Private execution

Run security assessments where your code and internal targets already live.

Enterprise private runners execute eligible source and live-target scans from Docker hosts inside networks you control. Keep cloud and private execution explicit per project, call your LLM provider directly, and choose how much result detail returns to ZeroQuarry.

Customer-controlled Docker hostsOutbound HTTPS onlyMinimized or standard results

Private reachability without pretending the control plane is air-gapped.

The runner stays connected to the ZeroQuarry SaaS control plane and the customer-selected LLM provider. The design gives buyers a precise execution and result boundary instead of a vague on-premise claim.

01

Internal application testing

Reach authorized RFC1918, loopback, link-local, and internal-DNS targets from inside the customer network while cloud workers retain SSRF protections.

02

Private Git source execution

Clone Git repositories directly on the runner with scoped credentials. Browser source uploads and binary uploads do not use private execution.

03

Outbound-only enrollment

Enroll a runner with a one-use, 15-minute token and make outbound HTTPS connections without opening an inbound firewall rule.

04

Per-project execution policy

Allow specific pools on a project, choose a default, and let scan creators select only compatible environments.

05

Result minimization

Return allowlisted finding metadata and safe locations while evidence, remediation text, logs, errors, and artifacts remain on the runner.

06

Operational controls

Separate trust zones into pools, monitor health and leases, drain for maintenance, revoke immediately, and retain an account audit trail.

A concrete path through the work.

ZeroQuarry automates investigation and coordination. Your team keeps control of authorization, risk ownership, and production changes.

STEP 01

Design

Choose the network boundary, eligible source or remote modes, returned-result policy, and account-managed models.

STEP 02

Enroll

Run the generated Docker command on a host that can reach the targets, Git host, LLM providers, and ZeroQuarry control plane.

STEP 03

Authorize

Allow the pool on selected projects and choose whether ZeroQuarry Cloud remains an approved alternative.

STEP 04

Operate

Assign scans explicitly, monitor runner health, and review result and audit behavior without automatic cloud fallback.

What the team gets back.

Useful coverage should lead to faster decisions, cleaner remediation, and evidence that holds up when someone asks for it later.

Coverage of internal attack surface

Assess private applications and APIs that a managed SaaS worker cannot safely reach.

A narrower result boundary

Keep detailed evidence local when minimized metadata is enough for centralized triage and reporting.

Explicit deployment control

Give security and infrastructure teams a reviewable model for network reachability, provider access, retries, and revocation.

Questions that come up in evaluation.

These are the product boundaries, controls, and operating details teams usually want to understand first.

Is a private runner fully on-premise or air-gapped?

No. It executes scans on a customer-controlled Docker host but makes outbound HTTPS calls to the ZeroQuarry control plane and directly to the selected LLM provider.

Which scans can use private runners?

Private pools support Git-backed source scans and authorized remote targets. Source file uploads, archives uploaded through the browser, and binary uploads are not private-runner inputs.

Can a failed private job fall back to ZeroQuarry Cloud?

No. A failed or expired attempt is retried in the same private pool. Cloud execution occurs only when a scan creator explicitly selects an allowed cloud environment.

Do private runners require bring-your-own model keys?

Yes. Every selected scan, review, and artifact model needs an account-managed provider key so the runner can call that provider directly.

Start with one real security boundary.

Use the free trial on your own product, then decide whether the resulting security work is useful enough to keep.