Lažne registracije
Botovi kreiraju naloge brže nego što vaš tim može da ih izbriše.
Oni iskrivljuju metriku, sagorevaju granice i pripremaju teren za prevaru.
Corpilus Shield je sigurnosni sloj između korisnika, vaše veb stranice, e-prodavnice, pozadinske mreže i alata AI. Štiti obrasce, prijavu, plaćanje, otpremanje i ćaskanje koje radi sa vašim podacima. Proverava rizične zahteve, odgovore i radnje alata, anonimizuje osetljive podatke i zaustavlja probleme pre nego što stignu do vaših sistema.
15-minutni tehnički poziv. Pregledamo vaše ćaskanje, veb lokaciju, MCP alate ili tok podataka sa najvećim rizikom.
Three real attacks every business sees daily. Then one line of code that stops all of them.
Credential stuffing is the most common attack on the open web. A bot uses lists of leaked username/password pairs from previous breaches — your site, your users.
Real HTTP request to our production API. No login required.
Real HTTP request to our production API. No login required.
We'll scan your domain for 18 known vulnerabilities — admin path probes, missing security headers, exposed config files, supply-chain risks, AI scraper policy — and send you a branded PDF report.
Napad više ne mora da izgleda kao klasičan hak. To može biti upit za ćaskanje, datoteka u obrascu, lažna prijava ili MCP poziv koji zahteva više podataka nego što bi trebalo da primi.
Botovi kreiraju naloge brže nego što vaš tim može da ih izbriše.
Oni iskrivljuju metriku, sagorevaju granice i pripremaju teren za prevaru.
Neko testira ukradene ili nagađane lozinke na vašoj veb lokaciji, često raspoređene na hiljade IP adresa.
Jedno uspešno prijavljivanje može pretvoriti korisnički nalog u incident.
Vaše prijemno sanduče se puni porukama koje niko nije napisao.
Poruke pravih kupaca bivaju zakopane, tim gubi vreme, a isporučivost pati.
Prevaranti testiraju hiljade kartica u odnosu na vašu kasu za cente, samo da bi proverili koji brojevi rade.
Provajderi plaćanja vas kažnjavaju, Stripe poverenje pada i stvarni klijenti mogu biti blokirani.
Makro virusi, PDF-ovi sa JavaScript i SVG korisnim opterećenjem stižu kao prilozi preko kontakt forme.
Malver stiže do poštanskog sandučeta, diska u oblaku ili računara kolege.
Napadač koristi vaš obrazac za slanje e-pošte u ime banke ili dobavljača, uz priloženu lažnu fakturu.
Vaš brend postaje put isporuke za phishing, stvarajući reputacijski i pravni rizik.
Strugači kopiraju vaš katalog, cene i kopiju za konkurente ili lažne prodavnice.
Gubite SEO vrednost, cenu i sadržaj koji ste platili da kreirate.
Chatbot se može nagovoriti da prekrši pravila ili da otkrije svoj sistemski prompt.
Interna uputstva ili curenje podataka, a vaša kompanija snosi odgovornost.
Ovo nije osam odvojenih problema. Oni su jedan problem: nečuvan ulaz u vaše podatke, račune i alate. Shield te ulaze stavlja pod jednu politiku i jedan revizorski trag.
47% veb saobraćaja u 2026. je neljudsko. (Izveštaj o lošem botu Imperva.)
Shield pomaže kompanijama da koriste AI bez slepo poverenja u svaki upit, odgovor ili poziv alata. Može da zaštiti Corpilus AI i ćaskanje koje već koristite preko LLM proksija, mehanizma politika MCP, anonimizacije osetljivih podataka, vidžeta za veb obrazac i pravila koja se mogu revidirati.
Ista politika može da pokriva kontakt forme, prijavljivanje, otpremanja, AI ćaskanje, MCP pozive alata i pristup bazi podataka samo za čitanje. Vaš tim vidi rizik na jednoj kontrolnoj tabli, a ne u pet odvojenih alata.
