Security Operations
Redefined.
OWASP codebase scanning meets real-time threat monitoring. One self-hosted dashboard. Zero external dependencies. Complete audit trail. Built for teams that won't compromise on data sovereignty.
Everything you need to
secure your stack
Six integrated modules working together — from codebase analysis to live threat response. All running on your own infrastructure.
OWASP Scanner
Static analysis of PHP, JS, HTML and config files. 52 rules covering every OWASP Top 10 category. Score 0–100 with per-finding remediation guidance.
Stream Monitor
Ingest Apache, Nginx, PHP, and syslog streams in real time. 21 threat detection rules with automatic alert creation and live SSE push to your browser.
Alert Pipeline
Unified alert feed from all sources. Severity tiers, acknowledgement workflow, visual indicators. In-place updates — no page reload required.
Scan History
Every scan persisted with a shareable report URL. File type breakdown, passed check count, OWASP distribution. Delete removes DB records and disk files.
User Management
Three-role RBAC: Admin, Analyst, Viewer. Add users, reset passwords, deactivate accounts, rotate API tokens. Cannot deactivate the last admin.
Audit Trail
Every login, scan, acknowledgement, and config change recorded. Action filter, live search by IP or action. Colour-coded severity. Admin-only access.
52 rules.
Zero blind spots.
Upload a ZIP of your codebase. VoxSecure dissects every PHP, JS, HTML, and config file against the full OWASP Top 10 — then gives you a score, a breakdown, and remediation steps for every finding.
PHP·Syslog
per token
request
Threats detected
as they happen.
Push events from any log source via a simple HTTP POST. 21 rules score every event 0–100. High and critical matches auto-create alerts and push live to your browser via SSE.
Hardened from
the ground up.
VoxSecure practices what it scans. Every layer of the stack — auth, transport, data, and sessions — is hardened by default, with no optional flags required.
Authentication
- Argon2ID password hashing (memory: 64MB)
- Account lockout after 5 failures
- Session fingerprinting (IP + UA)
- SameSite=Strict cookie policy
- Constant-time CSRF comparison
Transport & Headers
- HSTS (2 years + preload)
- Content-Security-Policy strict
- X-Frame-Options: DENY
- Permissions-Policy (camera/mic/geo)
- X-Content-Type-Options: nosniff
Data & Storage
- PDO prepared statements only
- MariaDB strict mode enforced
- Scan files stored outside web root
- ZIP magic bytes validation
- Zip bomb protection (10MB/entry)
Full control.
Every action logged.
Three-role RBAC, complete audit trail, user management, and settings — all with server-side enforcement. No action goes unrecorded.
- check_circleUser management
- check_circleAll scans and reports
- check_circleAudit log access
- check_circleAll stream sources
- check_circleSystem settings
- check_circleSubmit and view own scans
- check_circleAcknowledge alerts
- check_circleManage own stream sources
- check_circleChange own password
- cancelNo user management
- check_circleDashboard & stats
- check_circleRead scan reports
- check_circleView alerts
- cancelNo scans or sources
- cancelNo acknowledgements
Up in
5 minutes.
Shared hosting compatible. No SSH required. A built-in wizard walks you through database setup, directory configuration, and the initial admin account.
/install.php
— the wizard handles DB migration, config writing, and
directory setup.
install.php
immediately. Then log in to your new dashboard.
Requirements
Own your security.
Own your data.
Self-hosted. No telemetry. No subscriptions. No cloud dependencies. Your infrastructure, your rules.