Scan, flood, and inject arrive on different tempos. Packets die on the compass ring; clean egress leaves steady.
Living Aegis Atlas / live attack simulation
The edge should show its work.
Edgion Shield observes, classifies, and intercepts at an edge you own—then exposes the protection trace without exposing the people behind it.
Self-hosted control plane · no card to start · AI off by defaultInspect trace WAF / DNS / p95 / topology
- Observed
- 1,180 requests/s
- Classified
- 13K DNS observations
- Challenged
- 17% DNS blocked
- Blocked / passed
- 260 intercepted/min
- edgehealthy
- controlhealthy
- dnshealthy
- originhealthy
Instrument plates
Four attack tempos on one field.
Each plate runs a continuous plotter simulation — scan crawls, flood rushes, spam taps the reject mark, mail and DNS keep their own pulse.
Abuse traffic crawls toward the reject mark. The X taps on a slow pulse — drop, not explosion.
Authenticated mail rides a slower, steadier tempo through SPF → DKIM → DMARC.
DNS sweeps on its own cadence while flood and inject pressure meet the filter ticks.
Protection path
One request. Four accountable stages.
No decorative pipeline. This is the order used to explain a decision: what arrived, how it was classified, which boundary challenged it, and whether it passed.
- Observed
Request and DNS pressure enter the edge.
Measurements are taken before a verdict, with customer telemetry retained inside the customer boundary.
- Classified
Signals become an evidence set.
WAF rules, rate shape, topology health, and deterministic adaptive policy produce inspectable references.
- Challenged
Uncertainty meets a measured boundary.
Suspicious traffic can be challenged or constrained without turning every visitor into collateral damage.
- Blocked / passed
The origin receives an explicit outcome.
Protection wins are applied at the edge; healthy traffic continues through TLS and origin routing.
Instrument register
A control plane, not a vendor collage.
Each instrument writes to the same operating model and audit trail.
Deep request inspection, adaptive scoring, challenges, rate limits
DNSSEC, health-aware records, controlled delegation
Automatic TLS, reverse proxy, network streams, cache policy
SPF, DKIM, DMARC, send-safety policy
First-party event history under your retention policy
Public by proof, private by construction
If the crowd is too small, the instrument goes quiet.
- 120 seconds
- Minimum delay before a snapshot can become public.
- 5 accounts
- Minimum contributors to the global aggregate.
- 3 + 5
- Accounts and unique visitors required for a country cell.
- ≤ 50%
- Maximum contribution from one customer before suppression.
- 0 identifiers
- No IP, domain, path, tenant, agent, origin, rule, hash, error, or log.
Field questions
Read the margin before you trust the plate.
Does the public atlas expose customer traffic?
No. The browser never receives internal telemetry. The public endpoint emits one delayed global aggregate only after contributor, visitor, and dominance thresholds pass. Suppressed data stays suppressed.
Does AI control the edge by itself?
Not by default. Observe explains. Recommend prepares a bounded action for an owner or administrator. Autopilot can apply only approved, temporary, protection-raising overlays inside an active delegation.
What happens when AI or telemetry is unavailable?
Execution fails closed. The base policy and deterministic protections remain active; the public atlas shows an explicit unavailable state instead of invented data.
Is Free less secure than Pro?
No. Published plans share the same protection capabilities. Capacity, history, and operational limits change with scale; the security baseline does not.
Do I have to host Edgion Shield myself?
Yes. The control plane and edge run on infrastructure you operate. That ownership boundary is the product, not an implementation detail.