Promptna injekcija, jailbreaks, curenje sistemskog brzog, prekomerni MCP pozivi i osetljivi podaci u tekstu se procenjuju pre nego što zahtev krene napred.
PII, tajne, API ključevi i identifikatori kompanije mogu biti anonimizovani, redigovani ili blokirani smernicama. Cilj nije usporavanje AI, već sprečavanje nepotrebnog izlaganja podataka.
Svaka odluka ima razlog, nivo rizika i revizorski trag. Detalji detekcije su zaštićeni od zaobilaženja, dok kupci dobijaju objašnjenja, izvoz dnevnika i tehničke dokaze.
Shield nije samo anti-bot. To je sigurnosni sloj za mesta na kojima korisnik ili agent komunicira sa vašom kompanijom: upit, obrazac, otpremanje, prijavljivanje, MCP alat ili upit baze podataka.
Kombinuje bihevioralne signale sa rotirajućim device fingerprintom i IP reputacijom. Pragovi detekcije se ne objavljuju da bi se izbeglo kalibraciono mapiranje.
Prigušivanje po nalogu funkcioniše nezavisno od IP adrese, k-anonimni HIBP proki nikada ne vidi lozinku otvorenog teksta. Promena lozinke zahteva kombinaciju signala brzine, nedavnog prijavljivanja i promene sesije.
API proksi je BYOK — nikada ne vidimo niti čuvamo tokene kupaca. Semantički zaštitni zid koristi lokalne modele za ugrađivanje, bez troškova LLM po zahtevu.
Radi sa hashom card-fingerprinta od PSP — nikad ne vidimo sirov PAN. Kombinuje BIN-level velocity i fingerprint linking kroz device / session / tenant.
Otpremanja prolaze kroz karantin sa listom dozvoljenih ekstenzija, njuškanjem magičnih bajtova i skeniranjem sadržaja. Otkrivanje „pecanja“ ne zavisi od brenda — detektuje obrazac, a ne određeni brend.
AST validacija na svakom upitu. Redakcija osetljivih polja je konfigurabilna per-tenant. Crypto detekcija pokriva 7 blockchain formata adresa.
Nova pravila prolaze kroz uvođenje kanarinca sa gajtiranjem zasnovanim na anomalijama. Učenje među zakupcima samo propagira anonimne obrasce sa zrelošću: eksperimentalno → kandidat → potvrđeno.
RLS je forsiran na svakoj tabeli site_key. Tajna potpisivanja HMAC je samo za server — procureli shield_* ne može da falsifikuje token. Dnevnik revizije beleži aktera, vremensku oznaku i before/after diff.
SDK pokreće prekidač sa 3 stanja (zatvoren/otvoren/poluotvoren) i nije povezan sa jednom tačkom kvara. Kod za popravku omogućava front-end-u da prikaže poruku prilagođenu korisniku.
Dodavanje samo na nivou uloge baze podataka (REVOKE UPDATE, DELETE), parovi ključeva Ed25519 po zakupcu i sidrenje RFC 3161 na eksterni TSA. Jedan bajt promenjen unutar dnevnika poništava svaki sledeći heš — lanac odbija da proveri i manipulisanje je podložno reviziji.
Snimci su zapečaćeni hibridnom kovertom (RSA-OAEP-SHA256 za ključ AES-256-GCM, AES-256-GCM za korisni teret). Arhiva se može otpremiti u bilo koju prodavnicu kompatibilnu sa S3. Nedeljne cron auto-arhive su opcione. Samo vlasnik privatnog ključa može da dešifruje — Shield infrastruktura ne može da čita prethodne snimke.
Keystroke dynamics, mouse trajectory R², scroll patterns, touch events, form-fill timing, page-dwell — multi-signal inputs fed into the local scorer and backend scoring pipeline.
Canvas, WebGL, audio context, font detection, navigator fingerprinting fused into a SHA-256 device hash. Detects headless browsers and anti-detect tools.
