Early Beta v0.2.0

AUTARCH

Self-Hosted · AI-Driven · Security Operations Platform

One sovereign platform for offense, defense, forensics, OSINT and AI — running entirely on your own hardware. No cloud. No telemetry. Governed by you, powered by Agent HAL.

Early beta — v0.2.0. 73+ modules already live and shipping. A bold platform taking shape at speed, with major capabilities landing every release.

Get the Source See the Interface
73+
Modules
9
Categories
25,475
OSINT Sites
Any
Windows · Mac · Linux
// capabilities

73+ modules. Nine domains. One framework.

Autarch isn’t a pile of scripts — it’s a coherent operations platform. Every tool lives inside a category, and every category is tuned for a phase of security work, from hardening to red-teaming to mobile forensics.

Defense12 modules

Hardening audits, monitoring, and intrusion detection to keep the box locked down.

Offense29 modules

Pentesting workspace with live Metasploit integration for red-team operations.

Counter4 modules

Threat hunting and anomaly detection to surface what shouldn’t be there.

Analyze12 modules

Forensics toolkit — hex inspection, hashing, and artifact analysis.

OSINT7 modules

Search-engine reconnaissance across 25,475 indexed sites with live confidence scoring.

SimulateRed team

Attack simulation to rehearse adversary behaviour safely against your own assets.

Hardware4 modules

Device operations over ADB, Fastboot, and ESP32 flashing straight from the browser.

Android ForensicsNew

Mobile acquisition and IOC scanning for on-device investigation.

Network8-tab suite

Nmap, Wireshark, WiFi audit, deauth, evil-twin and MITM in one integrated suite.

// the interface

A dashboard that thinks alongside you

Everything runs from a fast, web-based command centre — calm, teal-forward, and readable at a glance. Here’s Autarch 2.0 in action.

Command Overview
Autarch Command Overview dashboard showing module count, CLAUDE LLM backend, uptime, nine category tiles, a 24-hour traffic graph, AI synthesis panel and system info.
01 / DASHBOARD

Command Overview

The home screen puts the whole platform on one pane: module count, active LLM backend, uptime, all nine category tiles, a live 24-hour traffic graph, and an AI-synthesis briefing from HAL — plus full system info for the host.

Defense · HAL
Quick Checks defense panel with Firewall, SSH, Ports, Users, Permissions and Services cards, and the HAL assistant showing a CLEAN risk analysis with Let HAL Fix It remediation buttons.
02 / DEFENSE

Quick Checks + HAL

One-click defense checks — Firewall, SSH, Ports, Users, Permissions, Services — each feeding straight into HAL. The assistant scores the risk, explains it in plain language, and offers “Let HAL Fix It” auto-remediation on the spot.

App Launcher
Autarch App Launcher showing the full module grid organised by category.
03 / LAUNCHER

App Launcher

The full module grid, organised by category and searchable. Every one of the 73+ tools is a click away — no terminal spelunking, no memorising flags.

OSINT Engine
OSINT search engine performing username and email lookups across thousands of sites with live confidence scoring.
04 / OSINT

OSINT Search Engine

Run username, email, and identity lookups across 25,475 indexed sites at once, with live confidence scoring so you can separate real hits from noise as results stream in.

Reporting Engine
Reporting engine pentest report builder with CVSS severity scoring and HTML, Markdown and JSON export options.
05 / REPORTING

Reporting Engine

Turn findings into deliverables. Build pentest reports with CVSS severity scoring and export to HTML, Markdown, or JSON — ready for clients or your own records.

Module Creator
Module Creator interface for creating, editing and validating custom modules from templates.
06 / EXTEND

Module Creator

Autarch is built to grow. Create, edit, and validate custom modules from templates right in the UI — the same framework that ships the core toolset is yours to extend.

// the analyst

Meet Agent HAL

Autarch doesn’t just run tools — it reasons about them. HAL is an autonomous AI analyst wired into every module, triaging risk in real time and fixing problems when you let it.

HAL

Backed by Claude (default claude-opus-4-6), with local and self-hosted backends for fully offline operation.

Real-Time Risk Triage

Every tool’s output is analysed the instant it runs — scored, summarised, and prioritised so you know what actually matters.

Let HAL Fix It

When HAL finds something, it can auto-remediate: apply the fix, run incident response, or report-only — your call, every time.

Autonomous, Not Just Automated

HAL plans multi-step investigations, walks specific scans, and briefs you in plain language rather than dumping raw logs.

MCP Server Built In

Expose Autarch’s tools over the Model Context Protocol to Claude Desktop, Claude Code, or any MCP-aware client.

