Decision and identity
Every login, API call and sensitive action gets a project-scoped allow, review, step-up or deny decision.
- Adaptive risk scoring
- Zero-trust service identities
- Signed agent identity
Free security check
Check a website or API address with one passive request. Shield reads only transport, reachability and visible response headers, then suggests a suitable starting package.
Free public check
Enter an HTTPS or HTTP address. Shield performs one short, passive request and checks transport, reachability and security headers – free of charge and without login.
Shield capability map
Shield combines everyday application controls with newer containment and learning safeguards. Availability is shown honestly: F.A.M.O.U.S. is an optional operational layer and does not replace the core decision API.
Every login, API call and sensitive action gets a project-scoped allow, review, step-up or deny decision.
Untrusted agent content, prompt injection, tool boundaries and worm-like fan-out are contained before propagation.
Security rules stay versioned, reviewable and reversible, with controlled recovery paths when an incident is detected.
Decisions remain traceable without publishing customer data. Append-only evidence and webhook controls support safe operations.
The fixed worker layer can provide health, drift, incident and daily reporting checks when the connected worker is available.
Shield never promises invulnerability. Public checks and product pages show orientation only; admin events, tenant data and raw attack artifacts stay private.