Self-hosted runner
Scan private and internal targets without exposing them publicly.
Overview
A self-hosted runner is an agent you enrol inside your own network. SecNxt routes scans of private or internal targets to it, so sensitive code and traffic never leave your environment.
It is essential for testing internal apps, private cloud and anything you can't (or shouldn't) expose to the public internet.
How it works
You enrol a runner, which registers with SecNxt and waits for work.
When a scan is marked for external execution, the runner claims the job, runs the engine locally, and posts findings and heartbeats back over the runner API.
How to use it
- 1Open the Runners area and enrol a new runner.
- 2Install and start the runner inside your network following the on-screen instructions.
- 3Confirm it reports healthy (heartbeat).
- 4Launch scans against internal targets and route them to the runner.
When to use it
- Testing internal-only web apps and APIs.
- Keeping regulated data inside your network during assessments.
Tips & best practices
- Keep at least one healthy runner online so scheduled internal scans don't stall.
FAQ
- What leaves my network?
- Only the findings and status the runner reports back — the target data stays local.
Related guides
Running a scan
Point SecNxt at a target and get prioritised findings in minutes.
Website / web app scanning (DAST)
Test a running web application the way an attacker would.
Container & cloud posture (CSPM / KSPM)
Find misconfigurations in cloud accounts, containers and Kubernetes.
VAPT — Vulnerability Assessment & Penetration Testing
Audit-grade, human-verified penetration testing with defensible reporting.