Web protection and service resilience

We tell you which threats can actually reach your website, stop attacks with measures you can undo, and keep your site useful for visitors even during an incident.

Your visitors keep a short, fast path. The heavy analysis runs to the side, where it can never make them wait.

  • Local edge decisions
  • Parallel analysis
  • Verified rollback
LIVE REQUEST PULSE--:--:--
    advisories synchronized
    requests observed in 24h

    Counters are live platform data. Request lines are illustrative: AegiFlow never publishes customer request contents.

    OPERATIONAL NETWORKIllustrative flow, no customer data
    NORMAL TRAFFICRequests are inspected locally and delivered without waiting for deep analysis.Fast path: global edge → AegiFlow Edge → origin
    1. Visitor traffic enters through the global edge.
    2. The AegiFlow Edge makes local request decisions.
    3. Telemetry is analyzed asynchronously by Threat Radar and live cases.
    4. Static Continuity can replace an isolated origin.
    5. Recovery returns traffic gradually after business checks pass.
    01How protection starts
    01

    From adding a domain to protection you can measure.

    At every stage you see who acts, what changes, how we check the result and how to go back if you want to.

    1. 01

      Create account

      Your team and permissions are set up separately from the traffic we protect.

    2. 02

      Verify domain

      A short record in your DNS proves the website is really yours.

    3. 03

      Observe

      We measure your traffic and test rules without blocking a single visitor.

    4. 04

      Activate safely

      The certificate, your server, the health checks and the way back must all be ready first.

    Open the complete onboarding flow
    02

    A scary headline becomes a clear yes or no.

    We compare each published vulnerability with the exact software versions your site runs. If we cannot tell, we say Unknown — we never round it up to «you are safe».

    Explore Threat Radar
    Protection statusIn observation
    CRITICAL
    Relevant WordPress vulnerabilityExact package and version match
    97%
    shop.exampleAffectedUpdate required
    portal.exampleControl installedLast verified 8 min ago
    api.exampleUnknownInventory is stale

    Example data. A protected state requires current inventory and verification evidence.

    03

    Your site stays fast. The deep analysis happens elsewhere.

    A visitor never waits for our database, our threat feeds, our AI or our dashboard. If any of them slows down, your website does not.

    SYNCHRONOUS REQUEST PATH
    CloudflareEnvoyCorazaOrigin
    Bounded local controls only
    ASYNCHRONOUS OPERATIONS
    TelemetryCasesThreat matchEvidence
    Sampling is reduced before traffic is affected
    See the performance architecture
    CASE-0041Action required

    Credential stuffing contained on /login

    Scope
    1 route · 7 fingerprints
    TTL
    15 min
    Health checks
    Passing
    Rollback
    Ready
    Illustrative case. Controls are disabled on the public site.
    04

    Nothing we switch on is permanent.

    A measure is first tested without blocking anyone. When it does go live, it covers only named pages, expires by itself, and can be undone in one click.

    Review reversible response
    05

    Stay useful during the incident, come back carefully after it.

    While your server is isolated, visitors still see the pages you approved in advance. Traffic then returns in small steps, and only while the important things keep working.

    Signed continuityOnly pages you approved
    Business checksHomepage, sign-in, ordering
    Traffic returns in steps1% → 5% → 25% → 50% → 100%
    06

    Five ways to connect, one place to operate.

    Pick how deeply AegiFlow sits in front of your website.

    Global Edge

    Cloudflare for SaaS provides global ingress; AegiFlow adds service context.

    Needs configuration

    Native Edge

    Envoy and Coraza apply provider-neutral controls close to the origin.

    In observation

    Hybrid Resilience

    Global and native paths share the same safety contract and evidence.

    Planned

    Observe Only

    Inventory, availability and threat relevance without traffic enforcement.

    Available

    Monitoring only

    Nothing points at us and nothing is installed. We check the domain from the outside: TLS and headers, certificates as they are issued, email authentication, look-alike names, and the pages you say must keep working.

    Available
    07

    A green tick means nothing without a recent check behind it.

    You always see when each piece of information was last confirmed. If a check has not run recently, we show Unknown instead of leaving a comfortable green.

    Open the Trust Center
    Capability stateAvailable, observing, degraded or unavailable
    Protection PassportInventory, control and verification freshness
    Evidence receiptsHash, release, decision and result
    Explain this stateOwner, next action, verification and rollback
    +

    The whole platform, at a glance.

    Every capability is labeled with its real operating state — including the ones still in observation.

    INVENTORY → ADVISORY MATCH8 components
    CMS coreversion on file
    e-commerceversion on file
    page builderversion on file
    PHP runtimeversion on file
    web serverversion on file
    upload libraryversion on file
    cacheversion on file
    TLS libraryversion on file
    CVE-2019-19576CRITICALEPSS 26.2%

    Real advisory from our public database: affects verot/class.upload.php < 1.0.3, fixed in 1.0.3. AegiFlow compares it with the version each service actually runs.

    1 AFFECTED6 CLEAR1 UNKNOWN
    Open this advisory →

    The advisory is real and verifiable. The component list is an example: a clean verdict requires current inventory, and anything unproven stays Unknown.

    Threat Radar matches every advisory against the exact software inventory of your service.
    ACTIVE

    Threat Radar

    Over 16,000 advisories normalized from public sources, matched against your exact inventory.

    SHADOW

    Edge inspection

    Envoy and Coraza observe every request out of process, without delaying visitors.

    AVAILABLE

    Cases & reversible response

    Correlated incidents with one timeline; every control keeps a TTL and a tested way back.

    AVAILABLE

    Static Continuity

    Signed bundles keep approved public content available while the origin is isolated.

    AVAILABLE

    Verified recovery

    Recovery is exercised with drills and receipts — never assumed from a green light.

    START WITH OBSERVATION

    Add one domain. Nothing changes for your visitors until you decide.

    We walk you through proving the domain, connecting your server, the certificate and the way back — before anything is switched on.

    Add a domainRead the setup guide