Short-lived cache snapshot of device_hash, webgl_renderer, user_agent, timezone, screen_resolution at session start. Sensitive events (login, form submit, checkout) compare the live fingerprint; drift adds significant risk signals respectively.
OpenAI- and Anthropic-compatible base URL. Shield scans every prompt before forwarding and every completion before returning, blocks on policy hit, strips PII / secrets on stream.
Embedding-based detection across many attack categories. "Disregard earlier directives" ≈ "Ignore previous instructions" at cosine similarity. Ollama-local embeddings — zero per-request API cost.
Tool-call interception for Claude / Cursor / IDE agents. JSON Schema validation of arguments, chain-step limit, domain allowlist, explicit approval gates on destructive tools. Inspects every invocation against agent-protection rules before execution.
40+ patterns scanning input + output + tool calls before / after the model runs. Runs alongside the Semantic Firewall for layered defence.
5 tools exposed via MCP: shield_get_stats, shield_get_threats, shield_add_rule, shield_get_events, shield_verify_token. Let your Claude / Cursor agent investigate and act on incidents without leaving the chat.
AST-parsed SQL validation. Blocks UNION, INTO OUTFILE, pg_sleep, information_schema. LIMIT capped. Sensitive columns (password, api_key, ssn) auto-redacted. Query fingerprinting and honeytoken trap tables.
Wallet detection: BTC (P2PKH/Bech32), ETH, SOL, TRX, XRP, LTC, DOGE. BIP-39 seed phrase scanning (12/24 word). Signing prompts (EIP-712). Mining domains blocked. Payment redirect patterns.
Bigram gibberish detection (EN / DE / CS / SK / ES), 100+ disposable email domains, spam patterns (repeated chars, ALL CAPS, URL flood), suspicious name detection. Phishing and bad-content corpus covers 9 languages (see Phishing card). Additive scoring with cluster bonuses.
Multi-layered email + attachment scanner. Detects Slovak/Czech/Polish/German/French/Spanish/Serbian bodies stripped of diacritics (the strongest real-world phishing signal), password-hint social engineering across 9 languages, mainframe-mimicry filenames, and password-protected PDF / Office files. Brand-agnostic cluster catches the same shape with any impersonated company name.
check_upload() accepts form_fields. When a file upload is accompanied by form data (title, description, name, message), Content Quality Scoring runs on those fields too. A clean PDF with gibberish metadata still gets rejected at high-confidence score.
Every file passes a quarantine gate — extension allowlist, magic-byte MIME sniffing, Office macro detection, PDF JavaScript / Launch / OpenAction, SVG / HTML script injection. Per-tenant max size and extension list.
Python (FastAPI / Django / Flask), Node.js (Express / Next.js), PHP (WordPress / Laravel). Validates X-Shield-Token on every request. No token → 403. HMAC verify is cached with a short-lived cache per (token, path).
3-state breaker (closed / open / half_open) in all three backend SDKs. After consecutive transport errors → OPEN for a brief interval → 1 HALF_OPEN probe. 4xx doesn't trip the breaker. PHP uses APCu for cross-FPM-worker state. No more timeouts on every request during an upstream incident.
Reason → (machine_code, human_hint) map. /shield/verify and all 3 SDK 403 bodies return remediation + remediation_code. Legit false-positive users see "Your session expired — please reload" instead of a silent 403.
Drop-in PHP plugin: auto-injects the widget, ships middleware that validates Shield tokens on /wp-login.php and admin endpoints. Fail-closed by default, configurable.
Multi-dimensional rate limiting: per-IP, per-device, per-endpoint, with progressive escalation. Server-side counters with sliding windows.
IP geolocation via ip-api.com (short-lived cache). Per-site blocked / allowed country lists. Datacenter and proxy / Tor score modifiers. Page-load hard block with access-denied overlay before widget initialises.
Widget prevents form submission at high-confidence score. Red overlay: "Blocked by Corpilus Shield". Server-signed HMAC-SHA256 tokens auto-attached to fetch() via interceptor.
278 compiled detection patterns scanned automatically on every event — covers all OWASP Top 10 2025 categories. Payload-level inspection happens before scoring.