Claude API · default opus-4-6 llama.cpp · local GGUF HuggingFace · Transformers OpenAI-compatible · any endpoint
// sovereign by design

Your machine. Your rules.

01 · Cost

Always Free

Open source, no licence, no tiers. The whole platform is yours to run, read, and modify.

02 · Privacy

No Telemetry

Nothing phones home. No accounts, no analytics, no data leaving the box unless you send it.

03 · Hardware

Runs Anywhere

Cross-platform on Windows, macOS and Linux across aarch64, x86 and x64 — from a Raspberry Pi to a full workstation.

04 · Control

Self-Governed

Self-hosted end to end. No cloud dependency, no third-party gatekeeper between you and your tools.

// one platform vs the stack

The whole security stack, minus the invoice

Enterprises stitch their security programs together from a dozen expensive, siloed products — each with its own licence, its own console, and its own renewal. Autarch folds comparable capability into one self-hosted platform that costs nothing and never phones home.

Capability What teams normally buy Typical list price / yr In Autarch
Endpoint DefenseEDR / XDR
Agent-based endpoint detection & response — e.g. CrowdStrike Falcon, SentinelOne
$50–150per endpoint
Defense + HAL triage
Log & Event AnalyticsSIEM
Ingest, search and correlate security telemetry — e.g. Splunk, Elastic Security
$20k–150k+ingest-based
Monitoring + Counter
Vulnerability ScanningVM / assessment
Network & host vulnerability assessment — e.g. Nessus, Qualys, Tenable
$3k–30k+per scanner
Offense + Network suite
OSINT & Link Analysisrecon
Identity, infrastructure & graph reconnaissance — e.g. Maltego
$2k–20k+per seat
25,475-site OSINT engine
Threat Intelligenceintel feeds
Curated indicators, enrichment & scoring — e.g. Recorded Future, commercial feeds
$25k–100k+subscription
Counter + IOC scanning
Forensics & MobileDFIR
Disk, artifact & mobile-device investigation — e.g. EnCase, Magnet AXIOM, Cellebrite
$3k–15k+per licence
Analyze + Android Forensics
Combined commercial stack
Six or seven separate vendors, consoles and renewal cycles — before a single analyst is hired.
$100k–$500k+
$0self-hosted · open source

Figures are ballpark public list-price ranges for comparable commercial products and vary widely by seats, endpoints, data volume and negotiated contract — they’re here to frame scale, not quote any vendor. Autarch offers comparable capability across these domains in one framework; it is not a drop-in replacement for every enterprise feature of the named tools. Product names belong to their respective owners and imply no affiliation or endorsement.

No per-seat licensing No ingest metering No renewal cliff No telemetry No cloud dependency
// on the roadmap

Coming Soon

The platform grows every release. Here’s what’s landing next — and the list only gets longer.

Coming Soon

Secure Network Endpoint Management

Easy enough to run at home, secure enough to deploy enterprise-wide. Detect breaches faster, shield yourself from a malicious insider, and keep your household off the sites it has no business visiting.

“Free porn is like free sex — you’re probably going to get an infection.”

Our endpoint agents non-intrusively watch for signs of malware, spyware, ransomware and other bad actors.*

* You have full control over how deep the agents scan — and because they report to you locally, not to some overlord in the cloud, your information and data stay yours.

Coming Soon

Keyhole+

A module packing a large, ever-growing database of ransomware decryption keys and emulated decryption servers — recovered and reconstructed from the darkest corners of the web.

When your files are being held for ransom, Keyhole+ goes hunting for the key — so you don’t have to pay for it.

An autarch is a sovereign ruler — one who governs themselves

Govern Your Digital Operations

Free. Open source. No telemetry. No cloud dependencies. Your machine, your rules — with an AI analyst on your side.

Also from Setec Labs

A DNS with all the options the others make you pay for… for free.

// encrypted resolver

Autarch DNS

A private, encrypted DNS resolver run on our own hardware — no third-party forwarders, no query logs shipped off the box. Point your phone, laptop, or router at it and every lookup travels encrypted.

Set Up Encrypted DNS

Fully Recursive

Resolves straight from the root servers — queries are never handed to Google, Cloudflare, or any outside provider.

Encrypted Transport

DNS-over-TLS (853) and DNS-over-HTTPS (RFC 8484). Works with Android Private DNS, Windows 11, and Firefox.

Network-Wide Blocking

Ads, trackers, malware, and phishing domains filtered by curated blocklists before they reach your devices.

Temporary Sandboxes

Spin up a private, self-expiring profile with its own filtering — no account, no email required.