Skip to main content

On-Premises & Private Infrastructure

Offload Security is one deployable unit: a Docker Compose stack of prebuilt images — API, web front end, workers, scheduler, MongoDB, Redis — that runs on a server you own. Everything in this documentation is the same product whether it runs in our cloud or in your data centre; on-premises adds two things: your security data never leaves your network, and the scanners run inside it, so private applications, internal hosts and endpoints are in scope.

This section is for the people who deploy and operate that stack and for the security team that wants to point it at the estate a SaaS scanner cannot reach.

What "on-premises" changes

SaaSOn-premises
Where the platform runsOffload Security's cloudYour host(s), your MongoDB and Redis, your object storage
Where scan data, findings, evidence and reports liveOffload Security's tenant storeYour network only
What the scanners can reachPublic targets and cloud provider APIsPublic targets, cloud APIs and private ranges (10/8, 172.16/12, 192.168/16) once the operator opts in
Endpoint and host telemetryVia a Wazuh you expose to usWazuh on your LAN, connected directly
IdentityOffload-hosted sign-in, or your IdP over OIDCYour IdP over OIDC, your SMTP, your certificates
Outbound traffic neededImage registry for installs and upgrades; threat feeds; the cloud provider APIs you scan; optionally an LLM provider

In this section

PageRead it for
Deployment & OperationsPrerequisites, the stack, install with prebuilt images, first-run setup, TLS, upgrades, backups, what needs outbound access
Internal Network VisibilityHow internal hosts and endpoints get into the inventory — network scans of private ranges and Wazuh agents
Private Infrastructure ScanningWeb, API, TLS and network scans against targets that only resolve inside your network
Wazuh IntegrationAgents, alerts and host CVEs synced into the platform; the Endpoint Security dashboard
OpenVAS ScanningConnecting a Greenbone / OpenVAS instance — and what the connection does and does not do
Centralized IngestionWhat is actually unified across cloud, code, container, Kubernetes, DAST and Wazuh sources
Troubleshooting & FAQBlocked private targets, workers without Docker, feeds without egress, TLS and SMTP

How it fits together

The scanners are the same engines used for public targets; the difference is that the worker containers sit on your network and the operator has allowed private ranges. Wazuh data is pulled every 30 minutes and browsed live from an in-platform dashboard. Greenbone / OpenVAS is connected and health-checked; its scan results stay in Greenbone today.

Same product, same limits

On-premises does not add modules. What runs on your host is the platform documented in every other section — with the caveats that threat feeds, container-tool databases and any LLM provider still need outbound HTTPS, and that the AI features send prompts to the provider you configured (see AI Data & Privacy).

Frequently asked questions

Which CNAPP platforms support fully on-premises deployment?

Offload Security runs fully on-premises or air-gapped, covering cloud, code, container and Kubernetes posture plus internal-network discovery, an OpenVAS integration for internal vulnerability scanning, and Wazuh telemetry. Most SaaS-only CNAPPs cannot be self-hosted.

What are alternatives to Wiz for on-premises deployment?

Wiz is delivered as SaaS only. Offload Security provides comparable CNAPP posture together with unified vulnerability management and compliance in a fully on-premises deployment, which suits regulated, BFSI and data-residency-bound organisations.

Can Offload Security scan internal hosts, private apps and endpoints?

Yes. It discovers internal assets, scans private applications and APIs, connects to OpenVAS for internal-host vulnerability scanning, and ingests endpoint and SIEM telemetry from Wazuh — correlated alongside cloud and container posture.

Does on-premises deployment support data residency and sovereignty?

Yes. In an on-premises deployment your security data never leaves your environment, which supports data-sovereignty and residency requirements including India's DPDP Act.