Version 2.2.1 · self-hosted

Know what's hitting your Nginx server before it becomes an incident.

SecuriReport AI tails your access and error logs, classifies SQL injection, XSS, path traversal, scanner and credential-stuffing attempts against CWE, and turns them into audit-ready reports and copy-pasteable firewall commands — all on your own infrastructure.

One-time payment. No subscription. Runs on your server. Logs never leave it by default. Node.js or Docker. Your choice.

Pick your report engine — or use none at all.

Ollama (local) Google Gemini OpenAI / ChatGPT Anthropic Claude Deterministic fallback
How it works

From raw log line to reviewed remediation, in four steps.

01

Ingest

Tail a log file on disk, upload one for a one-off pass, or paste a few lines to test — combined-format Nginx access and error logs, parsed in real time.

02

Detect & classify

Pattern-based detection flags SQL injection, XSS, path traversal, scanner fingerprints, credential stuffing and API abuse, each tagged with its CWE ID.

03

Report

Generate an executive briefing, a SOC 2 / NIST CSF style audit dossier, or a forensic deep-dive — via a local model, a cloud provider, or a deterministic template.

04

Remediate

Get the exact iptables, UFW, Nginx, Cloudflare or fail2ban command for an offending IP. You copy it, review it, and run it — on your terms.

What's inside

Built for operators who need signal, not another dashboard to babysit.

Top adversary attribution

A ranked table of your most active attacking IPs, with origin, attack volume and predominant vector — record a firewall rule straight from the row.

Per-event forensic drilldown

Open any flagged request for the raw payload, CWE classification, and an on-demand AI analysis with a suggested code-level patch.

Five report templates

Executive briefing, compliance dossier, technical forensic deep-dive, DevSecOps remediation blueprint, and a weekly threat digest.

Trusted admin IP whitelist

Keep your own office, VPN, or monitoring servers out of the attacker view — a browser-local convenience, not an access-control list.

Light, dark, or system theme

Follows your OS setting live, or pin it — persisted per browser, applied before first paint so there's no flash of the wrong theme.

Optional login screen

Turn on AUTH_USERS for a signed, HttpOnly session cookie in front of every API route — one more layer on top of your network controls.

Interface

A dashboard that reads like a SOC console, not a spreadsheet.

Diagram of the Dashboard tab: KPI cards for ingress, attacks detected, critical exploits, server faults and generated drops; an attack volume chart; a severity donut chart; and a top adversary attribution table.

To-scale diagram of the real Dashboard tab, built from the application's own source.

It reports. It never acts on its own.

The single most important design decision in this product: SecuriReport AI is a monitoring and reporting tool, not an enforcement agent.

  • It never modifies your host firewall, Nginx configuration, or DNS.
  • Every "ban" or "drop" action produces a command for you to review and run yourself.
  • It's built to run behind your own network-level access control — not exposed directly to the public internet.
  • Log-path and Ollama-host endpoints are allow-listed to prevent arbitrary file reads and SSRF.
Pricing

One license. Every minor and patch update in that version series.

Perpetual license
£99.99

One-time payment · handled by Lemon Squeezy · VAT calculated at checkout

  • Install on your own infrastructure, no seat limits
  • All minor & patch updates within this major version
  • Full source and documentation, no phone-home telemetry
  • Delivered as a license key by email, activates in minutes
Continue to checkout

You'll be redirected to Lemon Squeezy, our payment processor and merchant of record, to complete payment securely.

What you're not paying for

This is documentation-only licensing — no dedicated support contract, no managed hosting, no subscription. Major-version upgrades (v3, when it exists) are offered separately, sometimes at a discount for existing customers. Full terms are in the EULA.

Product ID: 1304718 · License keys via Lemon Squeezy
Questions

A few things people ask before buying.

Do my logs ever leave my server?

No, not by default. Everything runs on your own host. The only exception is if you deliberately select a cloud AI provider (Gemini, OpenAI or Claude) for report generation — in that case, the data needed for that one report is sent to whichever provider you chose.

Do I need Docker, or an AI provider, to use this?

No to both. Node.js 22+ is enough to run it directly, and if you configure no AI provider at all, report generation automatically falls back to a deterministic, template-based engine.

Is this a subscription?

No — it's a one-time £99.99 payment for a perpetual license to the major version you buy, covering all minor and patch releases in that series.