Run Cerberus on your own machine with Docker. Local users, run history, PDF-ready reports, and encrypted model credentials stay under your control. Passive checks are the safe default; authorized active tools are an explicit opt-in.
The first head watches what the world can see. Leaked API keys, missing security headers, exposed config files, open directories. The low-hanging fruit an attacker grabs in the first thirty seconds.
The second head checks DNS, public metadata, exposed files, security headers, and other signals that reveal too much to an attacker.
The third head guards your vitals. Speed, build quality, and the technical rot that quietly bleeds customers and rankings even when no one is attacking you at all.
The fourth head runs explicitly authorized Nuclei, OWASP ZAP, and conservative sqlmap checks from isolated workers. It stays disabled until the owner opts in.
Cerberus gives self-hosters a plain-English, prioritized view of public exposure, configuration problems, and performance issues. It is a diagnostic—not a penetration-test authorization slip or a promise that a site is secure.
Clone the public repository and let the setup script generate secrets, pull the hardened stack, and wait for health. Cerberus is free software under AGPL-3.0.
Clone the repository from GitHub.
Run ./scripts/setup.sh.
Open the local console and create the first owner.
Only scan websites you own or are explicitly authorized to assess. Read the Help, Terms, Privacy Policy, and Disclaimer before use.