12 Edge PoPs Active (3.2ms)
Monitor-Only Mode

Command Center

Live platform telemetry — traffic, threats, and edge health.

24h Inspected Traffic
38.42M reqs
4,250 RPS peak
Blocked Threats (24h)
241,890 blocked
16% malicious bot traffic
BAP Validation Rate
99.8%
Ed25519 CPS Verified
P99 Edge Latency
3.2 ms
Target: <5.0ms
Global Autonomous Edge Protection Active · 12 PoPs Synchronized
Month-3 Custom VM Rotation · Zero-Downtime HMAC Boundary Tri-Check · Sub-4ms Micro-PoW Soft Challenges

Real-Time Edge Traffic & Threat Stream

Live RPS breakdown across legitimate users vs. automated bot campaigns

Real Users Blocked Bot Attacks

7-Pillar WAAP Defense

Active mitigations across vectors

Headless Browser Farms Active Block
38.4M
Credential Stuffing K-Anonymity Guard
22,067
BOLA / ID Scraping PoW Soft Challenge
38,670
JA4 Fingerprint Spoofs 99.8% Caught
14,920

Auto-Discovery & Sensitivity Radar

Categorized API attack surface from live traffic

3 Shadow APIs Detected
Public
180 endpoints
Auth
92 endpoints
Admin
85 endpoints
Payment
44 endpoints
PII
8 endpoints

Compliance Posture

Automated regulatory policy coverage

96%
COMPLIANT
OWASP API Top 10 PCI DSS 4.0 GDPR Art. 32 HIPAA Audit

Live Security Incident Feed & Analyst Adjudication

Real-time security events streamed from edge Envoy PoPs with 1-click dispute feedback

Timestamp Client IP ASN / Source Threat Signature Target Endpoint Escalation Action Verdict Adjudicate

Bot & Fraud Intelligence (BAP)

Multi-layered client verification: Device Fingerprinting, JA4 TLS Signals, Proof-of-Work, and Hard Challenges.

BAP Tri-Check Sensor Engine

Verifies client hardware concurrency, screen depth, WebGL renderer, and touch event authenticity.

Headless Chromium DetectionARMED
AudioContext Fingerprint CheckARMED
Touch Event Timing VarianceARMED

Sensor Health

Live BAP ingest verdicts per client (from /sensor/health).

Last ingest
Total ingests0
Blocked0

Challenge Actions

Soft vs hard challenge + block decisions per client (from /sensor/health).

Soft challenge (PoW)0
Hard challenge (JS/CAPTCHA)0
Block (403)0
Geo/ASN verdicts

JA4 / JA4H Fingerprinting

Passive TLS Client Hello & HTTP header hash inspection. Detects Python, Go, and cURL scrapers.

Known Bad JA4 Blocklist38,400 Signatures
Cipher Suite Order AnalysisARMED
TLS Extension Anomaly DetectorARMED
Fingerprint (JA4)StatusReasonAdded

Adaptive Challenges (PoW & CAPTCHA)

Invisible client-side SHA-256 Proof-of-Work soft challenges and Turnstile/hCaptcha fallback clearance tokens.

Soft Challenge (Invisible PoW)Tier 1 Active
Hard Challenge (HMAC Token)Tier 2 Active
GoodBot rDNS ValidatorGoogle/Bing Verified

Interactive Hard Challenge CAPTCHA Sandbox

Test Turnstile/hCaptcha widgets and cryptographic HMAC clearance token generation live

Clearance Token Protocol: wgc_<base64_payload>.<hmac_sha256_signature>

Asset & API Auto-Discovery Matrix

Continuous inventory of subdomains, endpoints, semantic contract diffs, and breaking changes.

Method Path Template Sensitivity Tier Risk Exposure Spec Source Shadow API Version Challenge Actions

WAF, Policy Orchestration & Canary Engine

Configure sensitivity rules, rate limits, canary rollouts, and zero-trust service mesh access control.

Live Canary Deployment & SLO Auto-Rollback

Staged traffic shifting (25%) with automatic 0ms rollback on SLO breach

Target Version:
v2.5.0-waf-rules
Current Traffic Split:
25% Canary / 75% Base
Canary Error Rate:
0.04% (SLO limit 2.0%)

AI Model Feedback & Autonomous Self-Healing Pipeline

Continuous false-positive/negative learning loop with automatic canary policy mitigation and threshold tuning

Precision Score:
99.8%
Recall Rate:
100.0%
False Positive Rate (FPR):
0.02%
Automated Remediation:
ACTIVE · READY

Month-3 Operator-Wrapped Custom VM Tier & 3-Family Rotation

Polymorphic bytecode compiler with dynamic Fisher-Yates CFF permutations + Server-Side HMAC Boundary Tri-Check

Active Bytecode Architecture:
ALPHA (5-Register micro-VM)
Arithmetic lambda wrappers (_add, _sub)
Client AST Deobfuscation Shield:
CFF State Machine
Fisher-Yates dynamic execution ordering
Server-Side Boundary Truth:
Timing-Safe HMAC Tri-Check
crypto.timingSafeEqual + Nonce Replay Cache
BYTECODE INSTRUCTION PIPELINE & REGISTER TOPOLOGY EXECUTION ENTROPY: 9.98 / 10.00

Cryptographic PoW & Custom Micro-VM Benchmark Inspector

Direct side-by-side performance, AST deobfuscation resistance, and constant-time HMAC benchmark metrics

Client Micro-PoW Latency:
3.8 ms
vs 4000ms CAPTCHA friction
AST Deobfuscation Defense:
100% Entropy
Static AST pattern match: 0%
HMAC Constant-Time Delta:
0.038 ms
Immune to side-channel leaks
Server HMAC Check Time:
0.12 ms
Sub-millisecond verification

