Invisible to Bots. Clear to Humans.
The Obsidian Layer randomizes CSS classes and injects invisible noise into text, making your data un-scrapable while remaining readable.
The decentralized application firewall. AuraGuardian injects heuristic defense directly into your runtime, blocking bots with 0ms latency.
The Obsidian Layer randomizes CSS classes and injects invisible noise into text, making your data un-scrapable while remaining readable.
PHP, Node, Python, and WordPress agents share the same additive risk-scoring engine and graduated response system.
Additive 0 to 100 risk scoring with 5-tier graduated response: Allow, Slow, Challenge, Decoy, Block. Each threshold is tuned per policy.
Traditional firewalls are isolated. AuraGuardian is connected. When a single node detects a threat, the signature is broadcast to the entire network in 60 seconds.
Block entire regions, flip defense modes on or off, and watch threats drop in real time, all from a single console that pushes changes to every node in seconds.
Region-based access control.
Active heuristic analysis.
Real-time threat inspection.
Six inspection stages run on every request, from TLS handshake to application logic, blocking threats before they reach your code.
Rules enforce from local cache while background sync pulls the latest policy. Zero latency overhead, zero stale windows.
Extracts JA3/JA4 hashes from TLS handshakes to identify headless browsers and scripted clients spoofing legitimate User-Agents.
Cross-checks Origin, Referer, and Host headers against expected request chains. Mismatches flag spoofed or replayed requests instantly.
Resolves PTR records to classify source infrastructure: data centers, VPN endpoints, and residential proxies each get separate enforcement policies.
When CDN geo-headers are absent, a local CIDR lookup with 24-hour TTL maps IPs to countries, keeping geo-fencing rules active on any host.
Tracks per-session request cadence, form submission timing, and endpoint access sequences to separate credential-stuffing bots from real users.
Deploy as a single-file runtime agent, Composer package, npm module, or CMS plugin. No DNS changes. No reverse proxy. Pure runtime control.
$ composer require auraprotector/agent
$ npm i @auraprotector/agent
$ pip install auraprotector-agent
$ wp plugin install auraprotector --activate
<!-- Add to theme.liquid --> <script src="https://auraguardian.co/agent/shopify/v1.js" data-ag-key="UP_LIVE_..." defer></script>
Drop a single file into your application root or install via your package manager. The agent auto-detects the runtime environment and applies the correct hooks. No configuration files required.
Rules are AES-256 encrypted in transit and cached locally with stale-while-revalidate. Policy updates propagate across all agents within seconds. No restarts, no downtime.
Start in observe mode to audit traffic patterns and review logs. Switch to active enforcement once you've validated the policy. One toggle, zero code changes.
Use the same license key, telemetry pipeline, and threat intelligence across PHP, Node, Python, WordPress, and Shopify. One policy model governs all runtimes.
The controls are grouped by how teams deploy, observe, enforce, and maintain runtime protection.
Simple, predictable pricing. No hidden fees, no surprise invoices.
Basic protection for personal projects.
Full defense stack for your sites — WAF, geo-blocking, bot challenges included.
More domains, deeper rules, and AI-powered threat intel for production traffic.
Dedicated nodes, custom WAF rules, SLA-backed support, and full platform access.
Start with one runtime, watch the logs, tune the rules, then carry the same policy model across PHP, Node, Python, WordPress, and Shopify.