AI analyzér analyses events continuously. RAG context grounded in a curated security knowledge base. Auto-creates threats and rules from real observations.
Pre-built threat-intel context (mini-CAG). Bot signatures, attack patterns, OWASP samples baked in — new sites are protected from the first page view.
Shield's Security Knowledge collection ships with curated docs (OWASP Top 10, bot detection, incident response). Admins can upload their own company playbooks, post-mortem reports, or domain-specific threat intel. Every upload runs through a multi-layer scan. Clean docs land as trust_state='pending' until an admin explicitly promotes them to 'active'. Only active docs reach the AI analyzer's RAG context.
Anonymised pattern sharing — IPs reduced to /24, PII stripped, maturity gating (experimental → candidate → confirmed). One tenant's confirmed attacker becomes everyone's known threat within minutes.
Widget MutationObserver snapshots all <script> tags at boot. Any subsequently injected script is reported as script_integrity_violation telemetry with src, external/same-origin, content length, stable hash. Capped per page-load. Tenant allowlist for trusted CDNs.
Redis counter per SHA-256(account_id). Each failure over the cap adds significant risk score. A distributed attack that spreads many attempts over thousands of IPs still lands on the same account bucket — the attempt on victim@corp.com triggers challenge regardless of which IP sent it. Counter resets on a successful login.
GET /shield/password/breach-range/{prefix} — client computes SHA-1(password) locally in the browser, sends only the 5-char hex prefix, Shield proxies to api.pwnedpasswords.com and streams back the suffix+count list. Client compares its own suffix locally. Server never sees plaintext OR the full hash.
A/AAAA + MX record check on signup. Fail-open on timeout. Short-lived per-domain cache so rapid signup waves from the same throwaway domain don't re-hammer DNS.
25+ protected brands (Google, Microsoft, Apple, PayPal, Stripe, Meta, LinkedIn, Revolut, SK/CZ banks & insurers). Three-tier detector: 1) normalised exact match via homoglyph map, 2) Levenshtein distance for long brands, 3) brand-substring + decorative suffix (secure/login/support/verify/auth/signin/account/official/help).
Velocity counters per IP and per device. Recent-login requirement: no successful login from this device recently → significant risk signal. Session Continuity: password_change is now in the SENSITIVE event set, so full fingerprint drift blocks immediately. The classic 'attacker grabs session → changes password → locks out user' chain needs to survive all three gates.
Email (HTML), Slack, Discord, generic JSON webhooks. Weekly security report with stats, top threats, block rate. Per-webhook severity gate (low / medium / high / critical).
Every rule change, site config edit, manual block, AI decision is recorded with actor, timestamp, before/after diff. Hash-chained, signed, and exportable as auditor-ready evidence bundle.
HMAC-SHA256 tokens are minted server-side from the per-site secret and returned via /shield/events. The widget never holds the signing secret — a leaked site_key cannot be used to forge valid tokens.
PostgreSQL Row-Level Security forced on all shield_* tables. Each request runs under a tenant-scoped role — no application-layer bypass possible even if the API has a bug.
Tracks attempts per card BIN across rolling windows. Burst patterns consistent with card-testing activate progressive challenge or block. Thresholds are tenant-tunable; defaults are conservative.
When the same PSP-provided card fingerprint appears across multiple devices, sessions or tenants in a short window, attempts are correlated and scored as a coordinated attack. Raw PAN never leaves your PSP.
Tenant-scoped baseline of issuer-country distribution. A sudden concentration of attempts against issuers from a small number of countries — well above baseline — flags probable carding traffic.
Aggregates multiple signals — diverse BIN spread, same device or session, high failure ratio — into a named carding verdict. Upgrades decision severity when confirmed by post-charge PSP feedback.
Slow-burn attacks no longer slip through. Shield watches the whole conversation arc, not just one message at a time. An attacker who chats innocuously for many turns and only then pivots to data extraction or credential phishing is caught at the moment the pattern emerges.
