Offense and defense, one account

Find the flaws. Block the attacks.

SelfSec pairs an agentic DAST scanner you run yourself — core scan processing and findings stay on your machine — with a managed WAF that inspects every request before it reaches your origin.

  • Pre-release
  • Scanner runs on your machine
  • One plan, full detection depth

SelfSec DAST runs on a Windows or Linux host you own and confirms a vulnerability there. SelfSec WAF runs as a managed reverse proxy at the SelfSec edge and blocks the same attack before it reaches your origin.

21Vulnerability modules in the DAST engine
19Database engines in the SQLi sub-engine
71WAF and bot vendors fingerprinted
LocalScan processing, on a host you own
Agentic DAST · Self-hosted on Windows or Linux

Turn a live app into confirmed, actionable findings.

Crawl authenticated applications, attack the surface as it appears and prove exploitable behavior before it reaches the report — with core scan processing on your own machine.

  • Reach the real attack surface. Render modern applications, survive two-factor login walls and turn newly discovered routes into attack targets while the crawl is still running.
  • Prove it before you report it. A finding starts as Possible and only becomes Confirmed when independent evidence says so — a dialog that actually fired, a timing differential that survives its baseline, a callback from the target's own infrastructure.
  • Know what to fix first. Every CVE-bearing finding carries a CVSS 4.0 vector, whether CISA lists it as known-exploited, its EPSS exploitation probability and an SSVC decision — so the queue orders itself.

Synthetic live DAST preview showing crawl progress, active attack modules and confirmed findings.

Managed WAF · Nothing to install

Block malicious traffic before it reaches your app.

Point your domain at SelfSec and every request is inspected inline before it reaches your origin — managed rules, signed virtual patches and bot mitigation, with every block naming the rule that made it, no software on your servers and no change to your application.

  • Enforce in front, not inside. Every request is evaluated against 12 attack categories before it is forwarded, stopping injection, protocol abuse, bots and abusive rates while they are still in front of your application.
  • Patch exposure the same day. Shield a known-vulnerable route with a virtual patch while the application team ships the permanent fix. Rule bundles are signed and verified against a pinned key before they reach your traffic.
  • Explain every decision. A block names the rule that made it and leaves an evidence trail you can inspect — not a vendor decision you have to defend to a customer without knowing what it was.

Synthetic live WAF preview showing inspected requests, pass and block decisions, and aggregate counters.

Why SelfSec

Built around the parts you should control

A security platform should produce evidence, respect your infrastructure and stay simple to operate.

Confirmed over claimed

A finding starts as Possible and is promoted only when independent evidence agrees — a dialog that actually fired in a browser, a timing differential that survives its baseline, a callback from the target's own infrastructure.

Nothing you cannot look inside

The firewall starts in detection mode and every block names the rule behind it. The scanner keeps the raw request, the response and the baseline it was measured against. Neither product asks you to trust a verdict you cannot inspect.

Each product states its boundary

Core scan processing and findings stay on the scanner host, and out-of-band confirmation can stay inside your network entirely. WAF traffic is inspected on SelfSec infrastructure, and every field recorded from a request is documented.

One account, both products

From account to active in three steps

No license files and no per-seat administration. One account connects the local products to the subscription they can use.

01

Create your account

Join the launch list now, then choose the scanner, the WAF or both when public access opens.

02

Sign in from the app

The scanner asks for the same email and password you use here — no license files, no keys to copy.

03

Stay in sync

The machine takes a seat on your subscription and keeps its entitlement current on its own.

Be first to run SelfSec

Join the launch list for public availability, deployment guidance and the first production-ready release.