Not claimed, demonstrated: every figure has its own experiment behind it
SHIELD is validated on two fronts: real attacks executed against a real server —every capability with its own scenario, not simulations— and real traffic from production sites, with the applications and plugins that are actually served out there. In total, 2.6 million real files and events put through the same detection path that runs on the server. Everything below is measured, not estimated.
What was measured, over what, and with what result
None of these numbers comes from a model in isolation: they are measured through the same detection path that runs on the server, over 2,087,314 legitimate files —content-manager code, plugins, themes and libraries— and 554,801 events of real traffic from the most widely deployed CMSs and shops in the world, and against attacks actually executed. The zero false positives are a consequence of the design, not of luck: acting requires a certainty signal, and across those two million legitimate files not one reached it —those that raised a hand stayed at warning, without touching the service a single time—. All of it reproducible on your own traffic during the pilot.
| What is measured | Over what | Result |
|---|---|---|
| Wrong actions on legitimate files | 2,087,314 files from content managers, plugins, themes and libraries | 0 containments |
| False positives on real traffic | 554,801 events from the most widely deployed CMSs and shops in the world, running | 0 |
| Malware the system had never seen | Held-out corpus, from a source outside the training set | 86.9% detected |
| Brand-new families recognised by intent | Code fragments at the instant they execute | 96.6% |
| Attacks actually executed against the server | RCE, local and remote inclusion, gadget deserialisation, webshell drop | 100% detected and contained |
| Decision latency | Behaviour check, measured in the agent itself | 32 ns |
| Cost on the server | Agent running, hour after hour | ≈50 MB RAM · <1% of one core |
The usual doubts, answered straight
"What if it takes down a legitimate site?"
By design it cannot happen lightly: containment requires a certainty signal, and a suspicion stays a warning. And if you were wrong anyway, everything is reversible: a neutralised file carries how to restore it and the account is released instantly. Across more than two million legitimate files from real sites, none reached containment. Not one.
"What will it cost me in performance?"
A single binary, with no external engines to load and no cloud lookups. The per-event decision resolves in microseconds —the behaviour check in 32 nanoseconds— so you keep your accounts-per-server density and your margins.
"Do I have to touch my stack?"
No. No proxy to insert, no interpreter extension to install and maintain version after version, nothing to recompile. A self-contained installer, one configuration file and any distribution. You install a new PHP version and SHIELD recognises it and calibrates itself, with no restart.
"What if the attacker tries to switch it off?"
It only obeys signed orders with an increasing sequence number, verifies its own integrity and, if it loses contact with control, returns to its safe state on its own. And if it ever stopped seeing because of saturation, it does not let things through: it denies. What cannot be observed is not allowed.
"And against what nobody has seen yet?"
That is exactly its ground. There is no signature to wait for: SHIELD judges by what the code does when it runs. On completely new malware families its intent engine recognises 96.6%, and the whole system catches 86.9% of malware from an outside source it had never seen.
"Does my customers' code leave my server?"
No. SHIELD decides inside the server, with the intelligence embedded in the binary itself. No code is sent to any cloud, yours or ours.
Every capability on this page is implemented and verified in the source code, and every figure reproduces with one command over the captured traffic —and over your own during the pilot—. No testimonials and no third-party references are used. Last verified: August 2026.
See it on your own data
Deploy the agent on three servers and leave it in observation mode. Within days you will have the figures for your own traffic: what it would have detected, what it would have contained and with how much noise. Turning on blocking is a later configuration change, and it is your call.
