Skip to content
Agentic hybrid DAST · a self-hosted web application security scanner

Modules attack. The agent adapts. Proof decides.

Deterministic modules do the testing. An agent loop decides what to try next when a rule runs out of ideas. Nothing reaches the report until the engine reproduces it.

Runs on your Windows or Linux hostAI optional, off by defaultOne flat plan, published price

Illustration of the SelfSec scan console: a run past an authenticated wall, findings listed with the stage each has earned, Exploited, Confirmed, Possible or Refuted, and the evidence the engine recorded for the selected finding. The status line reads: confirm, browser dialog fired, promoted to Confirmed.
scan 2841 · app.example.internal

Product readout

21 Active vulnerability modules, plus 10 passive analyzersmodule list · release-pinned
19 Database engines fingerprinted with per-engine techniquesengine list · release-pinned
51 Weakness classes (CWEs) covered by the active and passive modulesCWE map · release-pinned
Local Core scan processing and the findings database stay on your host127.0.0.1 · Windows or Linux · nothing uploaded

Reports in the standards your tools already readCVSS 4.0CISA KEVEPSSSSVCSARIF 2.1.0MITRE ATT&CK Navigator

How hybrid agentic scanning works

Two ways of thinking about a target. One standard of proof.

SelfSec pairs a deterministic scan engine — crawler, injection modules, WAF evasion, confirmation workers — with an LLM agent that plans the next experiment when a rule runs out of ideas. Every candidate the agent raises must be reproduced by the engine before it reaches the report, and the whole thing runs on your own machine.

Illustration of the SelfSec orchestrator in four beats: the agent proposes an experiment, the engine executes it against the target, the response returns to a verification gate with three evidence types, and only a reproduced result becomes a Confirmed finding. The agent never sends a request itself.
Orchestrator
  1. 01 · Deterministic engine

    Hardcoded modules do the testing

    Fixed payload sets, a SQL injection engine with per-database techniques, a Chromium crawler that keeps authenticated state, and a WAF evasion chain composed per target. Every request is repeatable and every verdict is auditable.

    crawl → attack → observe · the same engine, with or without a model

  2. 02 · Agent loop

    The model plans the next experiment

    When a deterministic check stalls, the model is handed the real crawl data and findings, proposes the next experiment, watches the result and plans again — inside a turn cap and a per-run budget. It never sends a request itself; the engine executes what it proposes.

    dangerous actions wait for your approval · suggest or autonomous mode, your choice

  3. 03 · Verification gate

    The engine decides what is real

    Model text never confirms anything. A candidate the agent reports is recorded as Possible and handed to the same confirmation workers as every other finding. The model can nudge a confidence score only inside a narrow band, and it keeps no memory between scans.

    no alert() → not Confirmed · no reproduction → not Confirmed, however good the proposal looked

AI is optional and off by default. Turn it on with your own Anthropic or OpenAI key, keep it on your host with Ollama, or use the hosted AI included in the plan. Whether it finds more than the deterministic engine alone is a question for your own targets, not a claim this page makes.

Finding lifecycle

Confirmation is a stage, not an adjective

Most scanners hand you a severity and leave the verification to you. Here a finding carries the stage it has actually earned, and the engine is the thing that promotes it.

A single finding travels along a track: it begins as Possible with its raw request and baseline, becomes Confirmed when a second independent kind of evidence agrees, and Exploited when the engine demonstrates impact. A second finding sits on a siding marked Refuted, kept with its evidence rather than dropped.

Possible

A detection rule matched. The finding is recorded with its raw request, the response and the baseline it was compared against — and it stops here until something independent agrees.

Confirmed

A second, different kind of evidence agreed: a real browser dialog, a timing differential that survives a median-and-standard-deviation baseline, or an out-of-band callback from the target itself.

Exploited

The engine went further and demonstrated impact — extracted data through a confirmed injection point, or reached a resource the access-control check said it should not.

A client-side script finding is only Confirmed when a real dialog fires in a Chromium page the scanner is driving.

The depth behind the workflow

Every capability is a stage of the same engine

  1. 01

    Reach the real attack surface

    Render modern applications, survive two-factor login walls and turn newly discovered routes into attack targets while the crawl is still running.

  2. 02

    Prove it before you report it

    A finding starts as Possible and only becomes Confirmed when independent evidence says so — a dialog that actually fired, a timing differential that survives its baseline, a callback from the target's own infrastructure.

