MAYA - AI Agent
Team Leader of AI Agents
Remediation Agent
Runs a dry run, waits for your approval, then fixes it
Evidence Collector
Collects your SOC 2, ISO 27001 and DPDP proof from the tools you already use
IP Scanner
Checks every public address for open ports, known CVEs and weak TLS
DAST (Public + Private)
Tests your APIs for 300+ vulnerability classes, inside and outside the network
CSPM
1,000+ checks across AWS, Azure and Google Cloud, mapped to your frameworks
Cloud Cost Optimization
Rightsizing and idle detection - customers cut cloud spend 28% on average
Integrations
20+ Integrations with your favorite tools
Asset Management
Finds vulnerabilities on your laptops and servers
ECR Container Image Scanning
Scans every ECR image for CVEs before it reaches production
Cloud Security
Keeping AWS, GCP and Azure locked down
AI Governance
Using AI at work without losing control of it
Data Privacy
DPDP, GDPR and looking after personal data
GRC
Audits, controls and staying ready for them
FinOps
Spending less on cloud without breaking things
API Security
Finding holes in your APIs before anyone else
Test the internal APIs no cloud scanner can reach.
A DeDups private scanner is a small agent you run inside your own network, so it can test the internal APIs that no cloud scanner can reach. Requests to your APIs stay inside your network, and only the findings are sent to your DeDups dashboard.
One command to install. No inbound ports.
A cloud scanner can only test what the internet can reach.
Most of the APIs that carry sensitive data are not on the internet at all.
Internal APIs go untested
Service-to-service APIs, admin APIs, Kubernetes ClusterIP services and private VPC endpoints sit behind the firewall, out of reach of any outside scanner.
Opening the firewall is the wrong fix
Exposing an internal API so that it can be scanned creates the very risk the scan is meant to find.
Internal does not mean safe
Broken authentication, excessive data exposure and injection flaws are just as exploitable by an attacker who is already inside the network.
A private scanner removes the trade-off: the scanner moves to the APIs, so the APIs never have to move toward the internet.
Four steps, and no change to your firewall’s inbound rules.
Once started, the scanner works in a loop. It calls out to DeDups to pick up the private APIs queued for testing, runs the checks from inside your network, and sends the findings back. Every connection is opened by the scanner, outward; DeDups never connects in.
- 01Add your APIs
Add them manually, import a Postman collection, or let eBPF discovery find them.
- 02Generate an API key
The key ties the scanner to your DeDups organization.
- 03Pick where it runs
A Linux or macOS host that can reach your APIs, or a Kubernetes (EKS) cluster.
- 04Run one command
Copy it from the Private Scanners page and run it on that host or cluster.
Any team whose APIs are not reachable from the public internet.
| Team | Their situation | What a private scanner gives them |
|---|---|---|
| Security and AppSec | Internal APIs are a blind spot in every external scan | The same API security checks, run against internal services |
| Platform and DevOps | Microservices talk over ClusterIP services and private VPC endpoints | A scanner that runs as a workload inside the cluster, with no ingress to build |
| Compliance and GRC | Auditors ask for evidence that internal systems are tested too | Findings for private APIs in the same dashboard as public ones |
| Regulated industries | Policy forbids exposing internal systems or sending traffic through a third party | Testing that runs entirely inside the network boundary |
Everything your platform team will ask, at a glance.
- Form
- A single static binary with no Docker and no runtime dependencies.
- Host platforms
- Linux (x86-64, arm64) and macOS (Apple Silicon, Intel).
- Kubernetes
- A one-replica Deployment in the dedups namespace on EKS, built on an empty base image with zero OS packages.
- Credentials
- One API key. On Kubernetes it lives in a Secret you create; the hosted manifest contains no credentials.
- Network
- The host needs to reach your private APIs and make outbound calls to DeDups. No inbound ports.
- Coverage
- 700+ API security checks run against every API scanned.
- Schedule
- Checks for new work every 5 minutes by default.
- Monitoring
- Each scanner sends a heartbeat and appears in the dashboard within a minute. It is marked Down after 10 minutes of silence.
- Updates
- An administrator releases a version once; each scanner downloads, verifies and installs it on its next cycle, then restarts itself.
Set up your first private scanner.
Open Private Scanners in your DeDups dashboard, generate your API key, and run the install command on a host inside your network. The scanner reports in within a minute and appears under Installed connectors, ready to test your private APIs.
sales@dedups.ai - we reply within 2 hours