Internal application testing
Reach authorized RFC1918, loopback, link-local, and internal-DNS targets from inside the customer network while cloud workers retain SSRF protections.
Enterprise private runners execute eligible source and live-target scans from Docker hosts inside networks you control. Keep cloud and private execution explicit per project, call your LLM provider directly, and choose how much result detail returns to ZeroQuarry.
The runner stays connected to the ZeroQuarry SaaS control plane and the customer-selected LLM provider. The design gives buyers a precise execution and result boundary instead of a vague on-premise claim.
Reach authorized RFC1918, loopback, link-local, and internal-DNS targets from inside the customer network while cloud workers retain SSRF protections.
Clone Git repositories directly on the runner with scoped credentials. Browser source uploads and binary uploads do not use private execution.
Enroll a runner with a one-use, 15-minute token and make outbound HTTPS connections without opening an inbound firewall rule.
Allow specific pools on a project, choose a default, and let scan creators select only compatible environments.
Return allowlisted finding metadata and safe locations while evidence, remediation text, logs, errors, and artifacts remain on the runner.
Separate trust zones into pools, monitor health and leases, drain for maintenance, revoke immediately, and retain an account audit trail.
ZeroQuarry automates investigation and coordination. Your team keeps control of authorization, risk ownership, and production changes.
Choose the network boundary, eligible source or remote modes, returned-result policy, and account-managed models.
Run the generated Docker command on a host that can reach the targets, Git host, LLM providers, and ZeroQuarry control plane.
Allow the pool on selected projects and choose whether ZeroQuarry Cloud remains an approved alternative.
Assign scans explicitly, monitor runner health, and review result and audit behavior without automatic cloud fallback.
Useful coverage should lead to faster decisions, cleaner remediation, and evidence that holds up when someone asks for it later.
Assess private applications and APIs that a managed SaaS worker cannot safely reach.
Keep detailed evidence local when minimized metadata is enough for centralized triage and reporting.
Give security and infrastructure teams a reviewable model for network reachability, provider access, retries, and revocation.
These are the product boundaries, controls, and operating details teams usually want to understand first.
No. It executes scans on a customer-controlled Docker host but makes outbound HTTPS calls to the ZeroQuarry control plane and directly to the selected LLM provider.
Private pools support Git-backed source scans and authorized remote targets. Source file uploads, archives uploaded through the browser, and binary uploads are not private-runner inputs.
No. A failed or expired attempt is retried in the same private pool. Cloud execution occurs only when a scan creator explicitly selects an allowed cloud environment.
Yes. Every selected scan, review, and artifact model needs an account-managed provider key so the runner can call that provider directly.
Use the free trial on your own product, then decide whether the resulting security work is useful enough to keep.