AI security operations, under your control.
Haider unifies authorised offensive testing, defensive hardening, security research and cross-engagement learning in one self-hosted platform — reasoned by a local LLM, gated by human approval.
Designed to support local processing and controlled data routing — built for teams that need capable AI without sending sensitive security data outside their environment.
The problem
Security knowledge is fragmented.
Scanners, pentest tools, browser testing, AI assistants, hardening scripts, findings, remediation and threat intelligence live in separate places. Worse, what a team learns in one assignment is usually lost before the next one.
Scope · policy · approval · evidence · memory
Product
One controlled security intelligence layer.
Offensive Security
Authorised web and API assessments driven by scoped, evidence-first agents.
- Scoped reconnaissance & browser-based application testing
- Specialised AI agents behind risk ceilings
- Evidence-backed candidate findings — analyst-validated
- Isolated, argv-only tool execution (no shell strings)
Defensive Security
Turn findings into durable hardening across mixed estates.
- Linux & Windows baseline assessment
- Apache / Nginx / IIS hardening & configuration review
- Patch & vulnerability management, backup assurance
- Detection engineering & controlled remediation planning
Purple Team
Close the loop from offensive finding to verified defensive improvement.
- Finding → root cause → hardening
- Detection → retest → validated closure
- Every stage lane-coloured and auditable
Research & Experience Intelligence
A governed knowledge base that improves future planning.
- Public security research ingestion (governed sources)
- Bug-bounty methodology library & structured lessons
- Local RAG · false-positive memory · cross-engagement learning
- Source attribution & disclosure governance
Lifecycle
From authorised test to a reusable lesson.
Red for authorised offensive activity, violet for analysis and correlation, blue for defensive controls, green for verified closure.
Local AI
Your security data stays under your control.
- vLLM and Ollama support via OpenAI-compatible local endpoints
- Task-aware model routing with a data-classification allowance
- Local embeddings and private RAG for experience memory
- Optional cloud providers only when explicitly configured
- PRIVATE-classified engagement data never routes to a cloud model
Agents
Specialised agents behind scope, policy and approval.
A seeded roster of typed agent roles — each with a hard risk ceiling, an allowlist of actions and tools, and a local-model indicator. An agent can never grant itself capability it was not configured for.
Reconnaissance Coordinator
Plans passive recon
TLS Certificate Analyst
Cert / config review
HTTP Surveyor
Headers & responses
Access-Control Analyst
AuthZ / IDOR
Infra Service Scanner
Lab scanning
Hardening Advisor
Baseline defence
Detection Engineer
Rules from findings
Report Author
Validated-only reports
A roster of 26 specialised agent roles is defined today; the list above is a representative selection.
Figures reflect the current project design, not usage metrics.
Experience intelligence
Every assignment makes the next one sharper.
Raw events, candidate lessons, validated lessons, organisation lessons and sanitised global lessons are kept distinct. Target-controlled text and unverified AI output can never become trusted methodology on their own.
- The local LLM proposes candidate lessons only
- Analysts validate; nothing self-promotes to global
- Organisation memory never crosses tenant boundaries
- Global lessons are sanitised of private identifiers
Capabilities
Breadth across the security lifecycle.
Offensive
- Web application assessment
- API assessment
- Browser-based investigation
- Source-code review
- External exposure review
- Safe tool orchestration
- Evidence capture
Defensive
- Linux security
- Windows security
- Web-server hardening
- Database security
- Patch analysis
- Configuration drift
- Backup assurance
Intelligence
- Research ingestion
- Hybrid RAG
- Technique graph
- Experience memory
- Methodology governance
- False-positive learning
- Report quality analysis
Governance
- Multi-organisation isolation
- Engagement authorisation
- Scope enforcement
- Approval gates
- Immutable auditing
- Emergency stop
- Role-based access
Architecture
The intended platform architecture.
A Django control plane fronts a policy and approval engine, agent orchestration, local models, and isolated tool and browser workers — with evidence, findings and lessons persisted to PostgreSQL, pgvector and object storage.
Who it's for
Designed for teams protecting more with less.
Haider is intended to help volunteer CISOs, nonprofits, small security teams and administrators of mixed Linux/Windows estates and public websites — with practical prioritisation, low-cost remediation paths, and security knowledge that is retained across assignments. It supports trained professionals; it does not replace them.
Practical prioritisation
Executive and technical reporting from the same validated findings.
Self-hosted & open-friendly
Runs on your own infrastructure with local models and open-source options.
Multi-organisation
Strict separation between the organisations a volunteer CISO supports.
Responsible use
Authorised security testing and defensive operations only.
Haider is built to operate only against systems the operator owns or has explicit written permission to test. The controls are structural, not optional.
Registered organisations
Explicit target authorisation
Exact scope & rate limits
Isolated containers
Human approval gates
Immutable audit history
Emergency stop
Defensive remediation & retest
Roadmap
Where Haider is heading.
- Multi-organisation control plane
- Asset inventory & engagements
- Scope policy & approval engine
- Local LLM integration
- Safe execution workers
- Professional web interface
- Public security research
- Experience Intelligence
- Browser testing
- Methodology library
- Findings & evidence
- Defensive hardening
- Purple-team workflows
- Remediation verification
- Detection engineering
- Portfolio reporting
- Continuous posture improvement
Early access
Help shape Haider.
Join the early-access waiting list for development updates, private previews and opportunities to provide feedback.