Pre-release

Where SelfSec stands today

The account platform is live and the firewall already runs in production in front of this site — the request that loaded this page went through it. What is not open yet is public onboarding: a scanner package you can download, and domains other than our own pointed at the firewall.

  1. Account platform

    Live

    Accounts, subscriptions and the entitlement API run in production today. You can create an account and pick a plan before either product ships.

  2. SelfSec WAF

    Running in production

    The firewall already runs in production in front of selfsec.io — the request that loaded this page went through it. Onboarding customer domains and the self-service console around it are still being built.

  3. SelfSec DAST

    In release validation

    The scanner is pre-release. The Windows and Linux installers, their checksums and the published system requirements are being finalized before external use.

  4. Public downloads

    Not open yet

    No installer is published yet. The launch list is the channel that receives the availability notice, with the deployment guide alongside it.

No dates are published here on purpose: a self-hosted security product ships when its installer, its guide and its rollback path are all supportable, not when a quarter ends.

Before you start

What you will need

Neither product needs an account with your cloud provider or a change to your application code. The scanner needs a host you control; the firewall needs nothing on your side at all — only DNS records you can change.

SelfSec DAST

The scanner runs on a machine you already control and keeps its findings there.

  • A Windows or Linux host — your workstation or a VM you own
  • A target you are authorized to test
  • A SelfSec account — the app signs in with it directly, and you can release any device from your dashboard
  • For Android targets: the Android SDK platform tools on that host, plus a JDK and apktool if you use the APK repackaging path
  • Optional: your own OpenAI or Anthropic key, or a local Ollama runtime to keep AI analysis offline

SelfSec WAF

Nothing runs on your side, so the list is short.

  • A domain name whose DNS records you can change, so you can prove it is yours and then point it at SelfSec
  • An origin that keeps accepting requests once they arrive from SelfSec instead of directly from visitors
  • An active SelfSec WAF subscription, which covers every site you point at us
  • No host to provision, no package to install, no agent in your application

Host sizing, the checksum for each package and the supported operating-system versions are published with each installer, so the numbers on this page always match a build you can download. A companion Android app that pairs with the scanner over a certificate-pinned local connection is developed alongside it and is not part of the packages listed here.

After public access opens

How activation will work

One account covers both products. Core scan processing and findings stay on the scanner host; WAF traffic is inspected on SelfSec infrastructure on the way to your origin.

01

Install the scanner, or point your domain

The scanner installs on a Windows or Linux host you own; its package will be linked from this page. The WAF needs nothing installed — you prove the site name is yours, then point its DNS record at SelfSec.

02

Sign in with your account

The scanner asks for the same email and password you use on this site. There is no token to generate, copy or store.

03

Stay connected

The machine takes a seat on your subscription and keeps its entitlement current on its own; you can release it from the dashboard at any time. Protected sites inherit your plan from the account itself.

Know when public access opens

Join the launch list for download availability, deployment guidance and production release notes.