Pre-launch · in development

AI security operations, under your control.

Haider unifies authorised offensive testing, defensive hardening, security research and cross-engagement learning in one self-hosted platform — reasoned by a local LLM, gated by human approval.

Designed to support local processing and controlled data routing — built for teams that need capable AI without sending sensitive security data outside their environment.

Product concept Concept of the Haider engagement console showing scope, active agents, findings and local model status.
Self-hosted Local LLM Scope controlled Human supervised Evidence driven Purple-team ready

The problem

Security knowledge is fragmented.

Scanners, pentest tools, browser testing, AI assistants, hardening scripts, findings, remediation and threat intelligence live in separate places. Worse, what a team learns in one assignment is usually lost before the next one.

scannerspentest toolsbrowser testing AI assistantshardening scriptsfindings remediationthreat intelpast lessonsreports
One governed workflow

Scope · policy · approval · evidence · memory

Product

One controlled security intelligence layer.

Offensive Security

Authorised web and API assessments driven by scoped, evidence-first agents.

  • Scoped reconnaissance & browser-based application testing
  • Specialised AI agents behind risk ceilings
  • Evidence-backed candidate findings — analyst-validated
  • Isolated, argv-only tool execution (no shell strings)

Defensive Security

Turn findings into durable hardening across mixed estates.

  • Linux & Windows baseline assessment
  • Apache / Nginx / IIS hardening & configuration review
  • Patch & vulnerability management, backup assurance
  • Detection engineering & controlled remediation planning

Purple Team

Close the loop from offensive finding to verified defensive improvement.

  • Finding → root cause → hardening
  • Detection → retest → validated closure
  • Every stage lane-coloured and auditable

Research & Experience Intelligence

A governed knowledge base that improves future planning.

  • Public security research ingestion (governed sources)
  • Bug-bounty methodology library & structured lessons
  • Local RAG · false-positive memory · cross-engagement learning
  • Source attribution & disclosure governance

Lifecycle

From authorised test to a reusable lesson.

Red for authorised offensive activity, violet for analysis and correlation, blue for defensive controls, green for verified closure.

Purple-team lifecycle: research, authorised test, validated finding, root cause, remediation, detection, retest, reusable lesson.

Local AI

Your security data stays under your control.

  • vLLM and Ollama support via OpenAI-compatible local endpoints
  • Task-aware model routing with a data-classification allowance
  • Local embeddings and private RAG for experience memory
  • Optional cloud providers only when explicitly configured
  • PRIVATE-classified engagement data never routes to a cloud model
Platform data flow from local vLLM through the policy engine, agent recommendation, human approval and isolated execution.

Agents

Specialised agents behind scope, policy and approval.

A seeded roster of typed agent roles — each with a hard risk ceiling, an allowlist of actions and tools, and a local-model indicator. An agent can never grant itself capability it was not configured for.

Reconnaissance Coordinator

Plans passive recon

passivelocal

TLS Certificate Analyst

Cert / config review

lowlocal

HTTP Surveyor

Headers & responses

lowlocal

Access-Control Analyst

AuthZ / IDOR

low · approvallocal

Infra Service Scanner

Lab scanning

intrusive · lablocal

Hardening Advisor

Baseline defence

passivelocal

Detection Engineer

Rules from findings

passivelocal

Report Author

Validated-only reports

passivelocal

A roster of 26 specialised agent roles is defined today; the list above is a representative selection.

26
Specialised agent roles
4
Operational domains
8
Staged workflows
10+
Reference platforms reviewed

Figures reflect the current project design, not usage metrics.

Experience intelligence

Every assignment makes the next one sharper.

Knowledge flywheel from assignment through observations, findings, analyst feedback and local reflection to a validated lesson and better planning.

Raw events, candidate lessons, validated lessons, organisation lessons and sanitised global lessons are kept distinct. Target-controlled text and unverified AI output can never become trusted methodology on their own.

  • The local LLM proposes candidate lessons only
  • Analysts validate; nothing self-promotes to global
  • Organisation memory never crosses tenant boundaries
  • Global lessons are sanitised of private identifiers

Capabilities

Breadth across the security lifecycle.

Offensive

  • Web application assessment
  • API assessment
  • Browser-based investigation
  • Source-code review
  • External exposure review
  • Safe tool orchestration
  • Evidence capture

Defensive

  • Linux security
  • Windows security
  • Web-server hardening
  • Database security
  • Patch analysis
  • Configuration drift
  • Backup assurance

Intelligence

  • Research ingestion
  • Hybrid RAG
  • Technique graph
  • Experience memory
  • Methodology governance
  • False-positive learning
  • Report quality analysis

Governance

  • Multi-organisation isolation
  • Engagement authorisation
  • Scope enforcement
  • Approval gates
  • Immutable auditing
  • Emergency stop
  • Role-based access

Architecture

The intended platform architecture.

Architecture: Django control plane, policy and approval engine, agent orchestration, local vLLM/Ollama, isolated tool and browser workers, evidence and findings, PostgreSQL with pgvector and object storage.

A Django control plane fronts a policy and approval engine, agent orchestration, local models, and isolated tool and browser workers — with evidence, findings and lessons persisted to PostgreSQL, pgvector and object storage.

DjangoPostgreSQLpgvectorCeleryRedis vLLMOllamaDockerChrome DevTools MCP

Who it's for

Designed for teams protecting more with less.

Haider is intended to help volunteer CISOs, nonprofits, small security teams and administrators of mixed Linux/Windows estates and public websites — with practical prioritisation, low-cost remediation paths, and security knowledge that is retained across assignments. It supports trained professionals; it does not replace them.

Practical prioritisation

Executive and technical reporting from the same validated findings.

Self-hosted & open-friendly

Runs on your own infrastructure with local models and open-source options.

Multi-organisation

Strict separation between the organisations a volunteer CISO supports.

Responsible use

Authorised security testing and defensive operations only.

Haider is built to operate only against systems the operator owns or has explicit written permission to test. The controls are structural, not optional.

Registered organisations

Explicit target authorisation

Exact scope & rate limits

Isolated containers

Human approval gates

Immutable audit history

Emergency stop

Defensive remediation & retest

Roadmap

Where Haider is heading.

Foundation
  • Multi-organisation control plane
  • Asset inventory & engagements
  • Scope policy & approval engine
  • Local LLM integration
  • Safe execution workers
  • Professional web interface
Intelligence · in development
  • Public security research
  • Experience Intelligence
  • Browser testing
  • Methodology library
  • Findings & evidence
  • Defensive hardening
Operations · planned
  • Purple-team workflows
  • Remediation verification
  • Detection engineering
  • Portfolio reporting
  • Continuous posture improvement

Early access

Help shape Haider.

Join the early-access waiting list for development updates, private previews and opportunities to provide feedback.

Interests (optional)

Please don't submit security-testing data through this form. Email is the only required field.