Self-hosted Edition
Run Vulnsy on your own server from an offline package with Docker Compose. The same product for a single organization, with your data on your infrastructure and an offline license.
The self-hosted edition is Vulnsy packaged to run on your own server with Docker Compose. It is the same application as vulnsy.com, set up for a single organization: your team signs in at a hostname you choose, and reports, findings, evidence and user accounts are stored in a database and file store on your infrastructure.
Each release is one offline package, downloaded from the link in your license email. It contains an installer and every container image Vulnsy runs, so installing and upgrading need no container registry and no internet access on the server.
The self-hosted edition does not report back to Vulnsy. The license is checked on your server, offline, and there is no usage reporting.
The user guides in the rest of this documentation apply to the self-hosted edition too. Sign-up, billing, plans and Vulnsy-managed AI are the exceptions: they exist only on vulnsy.com.
What You Get
- The full application: clients, projects, findings, reports, DOCX export, and the modules your license includes (Client Portal, QA, Scoping and Disclosure).
- One organization at your own hostname, with its own users, roles and settings.
- Local accounts. Users sign in with an email address and a password. Passwords are stored as bcrypt hashes in your database. The first administrator sets their own password at first sign-in. SSO is available if your license includes it.
- Email through your SMTP server, for account emails and client communication.
- File storage in an S3-compatible store: Silo (a maintained MinIO fork) is included, or point the install at any S3-compatible service.
- The Vulnsy library: finding templates, report styles, DOCX export templates, email templates and more, installed on first start and updated by upgrades.
- Upgrades on your schedule. Each release is a versioned package, and you choose when to install it.
- An installer that sets up the server, and upgrades, backs up and restores the installation.
What Is Not Included
- Billing and subscriptions. A license from Vulnsy takes their place. It sets the expiry date, the user limit, and the modules and features available. See Licensing.
- Sign-up, trials and the vulnsy.com website. These pages do not exist on a self-hosted server.
- Vulnsy-managed AI. The AI assistant works with your own OpenRouter key or your own model endpoint.
- Email delivery and file hosting by Vulnsy. You provide the SMTP server, and files stay in your own store.
Architecture
Users' browsers
│
┌────────────────────┴────────────────────┐
│ https://APP_HOST │ https://FILES_HOST
▼ ▼
┌────────────────────────────────────────────────────────────────────┐
│ Caddy: TLS on ports 80 and 443 (or your own reverse proxy) │
└────────────────────────────────────────────────────────────────────┘
│ │
▼ ▼
Vulnsy app :3000 ──────────── S3 API ────────▶ MinIO :9000
│ (uploaded files)
▼
PostgreSQL 16 :5432
(vulnsy_control, vulnsy_shared, vulnsy_tenant)| Service | Role |
|---|---|
caddy | Terminates TLS for both hostnames and obtains certificates automatically. Optional: it runs only with the tls profile, and you can use your own reverse proxy instead. |
app | The Vulnsy server. It runs as an unprivileged user (UID 1001), and its application code is read-only. |
postgres | PostgreSQL 16 with three databases: installation settings and license (vulnsy_control), the Vulnsy library (vulnsy_shared), and your organization's data (vulnsy_tenant). |
minio | S3-compatible object storage for evidence, templates and documents (Silo, a maintained MinIO fork, at a fixed release shipped in the package). The app creates the bucket at start-up. |
The app reaches PostgreSQL and MinIO over the internal Docker network. Browsers download files directly from MinIO through the files host, using short-lived signed links that the app creates.
Run exactly one app container. The app keeps some state in memory, so running several replicas of the service is not supported.
Requirements
| Requirement | Details |
|---|---|
| Server | A 64-bit x86 (amd64) Linux server running Ubuntu 22.04 or 24.04, Debian 12, or Red Hat Enterprise Linux, Rocky Linux or AlmaLinux 9. The installer adds Docker Engine and the Docker Compose plugin if they are missing; existing installations need Compose version 2 or later. |
| CPU and memory | 2 CPU cores and 4 GB of RAM suggested |
| Disk | 20 GB to start. Usage grows with uploaded evidence and documents. |
| DNS | Two hostnames that point at the server: one for the app (for example reports.example.com) and one for file downloads (for example files.reports.example.com) |
| An SMTP server that accepts mail from the server | |
| Tools | bash, openssl and tar, used by the installer. Root access, through sudo. |
| AI (optional) | An OpenRouter API key, or an OpenAI-compatible model server on your network |
Network
| Connection | Needed for |
|---|---|
| Inbound TCP 80 and 443 (UDP 443 optional, for HTTP/3) | Users reaching both hostnames through the bundled Caddy. With your own reverse proxy, your proxy's ports apply instead. |
| Outbound to your SMTP server | Sending email |
Outbound HTTPS to download.docker.com | Only if the installer installs Docker for you. Installing and upgrading Vulnsy itself need no internet access. |
| Outbound HTTPS to Let's Encrypt | Automatic certificates from the bundled Caddy. Not needed if you use your own certificates. |
| Outbound to your AI provider or model server | The AI assistant, if you enable it |
Outbound HTTPS to api.pwnedpasswords.com | Checking new passwords against the Have I Been Pwned list of breached passwords. Only the first five characters of the password's SHA-1 hash are sent. If the service cannot be reached, the check is skipped. |
Next Steps
Install
Prepare DNS, download the package, run the installer, sign in and install your license.
Licensing
Instance IDs, installing and renewing a license, status and expiry.
Configuration
Every setting in .env, with the email, storage and AI options.
Backup & Restore
Back up with the installer, and restore on the same or a new server.
Upgrade
Install a new release from its package and verify it with the health and version endpoints.
Troubleshooting
Startup, license, file download, email, sign-in and AI problems.