self-hosted vs hosted
Self-host it free. Or skip the bills.
The engine is open source and fully capable — run it yourself whenever you want. The hosted cloud exists for one reason: predictable, hands-off scanning. No API keys, no surprise LLM token bills, and you only pay per live host you actually scan.
What does it really cost?
Self-hosting is free to run, but you pay your LLM provider for every token the agent burns — and agentic, multi-phase scans are token-hungry and hard to predict. Move the sliders to your setup.
LLM tokens only. Excludes your servers, maintenance, and time.
20 credits · pay-as-you-go. From $8.17/mo on a subscription. All-in.
At this volume, hosted is about $586/mo cheaper — and that ignores the servers, upgrades, and rate-limit babysitting you skip. No API keys, no bill surprises.
Estimates only, for comparison. Token usage varies widely with model, scope, and scan depth — tune the sliders to your own numbers. Hosted figures use current published pricing (pay-as-you-go at $0.70/credit, subscriptions from $0.41/credit).
Side by side
Both run the exact same 22-phase, exploit-verified engine. The difference is everything around the scan.
| Self-hosted (OSS) | Hosted cloud | |
|---|---|---|
| Price to start | Free, open source (Apache-2.0) | One full scan from $1 · credits never expire |
| LLM API key | Bring & manage your own | Included — no keys to wrangle |
| Cost per scan | Raw LLM tokens — variable, can spike on deep/agentic runs | 1 credit per live host — predictable, billed on results |
| Setup & ops | You install, update, and run the engine + toolchain | Nothing to run — scan in ~60 seconds |
| Out-of-band infra (SSRF, blind RCE, XXE) | You stand up your own OOB/collaborator server | Managed OOB included |
| Scale & concurrency | One box you nurse; you handle rate limits | Managed queue, multiple backends, auto-scaled |
| Scheduled & recurring scans | Wire up your own cron | Built in (daily / hourly) |
| Team, RBAC & shared credits | Single-user | Workspaces, roles, shared credit pool |
| Updates | Pull & rebuild yourself | Always on the latest engine |
| Data residency & privacy | Everything stays on your infrastructure | Runs on our infrastructure (DPA available) |
| Air-gapped / offline use | Supported (local models via Ollama) | Not applicable — it's a cloud service |
| Support | Community / GitHub issues | Email support with SLAs on paid plans |
★ = where self-hosting is the better fit. If data must never leave your network, or you want to run fully offline, self-host — that's exactly what it's for.
Try a full scan for $1
No subscription, no API keys, credits never expire. See exactly what an exploit-verified report looks like — then decide.
xalgorix