Vulnsy Docs
Self-hosted

Self-hosted Edition

Run Vulnsy on your own server from an offline package with Docker Compose. The same product for a single organization, with your data on your infrastructure and an offline license.

The self-hosted edition is Vulnsy packaged to run on your own server with Docker Compose. It is the same application as vulnsy.com, set up for a single organization: your team signs in at a hostname you choose, and reports, findings, evidence and user accounts are stored in a database and file store on your infrastructure.

Each release is one offline package, downloaded from the link in your license email. It contains an installer and every container image Vulnsy runs, so installing and upgrading need no container registry and no internet access on the server.

The self-hosted edition does not report back to Vulnsy. The license is checked on your server, offline, and there is no usage reporting.

The user guides in the rest of this documentation apply to the self-hosted edition too. Sign-up, billing, plans and Vulnsy-managed AI are the exceptions: they exist only on vulnsy.com.

What You Get

  • The full application: clients, projects, findings, reports, DOCX export, and the modules your license includes (Client Portal, QA, Scoping and Disclosure).
  • One organization at your own hostname, with its own users, roles and settings.
  • Local accounts. Users sign in with an email address and a password. Passwords are stored as bcrypt hashes in your database. The first administrator sets their own password at first sign-in. SSO is available if your license includes it.
  • Email through your SMTP server, for account emails and client communication.
  • File storage in an S3-compatible store: Silo (a maintained MinIO fork) is included, or point the install at any S3-compatible service.
  • The Vulnsy library: finding templates, report styles, DOCX export templates, email templates and more, installed on first start and updated by upgrades.
  • Upgrades on your schedule. Each release is a versioned package, and you choose when to install it.
  • An installer that sets up the server, and upgrades, backs up and restores the installation.

What Is Not Included

  • Billing and subscriptions. A license from Vulnsy takes their place. It sets the expiry date, the user limit, and the modules and features available. See Licensing.
  • Sign-up, trials and the vulnsy.com website. These pages do not exist on a self-hosted server.
  • Vulnsy-managed AI. The AI assistant works with your own OpenRouter key or your own model endpoint.
  • Email delivery and file hosting by Vulnsy. You provide the SMTP server, and files stay in your own store.

Architecture

                          Users' browsers
                                │
           ┌────────────────────┴────────────────────┐
           │ https://APP_HOST                        │ https://FILES_HOST
           ▼                                         ▼
┌────────────────────────────────────────────────────────────────────┐
│  Caddy: TLS on ports 80 and 443 (or your own reverse proxy)        │
└────────────────────────────────────────────────────────────────────┘
           │                                         │
           ▼                                         ▼
    Vulnsy app :3000 ──────────── S3 API ────────▶ MinIO :9000
           │                                      (uploaded files)
           ▼
    PostgreSQL 16 :5432
    (vulnsy_control, vulnsy_shared, vulnsy_tenant)
ServiceRole
caddyTerminates TLS for both hostnames and obtains certificates automatically. Optional: it runs only with the tls profile, and you can use your own reverse proxy instead.
appThe Vulnsy server. It runs as an unprivileged user (UID 1001), and its application code is read-only.
postgresPostgreSQL 16 with three databases: installation settings and license (vulnsy_control), the Vulnsy library (vulnsy_shared), and your organization's data (vulnsy_tenant).
minioS3-compatible object storage for evidence, templates and documents (Silo, a maintained MinIO fork, at a fixed release shipped in the package). The app creates the bucket at start-up.

The app reaches PostgreSQL and MinIO over the internal Docker network. Browsers download files directly from MinIO through the files host, using short-lived signed links that the app creates.

Run exactly one app container. The app keeps some state in memory, so running several replicas of the service is not supported.

Requirements

RequirementDetails
ServerA 64-bit x86 (amd64) Linux server running Ubuntu 22.04 or 24.04, Debian 12, or Red Hat Enterprise Linux, Rocky Linux or AlmaLinux 9. The installer adds Docker Engine and the Docker Compose plugin if they are missing; existing installations need Compose version 2 or later.
CPU and memory2 CPU cores and 4 GB of RAM suggested
Disk20 GB to start. Usage grows with uploaded evidence and documents.
DNSTwo hostnames that point at the server: one for the app (for example reports.example.com) and one for file downloads (for example files.reports.example.com)
EmailAn SMTP server that accepts mail from the server
Toolsbash, openssl and tar, used by the installer. Root access, through sudo.
AI (optional)An OpenRouter API key, or an OpenAI-compatible model server on your network

Network

ConnectionNeeded for
Inbound TCP 80 and 443 (UDP 443 optional, for HTTP/3)Users reaching both hostnames through the bundled Caddy. With your own reverse proxy, your proxy's ports apply instead.
Outbound to your SMTP serverSending email
Outbound HTTPS to download.docker.comOnly if the installer installs Docker for you. Installing and upgrading Vulnsy itself need no internet access.
Outbound HTTPS to Let's EncryptAutomatic certificates from the bundled Caddy. Not needed if you use your own certificates.
Outbound to your AI provider or model serverThe AI assistant, if you enable it
Outbound HTTPS to api.pwnedpasswords.comChecking new passwords against the Have I Been Pwned list of breached passwords. Only the first five characters of the password's SHA-1 hash are sent. If the service cannot be reached, the check is skipped.

Next Steps

On this page