Before your agent runs a tool, Shield asks: is the user's actual intent consistent with calling this tool? A request to summarise a document should not trigger a database export. A travel-booking chat should not be calling a payments tool. Mismatches are gated for review.
Compromised agents and curious LLMs typically scan the environment before acting — listing directories, reading config paths, enumerating environment variables. Shield flags this reconnaissance pattern early, before any data leaves the box.
A single conversation can never quietly burn your whole monthly AI budget. Shield enforces a per-session ceiling on tokens, tool calls and elapsed time. When the cap is reached the session is paused or terminated and the operator is notified.
Shield learns what normal looks like for each user — typical hours, typical actions, typical pace — and quietly flags the day that pattern breaks. A logged-in session that suddenly behaves nothing like the real user is treated as a possible takeover.
Decoy records, files and credentials are planted in places only an attacker would dig. Real users never see them. The moment one is touched, accessed or used, Shield has a high-confidence breach signal with effectively zero false positives.
Attackers hide malicious payloads inside layered encodings — base64, hex, percent-encoding, unicode escapes — to slip past simple string filters. Shield unwraps these layers before scoring, so the underlying attack is matched against the same protections as a plain-text version.
Before any rule, model or scorer update ships, it is run against a continuously growing corpus of real-world attack scenarios. If a release accidentally weakens detection on a known threat shape, the change is blocked at CI — not after a customer is breached.
Every security decision and config change is written to a tamper-evident chain. Edits and deletions are mathematically detectable. Auditors, regulators and incident responders get a trustworthy timeline even in the worst-case scenario where an attacker reaches admin credentials.
When something happens, you do not want to spend hours collecting logs. One click produces an encrypted, time-stamped bundle of the relevant tenant state — events, rules, decisions, recent traffic — ready to hand to your security team, lawyer or regulator.
Shield does not lock you into one AI vendor. Bring your own OpenAI / Anthropic / Google key, point at a dedicated Ollama instance, or run fully local. Set hard cost caps and routing rules. Your data flows only to providers you explicitly approve.
For your highest-risk actions Shield can require a hardware-rooted gesture: Touch ID, Windows Hello, a hardware security key. These are physical-presence checks that an LLM-powered agent or remote attacker cannot solve, no matter how clever the prompt.
For regulated, classified or disconnected environments Shield ships as a self-hosted package with signed release artifacts and a fully offline install path. Nothing has to talk to the public internet, but you still get rule, model and intel updates on your own schedule.
Shield can flag form, message and document submissions that look machine-generated rather than human-typed. Combined with behaviour and timing signals, this gives operators a clear answer to "is this real?" on application forms, CVs, support tickets and reviews.
The widget snapshots fetch, XHR, navigator and userAgent at boot and re-checks periodically. If a browser extension, injected script or third-party tag flips navigator.webdriver, wraps fetch, replaces XHR or mutates navigator descriptors, Shield reports the tampering and can refuse to issue a token. Per-attribute form.action / hidden-input change tracking is roadmap, not wired today.
Every request is checked in O(1) against 48,000+ real-time threat indicators refreshed frequently. No customer setup — platform-funded. Adds score boost on match.
Premium reputation services lookup on suspicious events only. Per-tenant Fernet-encrypted keys; no platform-shared keys, lookups happen on your quota.
All ten 2025 OWASP categories addressed — A01 access control, A02 misconfig, A03 supply chain, A04 crypto, A05 injection, A06 design, A07 auth, A08 integrity, A09 logging, A10 exception handling. Pattern set sourced from OWASP CRS v4, nuclei templates, PayloadsAllTheThings.
Identifies bots from OpenAI, Anthropic, Google-Extended, Perplexity, ByteDance, CommonCrawl, Meta, Apple, Cohere, Mistral, AllenAI, You.com and more. Tenant chooses block / monitor / allow per vendor.
log4j JNDI gadgets (${jndi:ldap://...}), LDAP injection, XML External Entity, MongoDB-style NoSQL operator injection — all blocked at the /shield/events ingest before reaching your backend.
