Command Center
Live platform telemetry — traffic, threats, and edge health.
Real-Time Edge Traffic & Threat Stream
Live RPS breakdown across legitimate users vs. automated bot campaigns
7-Pillar WAAP Defense
Active mitigations across vectors
Auto-Discovery & Sensitivity Radar
Categorized API attack surface from live traffic
Compliance Posture
Automated regulatory policy coverage
Live Security Incident Feed & Analyst Adjudication
Real-time security events streamed from edge Envoy PoPs with 1-click dispute feedback
| Timestamp | Client IP | ASN / Source | Threat Signature | Target Endpoint | Escalation Action | Verdict | Adjudicate |
|---|
Bot & Fraud Intelligence (BAP)
Multi-layered client verification: Device Fingerprinting, JA4 TLS Signals, Proof-of-Work, and Hard Challenges.
BAP Tri-Check Sensor Engine
Verifies client hardware concurrency, screen depth, WebGL renderer, and touch event authenticity.
Sensor Health
Live BAP ingest verdicts per client (from /sensor/health).
Challenge Actions
Soft vs hard challenge + block decisions per client (from /sensor/health).
JA4 / JA4H Fingerprinting
Passive TLS Client Hello & HTTP header hash inspection. Detects Python, Go, and cURL scrapers.
| Fingerprint (JA4) | Status | Reason | Added |
|---|
Adaptive Challenges (PoW & CAPTCHA)
Invisible client-side SHA-256 Proof-of-Work soft challenges and Turnstile/hCaptcha fallback clearance tokens.
Interactive Hard Challenge CAPTCHA Sandbox
Test Turnstile/hCaptcha widgets and cryptographic HMAC clearance token generation live
wgc_<base64_payload>.<hmac_sha256_signature>
Asset & API Auto-Discovery Matrix
Continuous inventory of subdomains, endpoints, semantic contract diffs, and breaking changes.
| Method | Path Template | Sensitivity Tier | Risk | Exposure | Spec Source | Shadow API | Version | Challenge | Actions |
|---|
WAF, Policy Orchestration & Canary Engine
Configure sensitivity rules, rate limits, canary rollouts, and zero-trust service mesh access control.
Live Canary Deployment & SLO Auto-Rollback
Staged traffic shifting (25%) with automatic 0ms rollback on SLO breach
Zero-Trust Service Mesh & SPIFFE Identity Guard
East-west microservice authorization matrix and internal mTLS policy enforcement
| Target Microservice | SPIFFE Trust Domain Pattern | Authorized Callers | Permitted Methods | Restricted Paths |
|---|---|---|---|---|
payment_processor |
^spiffe://cluster\.local/ns/prod/sa/.*$ |
order_service checkout_ui | POST, GET |
/metrics /internal/admin |
user_auth_service |
^spiffe://cluster\.local/ns/auth/sa/.*$ |
api_gateway | POST |
/actuator/env |
Compliance & Regulatory Vault
One-click regulatory rule packs and tamper-evident audit evidence generator.
Onboarding & Cryptographic Key Management
Manage DNS delegation verification, ACME certificates, and BAP CPS sensor key rotation.
Automated Domain Pilot Onboarding Wizard
Provision new customer domain with DNS TXT challenge verification and 7-day learning baseline
Add Domain to Client
Register additional domain for existing client. Optionally enable automatic TLS setup.
Low-KYC & Approval (Country-Wise)
Submit identity packet with country jurisdiction; admins/managers review & approve pending tasks with live sync.
Current Plan & Limits
Pending Approvals & Sync
BAP CPS Sensor Key Pair
Ed25519 asymmetric key pair used by client-side SensorDataBuilder to sign telemetry payloads.
loading…
ACME TLS Certificates
Automated Let's Encrypt TLS certificate provisioning for Path A DNS proxying.
Enterprise Settings Dashboard
Professional grade controls for organization management, RBAC, advanced SSO, unified billing, and document synchronization.
Pricing
Setup
Role‑Based Access Control
Define and assign roles to users, view permissions matrix.
| Username | Name | Role | Created | Mode | KYC |
|---|
Advanced SSO Integrations
Configure SAML, OIDC providers, and manage federation settings.
Unified Billing
View subscription usage, invoices, and edit payment methods.
Document Sync
Create, edit, and synchronize policy documents across the organization.
Manager Console
Team, roles, and approvals for managers.
Team Members
Pending Approvals
My Access
Your role and what you can do.
My Role
My Permissions
My Client Status
Client Protection & Endpoint Rules Setup
Configure endpoint rate limits, challenge tiers, and inspection modes according to your client plan limits.
Client Endpoint Policies
Fine-tune per-route rate limits and challenge tiers. Write operations are clamped to your plan tier.
| Method | Path Template | Rate Limit (req/min) | Challenge Tier | Enforcement Mode | Actions |
|---|---|---|---|---|---|
| Loading client rules… | |||||
Client Policy Tester & Simulation
Verify how incoming client traffic is evaluated against your rate limits and challenges in real-time.
Admin Setup & System Settings
Global control plane configuration, dynamic feature flags, edge subsystem telemetry, and incident runbooks.
Dynamic Feature Flags
Hot-toggle real-time WAAP capabilities across edge proxies without restarts.
Edge PoP Subsystems
Real-time edge cluster status and latency.
Automated Runbooks
Trigger automated incident playbooks and mitigation workflows.
Developer Docs
Endpoint reference for integrating with the WaapGuard control plane. Authenticated users only.
API Endpoint Reference
| Method | Endpoint | Description | Auth |
|---|