Private network DAST for the apps the internet can't see
The apps behind your VPN hold your privileged workflows, and cloud DAST never reaches them. NightVision does, through a Smart Proxy, with no inbound firewall changes.
Internal applications concentrate risk and get the least scrutiny.
They hold privileged workflows and sensitive data, they multiply as every team ships its own tools, and reaching them has historically meant appliances, network changes, or an infrastructure ticket that never gets prioritized.
Full-portfolio coverage, no infrastructure project
Smart Proxy, outbound only
Run a lightweight proxy inside the network; it connects outbound to NightVision and scan traffic reaches internal apps through that tunnel. No inbound firewall rules, no agents, nothing to rack.
Or run scans inside your VPC
Where scan traffic must not leave the network, a Terraform module deploys NightVision scanning inside your own AWS VPC, the model enterprises use for their most regulated applications.
The same scan, either side of the firewall
Internal apps get the same real-browser crawler and Playwright-recorded authenticated scanning with TOTP/MFA, and the same HTTP evidence on request-level findings.
From annual internal assessment to standing coverage
Most internal applications are only dynamically tested during a periodic engagement, if at all. With the Smart Proxy in place, they join the same schedule and CI/CD triggers as your public estate, with findings routed to the pull request, GitHub Security Alerts, or Jira, and the same triage and audit workflow.
One platform, one workflow: public and private applications scanned with the same authenticated engine and the same request/response evidence.
Private network DAST questions
How does NightVision scan apps on a private network?
Through the Smart Proxy: a lightweight proxy you run inside the network that makes an outbound connection to NightVision. Scan traffic reaches internal applications through that tunnel, so nothing about the apps themselves changes and no inbound path is opened.
Do we need firewall or network changes?
No inbound changes. The Smart Proxy connects outbound, so there are no inbound firewall rules, no VPN configuration for the scanner, no appliances to rack, and no agents installed on the applications.
Can scanning run entirely inside our own cloud?
Yes. NightVision provides a Terraform module that deploys scanning inside your own AWS VPC, the deployment model enterprises choose when scan traffic must not leave their network.
Does authenticated scanning work on internal apps?
Yes. Internal applications get the same authenticated scanning as public ones: record the login once as a Playwright script, credentials are vaulted automatically, and TOTP and MFA are supported. A login check verifies the session before testing begins.
Can internal scans run in CI/CD?
Yes. The same GitHub Actions, GitLab CI, Jenkins, Azure DevOps, and Bitbucket integrations trigger scans of internal and pre-production environments through the Smart Proxy. See DAST in CI/CD.
Bring your internal apps into scope.
Book a demo to see the Smart Proxy reach an app behind the firewall, or start free and connect your first target.