Edgion Shield
Index

Living Aegis Atlas / live attack simulation

The edge should show its work.

Edgion Shield observes, classifies, and intercepts at an edge you own—then exposes the protection trace without exposing the people behind it.

Self-hosted control plane · no card to start · AI off by default
Representative simulation of global edge protectionA hand-plotted atlas simulates scan, flood, inject, and spam tempos toward the Edgion shield, measures DNS pressure, and shows protected egress.EDGECONTROLORIGINDNS PRESSURE / MEASURED
REQUEST RATE1,180req/s
INTERCEPTED260/min
EDGE P9534ms
Representative live simulation
Inspect trace WAF / DNS / p95 / topology
Observed
1,180 requests/s
Classified
13K DNS observations
Challenged
17% DNS blocked
Blocked / passed
260 intercepted/min
  1. edgehealthy
  2. controlhealthy
  3. dnshealthy
  4. originhealthy
Global protection tempo built from real cross-account traffic, scaled for privacy and shown only as aggregate rates and per-country attack intensity — no IP, domain, path, tenant, host, or raw count is exposed. Falls back to a representative simulation whenever the aggregate is unavailable.

Instrument plates

Four attack tempos on one field.

Each plate runs a continuous plotter simulation — scan crawls, flood rushes, spam taps the reject mark, mail and DNS keep their own pulse.

Web edge / WAFIntercept

Scan, flood, and inject arrive on different tempos. Packets die on the compass ring; clean egress leaves steady.

Spam / mail abuseRejected

Abuse traffic crawls toward the reject mark. The X taps on a slow pulse — drop, not explosion.

Authenticated sendPassed

Authenticated mail rides a slower, steadier tempo through SPF → DKIM → DMARC.

DNS pressureMeasured

DNS sweeps on its own cadence while flood and inject pressure meet the filter ticks.

Protection path

One request. Four accountable stages.

No decorative pipeline. This is the order used to explain a decision: what arrived, how it was classified, which boundary challenged it, and whether it passed.

  1. Observed

    Request and DNS pressure enter the edge.

    Measurements are taken before a verdict, with customer telemetry retained inside the customer boundary.

  2. Classified

    Signals become an evidence set.

    WAF rules, rate shape, topology health, and deterministic adaptive policy produce inspectable references.

  3. Challenged

    Uncertainty meets a measured boundary.

    Suspicious traffic can be challenged or constrained without turning every visitor into collateral damage.

  4. Blocked / passed

    The origin receives an explicit outcome.

    Protection wins are applied at the edge; healthy traffic continues through TLS and origin routing.

Instrument register

A control plane, not a vendor collage.

Each instrument writes to the same operating model and audit trail.

InstrumentFunctionEvidence
Web edge
Classify and intercept

Deep request inspection, adaptive scoring, challenges, rate limits

Authoritative DNS
Publish and measure

DNSSEC, health-aware records, controlled delegation

Transport
Terminate and route

Automatic TLS, reverse proxy, network streams, cache policy

Mail
Authenticate and deliver

SPF, DKIM, DMARC, send-safety policy

Private analytics
Retain and explain

First-party event history under your retention policy

The AI acts only within limits you set

Useful because it cannot do everything.

The model proposes a closed action ID. Edgion validates the evidence, the actor, the delegation, and the current policy before anything can change.

A failed model, stale telemetry, expired delegation, or revoked tenant permission produces no execution.

OBSERVE

Explain the pattern.

Read-only aggregate analysis with evidence references. No configuration changes.

RECOMMEND

Prepare a reversible action.

Before, after, risk, expected effect, and rollback—then an owner or administrator decides.

AUTOPILOT / DELEGATED

Raise protection temporarily.

Only allow-listed actions, only inside scope, only until the overlay expires. It never writes the base policy.

Outside the boundary: DNS, TLS, origins, accounts, permissions, billing, data deletion, allow/deny lists, Geo/ASN, shell, SQL, or arbitrary HTTP.

Public by proof, private by construction

If the crowd is too small, the instrument goes quiet.

120 seconds
Minimum delay before a snapshot can become public.
5 accounts
Minimum contributors to the global aggregate.
3 + 5
Accounts and unique visitors required for a country cell.
≤ 50%
Maximum contribution from one customer before suppression.
0 identifiers
No IP, domain, path, tenant, agent, origin, rule, hash, error, or log.

Field questions

Read the margin before you trust the plate.

Does the public atlas expose customer traffic?

No. The browser never receives internal telemetry. The public endpoint emits one delayed global aggregate only after contributor, visitor, and dominance thresholds pass. Suppressed data stays suppressed.

Does AI control the edge by itself?

Not by default. Observe explains. Recommend prepares a bounded action for an owner or administrator. Autopilot can apply only approved, temporary, protection-raising overlays inside an active delegation.

What happens when AI or telemetry is unavailable?

Execution fails closed. The base policy and deterministic protections remain active; the public atlas shows an explicit unavailable state instead of invented data.

Is Free less secure than Pro?

No. Published plans share the same protection capabilities. Capacity, history, and operational limits change with scale; the security baseline does not.

Do I have to host Edgion Shield myself?

Yes. The control plane and edge run on infrastructure you operate. That ownership boundary is the product, not an implementation detail.

Control is the product.

Own the edge.
Keep the evidence.

Start with the full protection baseline