Every finding surfaced and routed. Caught in the first verification.

Before

No SBOM

Outcome

Full SBOM · CBOM · AIBOM · MLBOM — every component tracked over time

Before

Weeks of manual work to produce audit evidence

Outcome

Real-time and point in time compliance evidence — always audit-ready

Before

Security Champions KPIs manually tracked

Outcome

Every champion’s security score fed automatically by KvantumCI

The organization

T-Mobile and Slovak Telekom operate shared application-security infrastructure across three GitLab instances. Their estate spans 122 applications and 511 repositories. A scale where manual oversight of DevSecOps practices is not operationally viable.

The team runs a Security Champions program: 24 named champions covering 65 applications, with formal KPIs tied to security maturity. They needed tooling that would plug into this structure, not replace it.

Security Champion dashboard showing SSDLC maturity, KvantumCI scan scores, and container metrics
Customer internal security champion dashboard

Rules only on paper. No visibility into reality.

DevSecOps rules and scans existed, but they were applied ad-hoc, team by team, with no standardized view across markets or GitLab instances. There was no SBOM inventory. No way to compare one application's posture against another. No audit-ready evidence without weeks of manual work.

“We had rules. We just didn't know how well they were being applied.”

The team wanted continuous, standardized DevSecOps visibility they could onboard themselves, without building yet another internal tool.

One inventory. One scorecard. Everywhere.

KvantumCI integrates into the existing GitLab CI/CD pipeline as a SaaS engine. Apps and repos are onboarded automatically from the central application inventory with no per-team manual setup. Scans are triggered on demand and results flow back read-only into the team's internal AppSec Posture dashboard.

The rollout was opt-in and phased: a single flag in the central inventory brings an application into scope. That's how coverage grew from zero to 100% without disrupting delivery.

Integration: Fully API-driven and self-service

Scan types: SBOM · CBOM · AIBOM · MLBOM

Output: Per-app scorecards with severity trends, fed back into the team's existing AppSec Posture dashboard

Onboarding: Single flag in central inventory. No per-team work.

Exposed secrets. Dependency blind spots. Found immediately.

The first scans surfaced gaps that existing basic scanning had missed, including exposed secrets and blind spots in dependency coverage. These weren't exotic edge cases; they were present in repositories the team considered covered.

“KvantumCI found exposed secrets in repositories we considered clean.”

KvantumCI placed every finding into a standardized, per-app scorecard with severity trend arrows so the team could see what needed fixing and route it, rather than discovering it during an audit.

KvantumCI gave us 100% coverage across our entire GitLab estate at T-Mobile and Slovak Telekom. All mapped apps and repos, one continuous verification, driven from a single inventory. It surfaced gaps our previous setup missed, including exposed secrets we didn't know were there, and replaced point-in-time spreadsheets with a live SBOM view that moves with us.

Jan Koldinský Cybersecurity Expert @ T-Mobile

What the team wants next.

Active customers shape what we build. The T-Mobile / Slovak Telekom team has flagged three priorities for the next phase:

Richer trend history

Longer-term visibility into how each application's score, findings, and SBOM composition evolve scan over scan, not just the current state.

Standards mapping

Express findings as maturity tiers against SSDLC and OWASP DSOMM so progress is measurable against a recognized framework, not just an internal score.

AI-generated fix MRs

Automatically open GitLab merge requests that remediate findings, turning detection into a ready-to-review fix with no manual handoff.

See what your last scan didn't catch.

Try connecting your repo. KvantumCI runs a gap check and shows exactly what's missing, misconfigured, or inconsistent. It suggests fixes. And creates needed compliance documents. All that in minutes and fully secured.

Run a Free Repo Scan

Up and running in under 10 minutes — no credit card required.