Targets & Scope

How to Pentest Localhost Before Launch

Use APVISO's Free Local Pentest workflow to review a localhost web app before launch.

Localhost Scope

A Free Local Pentest is meant for a web app running on your own machine or another loopback address reachable from the APVISO runner. Use localhost, 127.0.0.1, a .localhost host, or ::1; do not use public, staging, private network, or client targets for the free local allowance.

Before You Start

Start your app locally, confirm you are authorized to test it, and configure your BYOK model provider on the runner host. APVISO does not store target credentials or model keys for this flow.

Runner Flow

Install the self-hosted runner, register it to your organization, add a localhost target, and start the medium Launch Review preset. The runner performs preflight checks locally, launches the pinned scan image, and streams findings back to the dashboard.

When To Upgrade

Upgrade when you need public/staging targets, private/internal networks, retests, scheduled testing, governance, integrations, partner-client scopes, or custom model routing.