Skip to content
ZEROWARN
Try it with no risk

Start in observation mode, on your own data

The figures on this site come from our lab and from real production traffic; the ones that decide a purchase should come from your fleet. That is exactly what the pilot is: SHIELD in log-only mode on your servers, measuring what it would have detected and what it would have contained —down to the last execution it would have denied, counted without denying a single one— and with how much noise.

  1. Week 1

    Deployment on a subset of your estate, in observation mode. It blocks nothing.

  2. Weeks 2 and 3

    A report with real detections and the false-positive rate on your traffic, not on ours.

  3. When you decide

    You turn blocking on there and then, with a configuration change and no restart. And you extend it to the fleet.

Requirements

  • A representative subset of the estate. Three servers are enough to get the figures
  • Administrative permissions to install the package and register the service
  • A few minutes of installation per server
  • No modification of the configuration, the vhosts or the interpreter

Deliverables

  • Report of detections and simulated containments over the estate's real traffic
  • False-positive rate measured over that same traffic, not over an outside corpus
  • Inventory of the covered surface: interpreter versions, data engines and libraries
  • A documented decision criterion: enable containment, extend the rollout, or stop

Zero risk to production

In observation mode it blocks nothing. And when you move to blocking, containment ships conservative: it only acts on certainty signals, leaves everything else as a warning, and is reversible if it ever gets one wrong.

Getting started

Install in three steps

There is no reboot, nothing to change in the interpreter and nothing to put in the traffic path. Uninstalling costs the same as installing.

  1. 1. Install the agent

    One command: curl -sSL …/install.sh | sudo sh. It detects the architecture, verifies the binary's signature and registers the service. One file and no interpreter dependencies; if it cannot verify the signature, it aborts instead of installing.

  2. 2. Drop in the licence

    Copy the file we give you to /etc/shield/license.lic and restart the service. The agent verifies it at startup and tells you what it grants.

  3. 3. Watch before you block

    It starts in observation mode: you see what it would have contained without touching anything. When the result convinces you, you turn blocking on live, with no restart.

See it on your own data

Deploy the agent on three servers and leave it in observation mode. Within days you will have the figures for your own traffic: what it would have detected, what it would have contained and with how much noise. Turning on blocking is a later configuration change, and it is your call.