Read-only view of all 278 patterns Shield runs on every request, grouped by category. Customers see exactly what's protecting them — no marketing claims to verify.
Kliknite na bilo koju karticu da biste je proširili za pun opis i model pretnje.
Napadi vođeni LLM-om sada pobeđuju naivnu detekciju botova — realistične sesije Playwright, putanje miša bezierove krive, rešavanje slike CAPTCHA. Isporučili smo 8 faza učvršćivanja na strani klijenta tako da se vidžet brani od prilagodljivih protivnika.
Nema promena u vašoj instalaciji — isti one-line snippet i dalje radi.
Vreme izvođenja je grupisano po zakupcu nedeljno. Obrnuti inženjering vidžeta jednog stanara ne pomaže u napadu na drugog.
Snimci vidžeta window.fetch, XMLHttpRequest, navigator pri pokretanju — ponovo proverava svakih 15 sekundi. Zlonamerna proširenja se hvataju.
Backend više ne vraća rezultat ili razlog vidžetu — zatvara gradijent curenja koje adaptivni napadači iskorišćavaju.
UV izazov sa hardverskim korenom — Touch ID, Windows Hello, bezbednosni ključevi. Nijedan LLM to ne može rešiti.
k-means na uređaju svaku sesiju dodeljuje jednom od 8 profila — 4 ljudska, 3 bot, 1 nepoznat. Backend ga koristi kao grubi ključ ličnosti.
Rezultat sličnosti među sesijama keširan u localStorage. Iznenadni padovi ukazuju na lažiranje.
Kada 10+ osoba deli ponašanje + IP CIDR + porodični potpis UA, aktivira se upozorenje. Kontra napadima zagrevanje pa udari.
Registracije pre pregleda: imejl za jednokratnu upotrebu, validnost telefona, prisustvo SSO. Zaustavlja farme naloga pre nego što postoje.
Cene se zasnivaju na zaštićenim domenima, zaštićenim radnjama i nivou podrške. Osnovni bezbednosni slojevi su uključeni u svaki plan, bez skrivenih dodataka za suštinsku zaštitu.
Zaštita botova, obrasci, prijavljivanje, AI ćaskanje, MCP alati, otpremanja, SQL zaštita i revizija su uključeni u svaki Shield plan. Uglavnom birate po obimu saobraćaja, broju domena i potrebnom nivou podrške.
Zaštićena radnja = slanje obrasca, prijavljivanje, plaćanje, otpremanje, MCP poziv ili AI/API zahtev. Normalan prikaz stranice se ne računa.
Ne odnosi se na Dedicated — sve je uključeno u ponudu.
Kada se približite ograničenju, prvo vas obaveštavamo. Nema tihih faktura iznenađenja.
Bez diplomatije. Ako ste tražili negde drugde i niste pronašli odgovor, verovatno je ovde.
Pet porodica napada: botovi i skraperi, pokušaji preuzimanja naloga, napadi preko vašeg AI (promptna injekcija, jailbreak, zloupotreba MCP), zlonamerni fajlovi i phishing u otpremanjima, sumnjivi SQL korisni podaci i kopiranje podataka. Matrica pune sposobnosti pripada ovim porodicama.
Da. Shield ne mora da zameni vaše postojeće ćaskanje. Može da radi kao zaštitni sloj ispred krajnje tačke LLM, interfejsa za ćaskanje ili alata MCP. On proverava unose, odgovore i pozive alata u skladu sa politikom vaše kompanije i može da anonimizuje osetljive podatke pre nego što se dalje pošalju.
Svaka odluka ima ocenu poverenja, šifru razloga i zaobilaženje jednim klikom. Kada nije siguran, Shield preferira mekši izazov (honeipot, PoV) umesto tvrdog 403. Možete da stavite na belu listu IP, korisnički ID ili zemlju za 30 sekundi, a svaki blok je podložan reviziji.