Zero-Trust Service Mesh & SPIFFE Identity Guard

East-west microservice authorization matrix and internal mTLS policy enforcement

Target Microservice SPIFFE Trust Domain Pattern Authorized Callers Permitted Methods Restricted Paths
payment_processor ^spiffe://cluster\.local/ns/prod/sa/.*$ order_service checkout_ui POST, GET /metrics /internal/admin
user_auth_service ^spiffe://cluster\.local/ns/auth/sa/.*$ api_gateway POST /actuator/env

Red-Team Chaos Adversary Emulation & Constant-Time Verifier

Automated AST deobfuscation attack probes, constant-time HMAC latency delta measurements, and high-concurrency race tests

Stage 1: AST Deobfuscation
BLOCKED (100% Entropy)
Lambda wrappers + CFF state machine
Stage 2: Constant-Time HMAC
PASS (Delta: 0.038ms)
crypto.timingSafeEqual < 0.2ms limit
Stage 3: 100-Req Race Replay
99/100 DROPPED (403)
Atomic single-use replay cache
Stage 4: VM Polymorphic JIT
99.98% Entropy
Rotates Alpha/Beta/Gamma

Compliance & Regulatory Vault

One-click regulatory rule packs and tamper-evident audit evidence generator.

Developer Onboarding & Cryptographic Key Management

Instant 1-click client provisioning, API credentials, dynamic JIT sensor integration, and automated ACME TLS certificates.

Developer API Credentials & Sensor Token

Instant zero-friction API keys and polymorphic JIT sensor tokens for client applications and backend APIs.

Instant Verified
Client ID
client_mhoomaya_blog
API Secret Key
wg_live_a820b75017481b01
JIT Sensor Stream URL
https://dostlive.in/api/v1/sensor/v.js

Instant Domain Management & Protection Rules

Add your production domain for automatic Let's Encrypt TLS certificate provisioning and edge proxy routing.

Scans discovered inventory and seeds active WAF & PoW rules instantly.
Loading plan…

30-Second Integration Snippet

Embed the lightweight client sensor into your website or web application in one step.

<!-- Include in <head> or before </body> of your HTML --> <script src="https://dostlive.in/api/v1/sensor/v.js" async></script>

BAP CPS Sensor Key Pair

Ed25519 asymmetric key pair used by client-side SensorDataBuilder to sign telemetry payloads.

Public Key Fingerprint (CPS Registry): loading…

ACME TLS Certificates

Automated Let's Encrypt TLS certificate provisioning for Path A DNS proxying.

Loading…

Enterprise Settings Dashboard

Professional grade controls for organization management, RBAC, advanced SSO, unified billing, and document synchronization.

Enterprise Settings
Loading…

Pricing

Setup

Loading…

Role‑Based Access Control

Define and assign roles to users, view permissions matrix.

UsernameNameRoleCreatedModeKYC

Advanced SSO Integrations

Configure SAML, OIDC providers, and manage federation settings.

Unified Billing

View subscription usage, invoices, and edit payment methods.

Document Sync

Create, edit, and synchronize policy documents across the organization.

SIEM & SOC Security Pipeline Connector

Stream real-time audit logs and threat telemetry to Splunk HEC, Datadog Logs, or Elastic Logstash.

Manager Console

Team, roles, and approvals for managers.

Team Members

Loading…

Pending Approvals

Loading…

My Access

Your role and what you can do.

My Role

Loading…

My Permissions

Loading…

My Client Status

Loading…

Client Protection & Endpoint Rules Setup

Configure endpoint rate limits, challenge tiers, and inspection modes according to your client plan limits.

Client Plan & Enforcement Policy
Client Default · Free Plan
Max Endpoints: 25
Rate Limit Cap: 60 req/min
Challenges: PoW / Soft

Client Endpoint Policies

Fine-tune per-route rate limits and challenge tiers. Write operations are clamped to your plan tier.

Method Path Template Rate Limit (req/min) Challenge Tier Enforcement Mode Actions
Loading client rules…

Client Policy Tester & Simulation

Verify how incoming client traffic is evaluated against your rate limits and challenges in real-time.

Admin Setup & System Settings

Global control plane configuration, dynamic feature flags, edge subsystem telemetry, and incident runbooks.

Dynamic Feature Flags

Hot-toggle real-time WAAP capabilities across edge proxies without restarts.

Loading flags…

Cryptographic Key Vault & Zero-Downtime Secret Rotation

Ed25519 asymmetric signatures and SHA-256 HMAC secret lifecycle with 15-minute dual-key verification grace window

Active Client ID:
client_default
Scoped Role: operator
Verification Grace Window:
15 Minutes Dual-Key
0 dropped requests during rollout
Server Boundary Tri-Check:
HMAC SHA-256
crypto.timingSafeEqual

Edge PoP Subsystems & Failover

Real-time edge cluster status and sub-50ms zero-downtime geo-routing.

ap-south-1 (Mumbai Primary) 1.8ms · 2850 RPS
ap-southeast-1 (Singapore Proxy) 24.2ms · 680 RPS
us-east-1 (N. Virginia Control) 142.1ms · 420 RPS
eu-central-1 (Frankfurt GDPR) 118.4ms · 310 RPS

Automated Runbooks

Trigger automated incident playbooks and mitigation workflows.

Developer Docs

Endpoint reference for integrating with the WaapGuard control plane. Authenticated users only.

API Endpoint Reference

Snippets:
MethodEndpointDescriptionAuth

Quick Start

Your OpenAPI Spec
Loading…