Internal Security Agent

Continuous security monitoring of your servers, from the inside. A lightweight on-premise agent that checks hardening, package vulnerabilities and exposed services β€” and alerts you when something changes.

External scans see your perimeter. The Internal Agent sees what the outside can't: system configuration, installed packages with known CVEs, services listening on the internal network. It runs on your servers, sends only the results, and turns your security posture into a stream monitored over time.

Cloud or on-premise β€” you decide where the data lives

Same platform, two deployment modes. Choose based on your constraints.

Cloud

simple, zero infrastructure

The agent sends results to SecureScan, which analyzes them and gives you reports, dashboards and monitoring. No infrastructure to manage.

On-premise (appliance)

data sovereignty

An appliance you install on your own servers: collection, CVE correlation and AI analysis all run inside your network. Nothing sensitive ever leaves β€” designed for regulatory or sovereignty constraints (banking, healthcare, public sector, air-gapped). Configuration flows down from the cloud panel; the data stays with you.

QVAC Logo Local AI Β· no cloud

On-premise AI analysis, powered by QVAC

QVAC is Tether's local AI runtime: an open-source engine (Apache 2.0) that runs language models directly on the customer's infrastructure, with no cloud calls. SecureScan uses it to turn the tools' raw results into readable analysis β€” explained risks, priorities and remediation steps β€” computed entirely inside your servers.

  • Runs on-premise: your data never leaves your network. The AI analyzes everything locally, nothing sent to the cloud.
  • Turns findings into plain language: what each vulnerability means, how urgent it is and how to fix it.
  • Lightweight thanks to TurboQuant (memory compression): less RAM required, runs even on modest servers.
  • OpenAI-compatible interface: the model stays configurable and replaceable, with no lock-in.

Powered by QVAC, Tether's local AI runtime (open-source SDK, Apache 2.0).

Your own LLM, even on GPU, on your premises

In the on-premise appliance the AI analysis runs locally. Start with a lightweight CPU model included, or β€” for more quality and speed β€” connect YOUR own vLLM + GPU server with the model you prefer. Just paste the endpoint URL into the panel.

  • Lightweight CPU model included: works without a GPU and downloads itself on first boot (zero config).
  • Or your own vLLM-on-GPU server with a more powerful model β€” configured from the panel (OpenAI-compatible endpoint).
  • Runtime of your choice: vLLM, Ollama, QVAC β€” same standard API, no lock-in, swap with one line.
  • The analysis runs overnight in batch: latency doesn't matter, you can use large models even on modest hardware.

What it checks

System hardening

Operating-system configuration audit with lynis: permissions, services, kernel, authentication policy. It tells you where the server is exposed and how to harden it.

Package vulnerabilities

Filesystem scan with trivy: every installed package is matched against CVE databases. Find vulnerable libraries and components before they are exploited.

Exposed internal services

Opt-in map of ports and services listening on the internal network: what's reachable from inside, often invisible to an external scan.

Malware (ClamAV)

Antivirus scan of sensitive paths with ClamAV: infected files become critical findings, which the AI then explains and prioritizes (assisted triage).

How it works

  1. 1Create an agent from the dashboard and get an install command: a single copy-paste on the server.
  2. 2The agent enrolls securely with a one-time token and runs on a schedule: no inbound ports to open, it only talks outward to SecureScan.
  3. 3Every run sends the tools' raw output; SecureScan normalizes it into findings with severity, package and CVE.
  4. 4Continuous monitoring tracks first and last seen, resolves issues that disappear and reopens the ones that come back β€” you only see what changed.

Built-in CVE correlation

CVE findings are enriched by SecureScan's correlation engine: CVSS score, presence in the CISA KEV catalog (actively exploited vulnerabilities), EPSS exploitation probability and a priority score. You immediately know what to look at first β€” not a flat list of CVEs, but a queue ranked by real risk.

Privacy and light footprint

The agent is a small Python package (standard library plus two dependencies), runs as a scheduled service and opens no inbound ports. It sends only the tools' results, never your data. Updates are signed (Ed25519) and verified before installation. lynis is invoked as an external process, with no GPL code embedded.

Weekly digest

Every week you get an email summary of what changed: new and resolved issues by severity, with critical and high highlighted. No noise when nothing changes.

System requirements

The agent installs and runs in two modes: on its own, or with local AI analysis. Here's what each one needs.

Base agent

always included

Collection (lynis, trivy, nmap), normalized findings and CVE correlation with KEV/EPSS and priority score. No AI required: runs on minimal resources.

Operating system
Linux with systemd (for automatic scheduling of scans and heartbeats).
Python
Version 3.8 or later, with the venv module (python3-venv package). No other dependencies to preinstall: the agent creates its own isolated environment.
Privileges
Root access: installation runs as a system service and full scans (hardening and filesystem) require root permissions.
Scan tools
lynis and/or trivy installed from your distribution's packages (Community Edition is enough). nmap only if you enable the optional internal-network scan.
Network
Outbound HTTPS to SecureScan only β€” no inbound ports to open. trivy downloads its own CVE database on first run.
Resources
Minimal: the agent is a small Python package, it installs no database or heavy services on the server.

With local AI analysis (QVAC)

optional

A local language model turns findings into readable analysis: explained risks, priorities and remediation in plain language, executive summary β€” all on-premise, no data leaves your network.

In addition to the base agent requirements:

  • 8–12 GB of RAM for the Qwen 7–14B model (Q4 quantized): ~8 GB for 7B, ~12 GB for 14B.
  • 5–10 GB of disk for the downloaded model.
  • QVAC runtime (or any OpenAI-compatible endpoint).

Bring monitoring inside your servers

Sign up, create your first agent in a minute and install it with one command.

Try Free β€” 50 Bonus Credits