Command Center
Live platform telemetry — traffic, threats, and edge health.
Real-Time Edge Traffic & Threat Stream
Live RPS breakdown across legitimate users vs. automated bot campaigns
7-Pillar WAAP Defense
Active mitigations across vectors
Auto-Discovery & Sensitivity Radar
Categorized API attack surface from live traffic
Compliance Posture
Automated regulatory policy coverage
Live Security Incident Feed & Analyst Adjudication
Real-time security events streamed from edge Envoy PoPs with 1-click dispute feedback
| Timestamp | Client IP | ASN / Source | Threat Signature | Target Endpoint | Escalation Action | Verdict | Adjudicate |
|---|
Bot & Fraud Intelligence (BAP)
Multi-layered client verification: Device Fingerprinting, JA4 TLS Signals, Proof-of-Work, and Hard Challenges.
BAP Tri-Check Sensor Engine
Verifies client hardware concurrency, screen depth, WebGL renderer, and touch event authenticity.
Sensor Health
Live BAP ingest verdicts per client (from /sensor/health).
Challenge Actions
Soft vs hard challenge + block decisions per client (from /sensor/health).
JA4 / JA4H Fingerprinting
Passive TLS Client Hello & HTTP header hash inspection. Detects Python, Go, and cURL scrapers.
| Fingerprint (JA4) | Status | Reason | Added |
|---|
Adaptive Challenges (PoW & CAPTCHA)
Invisible client-side SHA-256 Proof-of-Work soft challenges and Turnstile/hCaptcha fallback clearance tokens.
Interactive Hard Challenge CAPTCHA Sandbox
Test Turnstile/hCaptcha widgets and cryptographic HMAC clearance token generation live
wgc_<base64_payload>.<hmac_sha256_signature>
Asset & API Auto-Discovery Matrix
Continuous inventory of subdomains, endpoints, semantic contract diffs, and breaking changes.
| Method | Path Template | Sensitivity Tier | Risk | Exposure | Spec Source | Shadow API | Version | Challenge | Actions |
|---|
WAF, Policy Orchestration & Canary Engine
Configure sensitivity rules, rate limits, canary rollouts, and zero-trust service mesh access control.
Live Canary Deployment & SLO Auto-Rollback
Staged traffic shifting (25%) with automatic 0ms rollback on SLO breach
AI Model Feedback & Autonomous Self-Healing Pipeline
Continuous false-positive/negative learning loop with automatic canary policy mitigation and threshold tuning
Month-3 Operator-Wrapped Custom VM Tier & 3-Family Rotation
Polymorphic bytecode compiler with dynamic Fisher-Yates CFF permutations + Server-Side HMAC Boundary Tri-Check
Cryptographic PoW & Custom Micro-VM Benchmark Inspector
Direct side-by-side performance, AST deobfuscation resistance, and constant-time HMAC benchmark metrics
Zero-Trust Service Mesh & SPIFFE Identity Guard
East-west microservice authorization matrix and internal mTLS policy enforcement
| Target Microservice | SPIFFE Trust Domain Pattern | Authorized Callers | Permitted Methods | Restricted Paths |
|---|---|---|---|---|
payment_processor |
^spiffe://cluster\.local/ns/prod/sa/.*$ |
order_service checkout_ui | POST, GET |
/metrics /internal/admin |
user_auth_service |
^spiffe://cluster\.local/ns/auth/sa/.*$ |
api_gateway | POST |
/actuator/env |
Red-Team Chaos Adversary Emulation & Constant-Time Verifier
Automated AST deobfuscation attack probes, constant-time HMAC latency delta measurements, and high-concurrency race tests
Compliance & Regulatory Vault
One-click regulatory rule packs and tamper-evident audit evidence generator.
Developer Onboarding & Cryptographic Key Management
Instant 1-click client provisioning, API credentials, dynamic JIT sensor integration, and automated ACME TLS certificates.
Developer API Credentials & Sensor Token
Instant zero-friction API keys and polymorphic JIT sensor tokens for client applications and backend APIs.
client_mhoomaya_blog
wg_live_a820b75017481b01
https://dostlive.in/api/v1/sensor/v.js
Instant Domain Management & Protection Rules
Add your production domain for automatic Let's Encrypt TLS certificate provisioning and edge proxy routing.
30-Second Integration Snippet
Embed the lightweight client sensor into your website or web application in one step.
BAP CPS Sensor Key Pair
Ed25519 asymmetric key pair used by client-side SensorDataBuilder to sign telemetry payloads.
loading…
ACME TLS Certificates
Automated Let's Encrypt TLS certificate provisioning for Path A DNS proxying.
Enterprise Settings Dashboard
Professional grade controls for organization management, RBAC, advanced SSO, unified billing, and document synchronization.
Pricing
Setup
Role‑Based Access Control
Define and assign roles to users, view permissions matrix.
| Username | Name | Role | Created | Mode | KYC |
|---|
Advanced SSO Integrations
Configure SAML, OIDC providers, and manage federation settings.
Unified Billing
View subscription usage, invoices, and edit payment methods.
Document Sync
Create, edit, and synchronize policy documents across the organization.
SIEM & SOC Security Pipeline Connector
Stream real-time audit logs and threat telemetry to Splunk HEC, Datadog Logs, or Elastic Logstash.
Manager Console
Team, roles, and approvals for managers.
Team Members
Pending Approvals
My Access
Your role and what you can do.
My Role
My Permissions
My Client Status
Client Protection & Endpoint Rules Setup
Configure endpoint rate limits, challenge tiers, and inspection modes according to your client plan limits.
Client Endpoint Policies
Fine-tune per-route rate limits and challenge tiers. Write operations are clamped to your plan tier.
| Method | Path Template | Rate Limit (req/min) | Challenge Tier | Enforcement Mode | Actions |
|---|---|---|---|---|---|
| Loading client rules… | |||||
Client Policy Tester & Simulation
Verify how incoming client traffic is evaluated against your rate limits and challenges in real-time.
Admin Setup & System Settings
Global control plane configuration, dynamic feature flags, edge subsystem telemetry, and incident runbooks.
Dynamic Feature Flags
Hot-toggle real-time WAAP capabilities across edge proxies without restarts.
Cryptographic Key Vault & Zero-Downtime Secret Rotation
Ed25519 asymmetric signatures and SHA-256 HMAC secret lifecycle with 15-minute dual-key verification grace window
Edge PoP Subsystems & Failover
Real-time edge cluster status and sub-50ms zero-downtime geo-routing.
Automated Runbooks
Trigger automated incident playbooks and mitigation workflows.
Developer Docs
Endpoint reference for integrating with the WaapGuard control plane. Authenticated users only.
API Endpoint Reference
| Method | Endpoint | Description | Auth |
|---|
Quick Start
WaapGuard
Sign in to the control plane
Sign in with Google
Choose an account to continue to WaapGuard
Forensic Ingress Packet Inspector
Cryptographic boundary breakdown & JA4 TLS fingerprint telemetry