Sva telemetrija ostaje na infrastrukturi EU (primarni u Nemačkoj, prelazak na grešku EU-West). Potpisana DPA i lista podprocesora su dostupni pre potpisivanja. IP adrese su heširane, sa podrazumevanim zadržavanjem od 30 dana koje se može konfigurisati.
Podrazumevano: ugrađivanja i klasifikacija robota rade na lokalnim modelima Ollama u našoj EU infrastrukturi, tako da običan saobraćaj nikada ne vidi američki LLM. Opciona dublja analiza može da pozove Google / Anthropic / OpenAI kao opciju za svakog stanara, registrovanu i promenljivu. API proksi je BYOK — vaš LLM ključ i tokeni ostaju vaši, a mi ne vidimo sadržaj.
Ne. Shield koristi samo strogo neophodne kolačiće / localStorage za bezbednosnu sesiju. Prema ePrivaci i GDPR, oni su izuzeti od saglasnosti. Vaš postojeći baner kolačića može pokriti obaveštenje.
Tri opcije: SDK za Next.js / Node / Vercel / PHP / WordPress, režim obrnutog proksija bez promene koda ili rubni radnik za Cloudflare / Python. SDK putanja ne zahteva promenu DNS. Prva instalacija obično traje manje od 30 minuta.
Uz podrazumevanu lokalnu putanju Ollama, p95 prekomerni troškovi su u malim desetinama milisekundi i rade paralelno sa vašim zahtevom. Opcioni pozivi dubinske analize su podrazumevano asinhronizovani, tako da korisnik ne čeka. Strogi inline režim se može omogućiti na osetljivim krajnjim tačkama.
Podrazumevani režim je fail open: SDK propušta zahtev i evidentira incident radi revizije. Za osetljive krajnje tačke kao što su prijavljivanje ili plaćanje, možete omogućiti fail closed. SDK-ovi uključuju prekidač kako bi se izbegla kaskadna vremenska ograničenja.
Postavio si kapu. Na 80% limita, upozoravamo vas; na 100%, zatvaramo merač i nudimo paket dodataka za pretprodaju. Nema tihog prekoračenja. Nema iznenađenja po zahtevu.
Ne nudimo javni besplatni plan, ali za odgovarajući projekat možemo pripremiti 14-dnevnu integraciju beta za vaš domen i potpuni tok zaštite. Ugovori mogu biti mesečni ili godišnji, sa 10% popusta na godišnje planove. Izvoz dnevnika i otkazivanje se obrađuju transparentno u okviru ciklusa naplate.
Pošteno pitanje. Shield je deo Corpilus platforme i dizajniran je za evropske kompanije koje treba da zaštite veb stranice, e-prodavnice, AI ćaskanje i tokove podataka. SDK-ovi i materijali za integraciju se dostavljaju klijentima tokom implementacije. Tajna potpisivanja HMAC ostaje na strani servera, podaci se mogu izvoziti, a implementacije u preduzeću mogu uključiti opcije deponovanja koda ili kontinuiteta partnera.
Niste našli odgovor? Pitajte nas direktno →
Pokrećemo bezbednosnu reviziju vaše veb lokacije, prikazati botove i pokušaje brzog ubrizgavanja koje trenutno ne vidite i pregledaćemo integraciju za 15 minuta. Nema slajdova – samo vaši podaci.
Eksterno skeniranje javne površine. Ne zamenjuje antivirus, zaštitni zid ili formalni test penetracije.
Tehnička diskusija o vašoj infrastrukturi, veb lokaciji, ćaskanju i tokovima podataka.
Odgovor i report u roku od 3 radna dana.
Obaveštenje o opsegu zaštite. Corpilus Shield je zaštitni sloj AI u realnom vremenu dizajniran da proširi standardne bezbednosne mehanizme za veb-sajtove, e-prodavnice i LLM aplikacije, a ne da ih zameni. Ne zamenjuje antivirus, zaštitni zid, testiranje penetracije ili formalnu reviziju bezbednosti. Za sveobuhvatnu zaštitu preporučujemo kombinovanje nekoliko slojeva.