Guides, deployment docs, the agentic-AI explainer and answers to the questions security teams ask first.
Stand up ASPM or the API Security platform with one Docker Compose stack โ entirely offline.
Read the guide โTwo separate stacks, zero egress, air-gap topology and hardware sizing.
View architecture โHow the local-LLM agents threat-model, verify exploits and write fixes.
Learn the AI โSOC 2, PCI DSS, HIPAA, NIST and GDPR โ and SBOM export (CycloneDX/SPDX).
See mappings โHow discovery + the AI-assisted WAF cover BOLA, BFLA and mass assignment.
Explore coverage โOur identity model, data handling and the zero-egress guarantee.
Read trust โNo. Source code, scan traffic and AI inference all run on your hardware. There's no license phone-home and no telemetry โ you can run it behind an outbound deny-all firewall.
A local LLM (DeepSeek) running on your own compute. The agentic engine uses it for threat modeling, exploit verification, triage and fix suggestions โ with no per-token cloud bill.
No โ they're two independent products with separate apps, separate data and separate logs. Run one, run both. They're licensed individually and never share a console or store.
Yes. Models, scanners and templates ship with the install. Once deployed there are no outbound dependencies, so an isolated VLAN or air-gapped network works out of the box.
One Docker Compose stack per product โ Postgres, a scanner pool, the local LLM and the app, all as containers you run and own. No SaaS account required.
SSO/AD, RBAC, MFA/TOTP with backup codes, scoped API tokens, a configurable password policy and account lockout โ all built in.
A security product should hold itself to the standard it enforces.
No outbound calls after install. Verifiable with a deny-all firewall rule.
All findings, logs and models live on your infrastructure โ never ours.
MFA, RBAC, hashed API tokens, password policy and lockout by default.
Sensitive fields are encrypted; secrets are never stored in plaintext.
Every privileged action is logged for evidence and incident review.
Built to support SOC 2, PCI DSS, HIPAA, NIST and GDPR evidence.
Our team will walk you through a deployment for your environment.