Find the flaws. Block the attacks.
SelfSec pairs an agentic DAST scanner you run yourself — core scan processing and findings stay on your machine — with a managed WAF that inspects every request before it reaches your origin.
- Pre-release
- Scanner runs on your machine
- One plan, full detection depth
SelfSec DAST runs on a Windows or Linux host you own and confirms a vulnerability there. SelfSec WAF runs as a managed reverse proxy at the SelfSec edge and blocks the same attack before it reaches your origin.
Turn a live app into confirmed, actionable findings.
Crawl authenticated applications, attack the surface as it appears and prove exploitable behavior before it reaches the report — with core scan processing on your own machine.
- Reach the real attack surface. Render modern applications, survive two-factor login walls and turn newly discovered routes into attack targets while the crawl is still running.
- Prove it before you report it. A finding starts as Possible and only becomes Confirmed when independent evidence says so — a dialog that actually fired, a timing differential that survives its baseline, a callback from the target's own infrastructure.
- Know what to fix first. Every CVE-bearing finding carries a CVSS 4.0 vector, whether CISA lists it as known-exploited, its EPSS exploitation probability and an SSVC decision — so the queue orders itself.
Synthetic live DAST preview showing crawl progress, active attack modules and confirmed findings.
Block malicious traffic before it reaches your app.
Point your domain at SelfSec and every request is inspected inline before it reaches your origin — managed rules, signed virtual patches and bot mitigation, with every block naming the rule that made it, no software on your servers and no change to your application.
- Enforce in front, not inside. Every request is evaluated against 12 attack categories before it is forwarded, stopping injection, protocol abuse, bots and abusive rates while they are still in front of your application.
- Patch exposure the same day. Shield a known-vulnerable route with a virtual patch while the application team ships the permanent fix. Rule bundles are signed and verified against a pinned key before they reach your traffic.
- Explain every decision. A block names the rule that made it and leaves an evidence trail you can inspect — not a vendor decision you have to defend to a customer without knowing what it was.
Synthetic live WAF preview showing inspected requests, pass and block decisions, and aggregate counters.
Built around the parts you should control
A security platform should produce evidence, respect your infrastructure and stay simple to operate.
Confirmed over claimed
A finding starts as Possible and is promoted only when independent evidence agrees — a dialog that actually fired in a browser, a timing differential that survives its baseline, a callback from the target's own infrastructure.
Nothing you cannot look inside
The firewall starts in detection mode and every block names the rule behind it. The scanner keeps the raw request, the response and the baseline it was measured against. Neither product asks you to trust a verdict you cannot inspect.
Each product states its boundary
Core scan processing and findings stay on the scanner host, and out-of-band confirmation can stay inside your network entirely. WAF traffic is inspected on SelfSec infrastructure, and every field recorded from a request is documented.
From account to active in three steps
No license files and no per-seat administration. One account connects the local products to the subscription they can use.
Create your account
Join the launch list now, then choose the scanner, the WAF or both when public access opens.
Sign in from the app
The scanner asks for the same email and password you use here — no license files, no keys to copy.
Stay in sync
The machine takes a seat on your subscription and keeps its entitlement current on its own.
Understand the attacks behind the findings
new Image().src='//attacker.example/x'Cross-Site ScriptingBlind XSS: When Your Payload Fires in an Admin Panel You Never See
{ user(id: 1043) { email } }GraphQLBroken Object-Level Authorization in GraphQL Resolvers
; idCommand InjectionCommand Injection: How One Semicolon Hands Over Your Server
Origin: https://evil.exampleCORS MisconfigurationCORS Misconfiguration: When a Stranger's Website Can Read Your Logged-In Data
Be first to run SelfSec
Join the launch list for public availability, deployment guidance and the first production-ready release.