Security tooling that respects your boundaries

SelfSec builds application security products for engineers who would rather know exactly where their data goes than trust a label. The line pairs a self-hosted agentic DAST scanner — core scan processing and findings stay on the machine you run it on — with a managed reverse-proxy web application firewall that inspects requests before they reach your origin. Offense to find what is exploitable, defense to block it, with explicit data flows and without per-seat licensing.

Why this exists

Application security tooling drifted in a direction that suits vendors more than the teams using it. Scanners bill per seat, so the price of testing scales with headcount instead of with what you test. Firewalls sit on the traffic path without ever saying plainly which fields they read, which they record and which they never store. Both models ask you to move the most sensitive part of your stack — your targets, your findings, your live traffic — somewhere you cannot inspect.

SelfSec is the other answer: the scanning engine runs on your machine and its core processing and findings stay there, the firewall is a service we run in front of your site and we say so in plain words rather than burying it, and nothing that leaves either one is hidden behind a softer word.

Who it is for

Solo security engineers, AppSec consultants and internal security teams who need deep automated testing on their own machine, without shipping their targets and findings to a vendor cloud — and teams who want protection in front of their apps without provisioning, patching and tuning a firewall themselves.

The scanner

The scanner combines browser-driven crawling, deep injection engines, WebSocket testing, product and CVE reconnaissance, adaptive WAF evasion and an AI follow-up phase. The classical engine must confirm every reported result, so AI proposes attacks without becoming the source of truth.

The firewall

Protection we operate for you. You prove the name is yours, point it at SelfSec, and requests to it arrive here first: managed rules, virtual patching, rate limiting and bot mitigation inspect them inline before they are forwarded to your origin. There is no package to download, no server to provision and nothing to keep patched — and it does not matter what your application is built on.

Where each product runs

The scanner's core processing and findings database run on 127.0.0.1, on a host you own. The firewall runs on SelfSec infrastructure: requests to a protected site are terminated and inspected by us on the way to your origin, which is the trade a managed firewall asks you to make deliberately rather than discover later. The account service handles activation and can receive optional device diagnostics and, when you point the scanner at a managed collaborator rather than one you host yourself, out-of-band interaction evidence. The categories of data each flow carries, and why, are set out in the Privacy Policy.

How the claims on this site are verified

Security marketing is full of numbers nobody can check. The counts published here — vulnerability modules, database families, WAF vendors fingerprinted — are read from the product source and pinned to the exact scanner and firewall revisions they were verified against, rather than rounded up for a headline.

Competitor comparisons follow the same rule: every cell links to the vendor's own published page, carries a verification date, and states plainly that it compares product models and buying paths — not detection results. An automated check fails our build when that evidence goes stale, so a comparison cannot quietly rot on the site.

We run it on ourselves first

selfsec.io sits behind SelfSec WAF. Every request to this site — including the one that loaded this page — is inspected by the same firewall we sell, running exactly the way it will run in front of your domain. We deliberately do not publish that deployment's counters: how much traffic a protected site takes and how much of it gets through is operational detail an attacker can work with, and we hold our own site to the same rule we hold yours.

What we will not do

This site carries no analytics, no advertising and no cross-site tracking cookies; fonts and application assets are served from SelfSec infrastructure rather than a third-party CDN. We will not hide what the firewall does with your traffic behind a softer word: requests to a protected site are inspected by us on the way to your origin, and we say so on the product page rather than in a footnote. Optional telemetry is never described as "anonymous" to avoid explaining it, and it stays off until you turn it on. And pricing does not tax you per seat.

SelfSec products are intended strictly for authorized security testing and protection of systems you own or are explicitly permitted to assess.