Security tooling that respects your boundaries
SelfSec builds application security tooling for engineers who would rather know exactly where their data goes than trust a label. The product is a self-hosted hybrid agentic vulnerability scanner: deterministic modules crawl and attack an application you are authorized to test, an optional agent loop plans follow-up experiments, and the engine proves a finding is real before it reaches the report — with core scan processing and findings staying on the machine you run it on, and without per-user licensing.
How the claims on this site are verified
Security marketing is full of numbers nobody can check. The counts published here — vulnerability modules, database families, firewall vendors fingerprinted — are read from the product source and pinned to the exact scanner revision they were verified against, rather than rounded up for a headline.
Competitor comparisons follow the same rule: every cell links to the vendor's own published page, carries a verification date, and states plainly that it compares product models and buying paths — not detection results. An automated check fails our build when that evidence goes stale, so a comparison cannot quietly rot on the site.
We run our own defenses on ourselves
selfsec.io is served through a web application firewall we wrote and operate ourselves — a reverse proxy that inspects every request to this site, including the one that loaded this page, before it reaches the application behind it. It is our infrastructure, not a product: we do not put it in front of anyone else's domain, we do not sell it, and we deliberately do not publish its counters or its thresholds. How much traffic this site takes and how much of it gets through is operational detail an attacker can work with. Its own code is in scope for our vulnerability disclosure policy, so a flaw in it is a report we want.
Why this exists
Application security tooling drifted in a direction that suits vendors more than the teams using it. Scanners bill per user, so the price of testing scales with headcount instead of with what you test. They ship a severity and leave the verification to you, and they ask you to move the most sensitive part of the work — your targets, your evidence, your reports — somewhere you cannot inspect.
SelfSec is the other answer: the scanning engine runs on your machine and its core processing and findings stay there, the small number of flows that do leave are named rather than softened, and a finding carries the stage it has actually earned instead of the one a rule claimed for it.
Who it is for
Solo security engineers, AppSec consultants and internal security teams who need deep automated testing on their own machine, without shipping their targets and findings to a vendor cloud.
The scanner
The scanner is hybrid. Deterministic modules — browser-driven crawling, deep injection engines, WebSocket testing, product and CVE reconnaissance, adaptive firewall evasion, dedicated confirmation workers — do the testing. An optional LLM agent loop reads what those modules observed and plans the next experiment, which the engine executes. The engine must reproduce every candidate the agent raises, so the model proposes attacks without becoming the source of truth.
Where it runs
The scanner's core processing and findings database run on 127.0.0.1, on a host you own. The account service handles activation only — which device holds which plan. The categories of data each flow carries, and why, are set out in the Privacy Policy.
What we will not do
This site carries no analytics, no advertising and no cross-site tracking cookies; fonts and application assets are served from SelfSec infrastructure rather than a third-party CDN. The product sends no telemetry at all, so there is nothing to describe as "anonymous" and nothing for you to turn off. Capability claims are pinned to a source revision rather than asserted, and pricing does not tax you per user.