Internal Security Agent
Continuous security monitoring of your servers, from the inside. A lightweight on-premise agent that checks hardening, package vulnerabilities and exposed services β and alerts you when something changes.
External scans see your perimeter. The Internal Agent sees what the outside can't: system configuration, installed packages with known CVEs, services listening on the internal network. It runs on your servers, sends only the results, and turns your security posture into a stream monitored over time.
Cloud or on-premise β you decide where the data lives
Same platform, two deployment modes. Choose based on your constraints.
Cloud
simple, zero infrastructureThe agent sends results to SecureScan, which analyzes them and gives you reports, dashboards and monitoring. No infrastructure to manage.
On-premise (appliance)
data sovereigntyAn appliance you install on your own servers: collection, CVE correlation and AI analysis all run inside your network. Nothing sensitive ever leaves β designed for regulatory or sovereignty constraints (banking, healthcare, public sector, air-gapped). Configuration flows down from the cloud panel; the data stays with you.
On-premise AI analysis, powered by QVAC
QVAC is Tether's local AI runtime: an open-source engine (Apache 2.0) that runs language models directly on the customer's infrastructure, with no cloud calls. SecureScan uses it to turn the tools' raw results into readable analysis β explained risks, priorities and remediation steps β computed entirely inside your servers.
- Runs on-premise: your data never leaves your network. The AI analyzes everything locally, nothing sent to the cloud.
- Turns findings into plain language: what each vulnerability means, how urgent it is and how to fix it.
- Lightweight thanks to TurboQuant (memory compression): less RAM required, runs even on modest servers.
- OpenAI-compatible interface: the model stays configurable and replaceable, with no lock-in.
Powered by QVAC, Tether's local AI runtime (open-source SDK, Apache 2.0).
Your own LLM, even on GPU, on your premises
In the on-premise appliance the AI analysis runs locally. Start with a lightweight CPU model included, or β for more quality and speed β connect YOUR own vLLM + GPU server with the model you prefer. Just paste the endpoint URL into the panel.
- Lightweight CPU model included: works without a GPU and downloads itself on first boot (zero config).
- Or your own vLLM-on-GPU server with a more powerful model β configured from the panel (OpenAI-compatible endpoint).
- Runtime of your choice: vLLM, Ollama, QVAC β same standard API, no lock-in, swap with one line.
- The analysis runs overnight in batch: latency doesn't matter, you can use large models even on modest hardware.
What it checks
System hardening
Operating-system configuration audit with lynis: permissions, services, kernel, authentication policy. It tells you where the server is exposed and how to harden it.
Package vulnerabilities
Filesystem scan with trivy: every installed package is matched against CVE databases. Find vulnerable libraries and components before they are exploited.
Exposed internal services
Opt-in map of ports and services listening on the internal network: what's reachable from inside, often invisible to an external scan.
Malware (ClamAV)
Antivirus scan of sensitive paths with ClamAV: infected files become critical findings, which the AI then explains and prioritizes (assisted triage).
How it works
- 1Create an agent from the dashboard and get an install command: a single copy-paste on the server.
- 2The agent enrolls securely with a one-time token and runs on a schedule: no inbound ports to open, it only talks outward to SecureScan.
- 3Every run sends the tools' raw output; SecureScan normalizes it into findings with severity, package and CVE.
- 4Continuous monitoring tracks first and last seen, resolves issues that disappear and reopens the ones that come back β you only see what changed.
Built-in CVE correlation
CVE findings are enriched by SecureScan's correlation engine: CVSS score, presence in the CISA KEV catalog (actively exploited vulnerabilities), EPSS exploitation probability and a priority score. You immediately know what to look at first β not a flat list of CVEs, but a queue ranked by real risk.
Privacy and light footprint
The agent is a small Python package (standard library plus two dependencies), runs as a scheduled service and opens no inbound ports. It sends only the tools' results, never your data. Updates are signed (Ed25519) and verified before installation. lynis is invoked as an external process, with no GPL code embedded.
Weekly digest
Every week you get an email summary of what changed: new and resolved issues by severity, with critical and high highlighted. No noise when nothing changes.
System requirements
The agent installs and runs in two modes: on its own, or with local AI analysis. Here's what each one needs.
Base agent
always includedCollection (lynis, trivy, nmap), normalized findings and CVE correlation with KEV/EPSS and priority score. No AI required: runs on minimal resources.
- Operating system
- Linux with systemd (for automatic scheduling of scans and heartbeats).
- Python
- Version 3.8 or later, with the venv module (python3-venv package). No other dependencies to preinstall: the agent creates its own isolated environment.
- Privileges
- Root access: installation runs as a system service and full scans (hardening and filesystem) require root permissions.
- Scan tools
- lynis and/or trivy installed from your distribution's packages (Community Edition is enough). nmap only if you enable the optional internal-network scan.
- Network
- Outbound HTTPS to SecureScan only β no inbound ports to open. trivy downloads its own CVE database on first run.
- Resources
- Minimal: the agent is a small Python package, it installs no database or heavy services on the server.
With local AI analysis (QVAC)
optionalA local language model turns findings into readable analysis: explained risks, priorities and remediation in plain language, executive summary β all on-premise, no data leaves your network.
In addition to the base agent requirements:
- 8β12 GB of RAM for the Qwen 7β14B model (Q4 quantized): ~8 GB for 7B, ~12 GB for 14B.
- 5β10 GB of disk for the downloaded model.
- QVAC runtime (or any OpenAI-compatible endpoint).
Bring monitoring inside your servers
Sign up, create your first agent in a minute and install it with one command.
Try Free β 50 Bonus Credits