  3. 03

    Know what to fix first

    Every CVE-bearing finding carries a CVSS 4.0 vector, whether CISA lists it as known-exploited, its EPSS exploitation probability and an SSVC decision — so the queue orders itself.

Your infrastructure

Know where every security-sensitive flow goes

Data boundary diagram. On your host: the crawler, the attack engine, responses and evidence, the findings database, exports and optional local AI. On selfsec.io: your account and subscription, the device check that tells us which device holds which plan, and a callback relay for out-of-band checks that keeps timing metadata only, never callback contents. A dashed third zone marks an optional configured AI service that receives only the scan context the work needs. Targets, responses and findings never cross the boundary.
Data boundary · local core · explicit remote flows

Targets, responses and findings remain with the scanner. Activation is narrowly scoped: which device holds which plan, and nothing else. Claims on this site are checkable by design:

  • Every number is pinned to a scanner release

    21 modules, 19 database engines, 51 CWEs: each count comes from the scanner's own lists at a named release, and each number links to the list it was read from.

  • Comparisons are sourced and dated

    Every competitor cell quotes the vendor's own page with a link and the date it was checked; SelfSec's own cells link to the page that states the fact. Stale evidence is removed, not left standing.

  • We run our own defenses on ourselves

    selfsec.io sits behind the same kind of firewall the scanner is built to test through.

  • No analytics, no tracking

    This site uses no advertising or third-party analytics. What you read here stays between you and the page.

SelfSec DAST · one plan Launch price

Flat pricing. Everything included.

$250 / month

  • Unlimited targets and scans
  • Up to 5 devices · no per-user fees; release a device from your dashboard any time
  • Every module · 21 active and 10 passive, nothing held back for a higher tier
  • Hosted AI included · or bring your own Anthropic or OpenAI key, or run Ollama on your host
  • Every export · HTML, JSON, Markdown, SARIF 2.1.0, ATT&CK Navigator
Join the launch list

Nothing is charged during pre-release; this is the launch price. USD, excl. VAT, billed monthly. SelfSec is sold to businesses and self-employed professionals only.

How SelfSec compares

Product model, deployment and buying path, in each vendor's own words

Acunetix is now sold as Invicti Web + API; the two right-hand columns describe one vendor's two products.

How SelfSec compares: product model, deployment and buying path, in each vendor's own published words. Checked 2026-10-03.
Axis SelfSecBurp Suite ProInvictiInvicti Web + APIformerly Acunetix
Buying basisOne flat plan at a published launch price, up to five devices. Nothing is charged during pre-release. Sold to businesses and self-employed professionals only.S$4991 · Licensed for individual users.Start a quote2 · on every tier; the only published figure is "$500 max per pentest"Get a quote3 · A target is defined in Invicti as a fully qualified domain name (FQDN).
DeploymentRuns on 127.0.0.1 on a Windows or Linux host you control.SLocal installation only.4SaaS, on-prem, and hybrid options5 · the pricing page lists "On-Premises (coming soon)" for Web + APIdeploy Invicti on premises or as a SaaS solution6 · the pricing page lists "On-Premises (coming soon)"
Validation approachA finding stays Possible until independent evidence promotes it to Confirmed; Exploited only when impact is demonstrated; Refuted findings are kept with their evidence.SNot stated on page7Proven exploitability. Zero guesswork.5automated proof of exploit for many findings6
Sources · checked

“S” markers link to the SelfSec page that states the fact. This compares product models and buying paths, not detection results. Quoted text is copied from the linked page as it read on the checked date. “Not stated on page” means the linked page does not say; it does not mean the product lacks it. Vendor offerings and prices change; follow each source before purchasing.

Sources (11)
  1. https://portswigger.net/buy/pro (opens in a new tab)
  2. https://www.invicti.com/pricing (opens in a new tab)
  3. https://www.acunetix.com/pricing/ (opens in a new tab)
  4. https://portswigger.net/burp/dast/resources/dast-vs-professional (opens in a new tab)
  5. https://www.invicti.com/product/dast (opens in a new tab)
  6. https://www.acunetix.com/vulnerability-scanner/ (opens in a new tab)
  7. https://portswigger.net/burp/pro/features (opens in a new tab)
  8. https://portswigger.net/burp/pro (opens in a new tab)
  9. https://www.invicti.com/ (opens in a new tab)
  10. https://www.acunetix.com/ (opens in a new tab)
  11. https://www.invicti.com/platform-overview (opens in a new tab)
Launch list

Be first to run SelfSec

Join the launch list to hear when public downloads open, with deployment guidance and the first production-ready release. Nothing is charged during pre-release.