Private scanners Runs inside your network

Test the internal APIs no cloud scanner can reach.

A DeDups private scanner is a small agent you run inside your own network, so it can test the internal APIs that no cloud scanner can reach. Requests to your APIs stay inside your network, and only the findings are sent to your DeDups dashboard.

One command to install. No inbound ports.
Scan private APIs where they live: a scanner agent inside your network tests internal services, APIs and private endpoints, and only the results cross the firewall to the DeDups cloud. No inbound ports.
Why it is needed

A cloud scanner can only test what the internet can reach.

Most of the APIs that carry sensitive data are not on the internet at all.

Internal APIs go untested

Service-to-service APIs, admin APIs, Kubernetes ClusterIP services and private VPC endpoints sit behind the firewall, out of reach of any outside scanner.

Opening the firewall is the wrong fix

Exposing an internal API so that it can be scanned creates the very risk the scan is meant to find.

Internal does not mean safe

Broken authentication, excessive data exposure and injection flaws are just as exploitable by an attacker who is already inside the network.

A private scanner removes the trade-off: the scanner moves to the APIs, so the APIs never have to move toward the internet.

How it works

Four steps, and no change to your firewall’s inbound rules.

Once started, the scanner works in a loop. It calls out to DeDups to pick up the private APIs queued for testing, runs the checks from inside your network, and sends the findings back. Every connection is opened by the scanner, outward; DeDups never connects in.

  1. 01Add your APIs

    Add them manually, import a Postman collection, or let eBPF discovery find them.

  2. 02Generate an API key

    The key ties the scanner to your DeDups organization.

  3. 03Pick where it runs

    A Linux or macOS host that can reach your APIs, or a Kubernetes (EKS) cluster.

  4. 04Run one command

    Copy it from the Private Scanners page and run it on that host or cluster.

Who needs it

Any team whose APIs are not reachable from the public internet.

TeamTheir situationWhat a private scanner gives them
Security and AppSecInternal APIs are a blind spot in every external scanThe same API security checks, run against internal services
Platform and DevOpsMicroservices talk over ClusterIP services and private VPC endpointsA scanner that runs as a workload inside the cluster, with no ingress to build
Compliance and GRCAuditors ask for evidence that internal systems are tested tooFindings for private APIs in the same dashboard as public ones
Regulated industriesPolicy forbids exposing internal systems or sending traffic through a third partyTesting that runs entirely inside the network boundary
Technical setup

Everything your platform team will ask, at a glance.

Form
A single static binary with no Docker and no runtime dependencies.
Host platforms
Linux (x86-64, arm64) and macOS (Apple Silicon, Intel).
Kubernetes
A one-replica Deployment in the dedups namespace on EKS, built on an empty base image with zero OS packages.
Credentials
One API key. On Kubernetes it lives in a Secret you create; the hosted manifest contains no credentials.
Network
The host needs to reach your private APIs and make outbound calls to DeDups. No inbound ports.
Coverage
700+ API security checks run against every API scanned.
Schedule
Checks for new work every 5 minutes by default.
Monitoring
Each scanner sends a heartbeat and appears in the dashboard within a minute. It is marked Down after 10 minutes of silence.
Updates
An administrator releases a version once; each scanner downloads, verifies and installs it on its next cycle, then restarts itself.
Get started

Set up your first private scanner.

Open Private Scanners in your DeDups dashboard, generate your API key, and run the install command on a host inside your network. The scanner reports in within a minute and appears under Installed connectors, ready to test your private APIs.

sales@dedups.ai - we reply within 2 hours