The SelfSec product line

One security loop. Two products.

Use agentic DAST to find and confirm exploitable weaknesses before release, then put the managed WAF in front of your site to stop malicious traffic in production.

  • One account
  • One sign-in
  • Documented data boundaries

SelfSec DAST runs on a Windows or Linux host you own and confirms a vulnerability there. SelfSec WAF runs as a managed reverse proxy at the SelfSec edge and blocks the same attack before it reaches your origin.

Offense meets defense

From a confirmed flaw to a blocked attack

The scanner finds and confirms the weakness on a host you own. The firewall enforces protection in front of your origin, on traffic we inspect for you.

Offense · SelfSec DAST

Attacks like an adversary

The agentic scanner crawls, attacks and confirms — finding the flaws before anyone else does.

CrawlAttackConfirm

Your application

scanned from a host you run · served from your origin

Tested locally, shielded in production

Defense · SelfSec WAF

Blocks the real ones

The reverse-proxy firewall inspects every request inline and drops the attacks before they reach your app.

SQLiXSSbotrate-limit
Agentic DAST · Self-hosted on Windows or Linux

Turn a live app into confirmed, actionable findings.

Crawl authenticated applications, attack the surface as it appears and prove exploitable behavior before it reaches the report — with core scan processing on your own machine.

Reach the real attack surface

Prove it before you report it

Know what to fix first

Synthetic SelfSec DAST preview showing confirmed findings from a live scan.

Managed WAF · Nothing to install

Block malicious traffic before it reaches your app.

Point your domain at SelfSec and every request is inspected inline before it reaches your origin — managed rules, signed virtual patches and bot mitigation, with every block naming the rule that made it, no software on your servers and no change to your application.

Enforce in front, not inside

Patch exposure the same day

Explain every decision

Synthetic SelfSec WAF preview showing live pass and block decisions at the edge.

Choose your starting point

Which product fits the job?

The products solve different moments in the same application-security loop. Use either one independently or connect both through the same account.

SelfSec DAST

Offense

Role
Offense
What it covers
Web and Android apps; Windows desktop apps on a Windows host
When it works
Before release and on demand
Primary output
Confirmed findings
Runs on
Windows or Linux host
Data boundary
Scan processing and findings stay local

SelfSec WAF

Defense

Role
Defense
What it covers
Every request reaching the sites you protect
When it works
On every live request
Primary output
Enforced traffic decisions
Runs on
SelfSec-operated edge — nothing on your servers
Data boundary
Requests are inspected on SelfSec infrastructure

Both products are pre-release and managed from the same account. The scanner installs on a Windows or Linux host you own and activates when you sign in with your account; the WAF needs nothing installed — you prove the name is yours, then point its DNS record at it.

Who runs SelfSec

Three reasons teams choose SelfSec

Cost, confidentiality and compliance decide the tool long before the feature list does. These are the situations the product line is shaped around.

You pay for your own tools

Solo engineers and bug-bounty hunters carry the licence cost themselves. There is one plan and it keeps the full module set rather than crippling detection at the low end, and core scan processing stays on your machine.

See what the plan includes

You test other people's applications

Consultants work under NDA, and client URLs, evidence and reports are exactly what an assessment agreement says cannot be shared. Scanning runs locally, and flat pricing means one more client is not one more seat charge.

Review reporting and exports

You have to know exactly where data goes

When a contract, a regulator or an internal policy governs where application data may travel, the deployment model decides the purchase. The scanner keeps core processing and findings on your host; the firewall is a service we run, so requests to a protected site are inspected by us on the way to your origin.

Read the Privacy Policy

Build your security loop with both products

Join the launch list for public availability, deployment guidance and the first production-ready release.