Web Resilience Control Plane

See which threats can actually reach your service, prepare measures you can undo, and verify that critical journeys remain useful during an incident.

Cloudflare supplies global ingress. AegiFlow adds service context, bounded response, continuity, recovery checks and evidence without putting deep analysis in the visitor's critical path.

  • Lokale Edge-Entscheidungen
  • Parallele Analyse
  • Rollback before action
ILLUSTRATIVE REQUEST PULSE--:--:--
Advisories synchronisiert
Anfragen in 24 h beobachtet

Counters appear only from a fresh, fully validated public snapshot. Request lines are illustrative: AegiFlow never publishes customer request contents.

OPERATIONAL NETWORKIllustrative flow, no customer data
ILLUSTRATIVE NORMAL FLOWThis scenario shows requests inspected locally and delivered without waiting for deep analysis.Illustrative path: global edge → AegiFlow Edge → origin
  1. Visitor traffic enters through the global edge.
  2. The AegiFlow Edge makes local request decisions.
  3. Telemetry is analyzed asynchronously by Threat Radar and live cases.
  4. Static Continuity can replace an isolated origin.
  5. Recovery returns traffic gradually after business checks pass.
01Current verified state

GoTe now

GoTe nowGoTePrivate beta · operator-assisted
Traffic
Checking current route
Protection
Unknown
Runtime
Unknown
Scope
Not verifiable
Traffic proof until
Not verifiable

Current state is shown only after a fresh, schema-validated snapshot is loaded.

Open status evidence
01

From domain to measured protection.

Every stage explains who acts, what changes, how AegiFlow verifies the result and how to return safely.

  1. 01

    Konto erstellen

    Organization and roles are kept separate from protected traffic.

  2. 02

    Verify domain

    A DNS proof confirms that the service is authorized.

  3. 03

    Analyse safely

    AegiFlow measures compatibility without blocking visitors.

  4. 04

    Activate safely

    Certificate, origin, health checks and rollback must all pass.

Open the complete onboarding flow
02

A new vulnerability becomes a clear answer.

AegiFlow connects advisories to the exact software inventory of each service. Unknown evidence stays unknown; it is never presented as safe.

Explore Threat Radar
Protection statusAnalysis only
CRITICAL
Relevant WordPress vulnerabilityExact package and version match
97%
shop.exampleAffectedUpdate required
portal.exampleControl installedLast verified 8 min ago
api.exampleUnknownInventory is stale

Example data. A protected state requires current inventory and verification evidence.

03

Fast traffic. Deep analysis in parallel.

Databases, threat feeds, assisted analysis and the dashboard are never dependencies of the visitor request.

SYNCHRONOUS REQUEST PATH
CloudflareEnvoyCorazaOrigin
Bounded local controls only
ASYNCHRONOUS OPERATIONS
TelemetryCasesThreat matchEvidence
Sampling is reduced before traffic is affected
See the performance architecture
CASE-0041Action required

Credential stuffing contained on /login

Scope
1 route · 7 fingerprints
TTL
15 min
Health checks
Passing
Rollback
Ready
Illustrative case. Controls are disabled on the public site.
04

Automation has a scope, a clock and a way back.

Candidate controls run without blocking first. Canary checks, a short time window and explicit rollback precede active blocking.

Review reversible response
05

Keep the service useful, then recover deliberately.

AegiFlow builds signed copies of approved public content. Independent activation and business-journey recovery remain explicit checks before production use.

Signed continuityApproved pages only
Business checksHomepage, public catalog, API health
Target recovery stagesPlanned: 1% → 5% → 25% → 50% → 100%
06

One control plane. Four integration modes.

Choose the operating boundary that fits the service.

Global Edge

Cloudflare for SaaS provides global ingress; AegiFlow adds service context.

Platform · implemented

Native Edge

Independent native ingress and a second edge provider remain planned.

Platform · planned

Hybrid Resilience

Global and native paths share the same safety contract and evidence.

Platform · planned

Monitor only

Inventory, availability and threat relevance without changing or blocking traffic.

Platform · implemented
07

A state is credible only when the evidence is recent.

Capability state, inventory freshness, applied controls and recovery results remain explicit. A missing check becomes Unknown, never a green status.

Open the Trust Center
Capability truthDelivery stage and runtime health are independent
Service PassportInventory, control and verification freshness
Evidence receiptsHash, release, decision and result
Explain this stateOwner, next action, verification and rollback
+

The whole platform, at a glance.

These cards define platform scope. The current GoTe state, scope and freshness come only from the validated snapshot above.

INVENTORY → ADVISORY MATCH8 components
CMS coreversion on file
e-commerceversion on file
page builderversion on file
PHP runtimeversion on file
web serverversion on file
upload libraryversion on file
cacheversion on file
TLS libraryversion on file
CVE-2019-19576CRITICALEPSS 26.2%

Real advisory from our public database: affects verot/class.upload.php < 1.0.3, fixed in 1.0.3. AegiFlow compares it with the version each service actually runs.

1 AFFECTED6 CLEAR1 UNKNOWN
Open this advisory →

The advisory fields are a dated public reference (2026-07-31). The component list and verdicts are illustrative: a clean verdict requires current inventory, and anything unproven stays Unknown.

Illustrative inventory match. A clean verdict requires current, verified software evidence.
PLATFORM CAPABILITY

Threat Radar

Configured public advisory sources are normalized and matched against exact inventory; the current count is loaded from the public snapshot.

PLATFORM CAPABILITY

Edge inspection

Envoy routes requests while Coraza inspects them out of process on the request path, with bounded timeouts and analysis before blocking.

PLATFORM CAPABILITY

Cases & reversible response

Correlated incidents share one timeline; promotion requires a bounded TTL, verification and a linked rollback receipt.

PLATFORM CAPABILITY

Static Continuity

Signed bundles are built for approved public content; independent activation is not yet proven.

PLATFORM CAPABILITY

Verified recovery

Technical validation receipts exist; login, checkout and apex recovery are not yet demonstrated.

START WITHOUT CHANGING TRAFFIC

Add one domain. Change no traffic until the checks pass.

AegiFlow guides ownership, origin, certificate and rollback before activation.

Domain hinzufügenDie Einrichtungsanleitung lesen