0% of apps under continuous verification
100% coverage — 79 apps, 264 repos, fully automated
Case Study · T-Mobile / Slovak Telekom
KvantumCI brought 79 applications, 264 repositories, and 3 GitLab instances under continuous DevSecOps compliance. Automatically, from a single inventory.
“Gaps our setup missed. Ready to implement fixes. One clear SBOM. One scorecard. Always audit-ready. All from day 1.”
Outcome tracking
0% of apps under continuous verification
100% coverage — 79 apps, 264 repos, fully automated
Quarterly manual reports, stale on delivery
Live posture dashboard, results on demand
3 GitLab instances, no shared view, no comparable score
One inventory, one standardised scorecard across all instances.
Exposed secrets and dependency blind spots — undetected
Every finding surfaced and routed. Caught in the first verification.
No SBOM
Full SBOM · CBOM · AIBOM · MLBOM — every component tracked over time
Weeks of manual work to produce audit evidence
Real-time and point in time compliance evidence — always audit-ready
Security Champions KPIs manually tracked
Every champion’s security score fed automatically by KvantumCI
T-Mobile and Slovak Telekom operate shared application-security infrastructure across three GitLab instances. Their estate spans 122 applications and 511 repositories. A scale where manual oversight of DevSecOps practices is not operationally viable.
The team runs a Security Champions program: 24 named champions covering 65 applications, with formal KPIs tied to security maturity. They needed tooling that would plug into this structure, not replace it.
DevSecOps rules and scans existed, but they were applied ad-hoc, team by team, with no standardized view across markets or GitLab instances. There was no SBOM inventory. No way to compare one application's posture against another. No audit-ready evidence without weeks of manual work.
“We had rules. We just didn't know how well they were being applied.”
The team wanted continuous, standardized DevSecOps visibility they could onboard themselves, without building yet another internal tool.
KvantumCI integrates into the existing GitLab CI/CD pipeline as a SaaS engine. Apps and repos are onboarded automatically from the central application inventory with no per-team manual setup. Scans are triggered on demand and results flow back read-only into the team's internal AppSec Posture dashboard.
The rollout was opt-in and phased: a single flag in the central inventory brings an application into scope. That's how coverage grew from zero to 100% without disrupting delivery.
Integration: Fully API-driven and self-service
Scan types: SBOM · CBOM · AIBOM · MLBOM
Output: Per-app scorecards with severity trends, fed back into the team's existing AppSec Posture dashboard
Onboarding: Single flag in central inventory. No per-team work.
The first scans surfaced gaps that existing basic scanning had missed, including exposed secrets and blind spots in dependency coverage. These weren't exotic edge cases; they were present in repositories the team considered covered.
“KvantumCI found exposed secrets in repositories we considered clean.”
KvantumCI placed every finding into a standardized, per-app scorecard with severity trend arrows so the team could see what needed fixing and route it, rather than discovering it during an audit.
KvantumCI gave us 100% coverage across our entire GitLab estate at T-Mobile and Slovak Telekom. All mapped apps and repos, one continuous verification, driven from a single inventory. It surfaced gaps our previous setup missed, including exposed secrets we didn't know were there, and replaced point-in-time spreadsheets with a live SBOM view that moves with us.
Active customers shape what we build. The T-Mobile / Slovak Telekom team has flagged three priorities for the next phase:
Longer-term visibility into how each application's score, findings, and SBOM composition evolve scan over scan, not just the current state.
Express findings as maturity tiers against SSDLC and OWASP DSOMM so progress is measurable against a recognized framework, not just an internal score.
Automatically open GitLab merge requests that remediate findings, turning detection into a ready-to-review fix with no manual handoff.
Try connecting your repo. KvantumCI runs a gap check and shows exactly what's missing, misconfigured, or inconsistent. It suggests fixes. And creates needed compliance documents. All that in minutes and fully secured.
Up and running in under 10 minutes — no credit card required.