Self-hosted · Local inference by default

One self-hosted system for the full offensive workflow.

From scanner evidence to reviewed reports today, then validation, collaboration, and human-supervised assessment on the same foundation you run yourself.

  • Ollama by default
  • Cloud is opt-in, BYO key
  • Operator signs every finding
Preview of the Nullsid workspace: an engagement with 214 normalized findings from five evidence sources, drafted by a local model and awaiting operator review.

Reads evidence from

  • Burp Suite
  • Nmap
  • Nuclei
  • Nessus
  • OpenVAS
  • Operator notes

Workflow

Three steps. One accountable operator.

Nullsid keeps mechanical execution, model interpretation, and human judgment as separate, visible stages instead of blurring them into “autonomy”.

  1. Automation

    Ingest the evidence

    Normalize scanner exports and plain notes into one findings workspace, with each claim tied back to its source file.

    Raw evidence structured state

  2. Local model

    Draft with your model

    Correlate duplicates, suggest CVSS metrics, and draft descriptions, remediation, and summaries, with provenance attached to every field.

    Structured state reviewable proposal

  3. Operator

    Review and deliver

    Trace any sentence to the evidence behind it, edit every field, then export a client-ready DOCX or PDF on your own template.

    Reviewable proposal signed deliverable

Product

One findings spine. Every workflow connected.

Reporting is the first operator loop, not the ceiling. Evidence, assets, severity, provenance, remediation, status, and audit history stay connected as new workflows land.

Findings that keep their evidence

Every normalized finding carries the parser, host, raw record, and the operator decisions applied to it. Nothing becomes an unsourced assertion in a client deliverable.

  • Per-host rollup before the model ever sees a template
  • Deduplication across overlapping scanners
  • Field-level diff between AI draft and operator edit

Provenance on every field

AI-generated text is marked, editable, and traceable to the evidence that produced it.

Runs on your hardware

Docker Compose, your host, your storage. No vendor tenancy holding client engagement data.

Deliverables clients accept

Export to the formats and templates you already use, without a manual reformat pass.

  • DOCX
  • PDF
  • JSON
  • Markdown

Model routing

Local models by default. Cloud only when you configure it.

Nullsid ships pointed at Ollama. Cloud providers stay off until an engagement permits them and you supply your own key, so the default path is the private one.

Default route

Self-hosted workspace Ollama endpoint

  1. Run it where you work

    The workspace and the reporting pipeline live in infrastructure you control.

  2. Ollama handles inference

    Model requests go to your configured Ollama endpoint, on the box or on your network.

  3. Operators review output

    Generated claims stay editable until a human signs them into the deliverable.

Workspace Ollama Reviewed output

Roadmap

Reporting first. The rest of the loop next.

Each stage reuses the same evidence, findings, provenance, and inference layer, so the privacy model does not change as the surface grows.

  1. Now · in development

    Report workspace

    Import, normalize, draft, review, and export client-ready deliverables.

    Scanner output signed-off report

  2. Next · planned

    Validation assistant

    Ground claims in raw evidence, flag likely false positives, surface review priorities.

    Evidence verified finding

  3. Next · planned

    Team operations

    Ownership, comments, approval states, and reusable delivery standards.

    Finding team decision

  4. Later · direction

    Agentic assessment

    Human-supervised workflows that operate only inside an explicitly authorized scope.

    Approved action auditable result

FAQ

Questions operators ask first.

Anything else: hello@nullsid.com.

Does client data leave my network?

Not on the default configuration. Nullsid runs on your infrastructure and sends model requests to the Ollama endpoint you configure. A cloud provider is only contacted if you explicitly enable one and supply a key.

Which model do I need to run?

Anything your Ollama instance serves. Larger models produce better narrative sections; the structured work (parsing, dedup, scoring, export) does not depend on the model.

How do I know what the AI wrote?

Generated fields are marked with their provenance and remain editable. You can trace a sentence back to the finding and the raw scanner record behind it before signing off.

What does it take to deploy?

A Docker host and an Ollama endpoint. Storage stays local, and the workspace is API-first so it can sit behind your existing authentication.

Does it replace the pentester?

No. It removes the mechanical hours around the engagement. Severity, scope, and every claim in the deliverable stay a human decision.

When is early access?

The report workspace is in active development. Join the list and you get one message when operator access opens. No drip campaign.

Early access

Start local. Choose every connection.

Join the list for the self-hosted reporting workspace: Ollama as the default provider, BYO-key cloud when you decide otherwise.

No spam. One update when early access opens.