Global Edge
Cloudflare for SaaS provides global ingress; AegiFlow adds service context.
Cloudflare supplies global ingress. AegiFlow adds service context, bounded response, continuity, recovery checks and evidence without putting deep analysis in the visitor's critical path.
Counters appear only from a fresh, fully validated public snapshot. Request lines are illustrative: AegiFlow never publishes customer request contents.
Current state is shown only after a fresh, schema-validated snapshot is loaded.
Open status evidenceEvery stage explains who acts, what changes, how AegiFlow verifies the result and how to return safely.
Organization and roles are kept separate from protected traffic.
A DNS proof confirms that the service is authorized.
AegiFlow measures compatibility without blocking visitors.
Certificate, origin, health checks and rollback must all pass.
AegiFlow connects advisories to the exact software inventory of each service. Unknown evidence stays unknown; it is never presented as safe.
Explore Threat RadarExample data. A protected state requires current inventory and verification evidence.
Databases, threat feeds, assisted analysis and the dashboard are never dependencies of the visitor request.
Candidate controls run without blocking first. Canary checks, a short time window and explicit rollback precede active blocking.
Review reversible responseAegiFlow builds signed copies of approved public content. Independent activation and business-journey recovery remain explicit checks before production use.
Choose the operating boundary that fits the service.
Cloudflare for SaaS provides global ingress; AegiFlow adds service context.
Independent native ingress and a second edge provider remain planned.
Global and native paths share the same safety contract and evidence.
Inventory, availability and threat relevance without changing or blocking traffic.
Capability state, inventory freshness, applied controls and recovery results remain explicit. A missing check becomes Unknown, never a green status.
Open the Trust CenterThese cards define platform scope. The current GoTe state, scope and freshness come only from the validated snapshot above.
Real advisory from our public database: affects verot/class.upload.php < 1.0.3, fixed in 1.0.3. AegiFlow compares it with the version each service actually runs.
The advisory fields are a dated public reference (2026-07-31). The component list and verdicts are illustrative: a clean verdict requires current inventory, and anything unproven stays Unknown.
Configured public advisory sources are normalized and matched against exact inventory; the current count is loaded from the public snapshot.
Envoy routes requests while Coraza inspects them out of process on the request path, with bounded timeouts and analysis before blocking.
Correlated incidents share one timeline; promotion requires a bounded TTL, verification and a linked rollback receipt.
Signed bundles are built for approved public content; independent activation is not yet proven.
Technical validation receipts exist; login, checkout and apex recovery are not yet demonstrated.
AegiFlow guides ownership, origin, certificate and rollback before activation.