Skip to content

Web security gateway

In the dark, every requestlooks the same.

NYXR picks out the ones attacking you and stops them. Then it tells you why, and what to do next.

Move your mouse over the log to see what NYXR catches.Touch the log to see what NYXR catches.

01Your turn

Try toget through.

Pick an attack and watch it go through NYXR's nine checks. You will see which one stops it, and why.

Pick a request

request.http
GET /products?id=1' OR '1'='1 HTTP/2
Host: my-shop.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64)

Stopped at step 9 of 9 · Attack filtering

BlockedResponse 403

Why : The id in the address hides SQL code meant to read your whole database. The standard rules recognise it, and the request never reaches your site.

Rule
OWASP CRS 942100
What the attacker sees
An 'Access blocked' page, with a reference number they can send you.
Reference
9cb6bfa2e643457bce2ce8e45665c2d1
Put NYXR in front of your site

This is a replay, but every verdict is exactly what the real gateway returns.

02AI advisor

It blocks, and thenit advises you.

While you sleep, the AI looks into suspicious visitors and double-checks bans before they apply. It also notices when a rule starts blocking the wrong people. By morning, its fixes are waiting for your approval.

An example night on a small online shop.

AI verdict203.0.113.42 03:12

Verdict

Ban · 24 h

Confidence 0.97

Category scanner

Reason

This address requested 41 sensitive paths in 2 minutes, including /.env, /wp-admin and /backup.zip, almost all returning 404. That is the behaviour of an automated vulnerability scanner.

41Paths probed
93%404 responses
20 / minRate

The model of your choice · your own API keys · Reason written by the AI, in English and French.

03NYXR rules

When a flaw gets exploited,NYXR writes the rule.

We track the flaws attackers are exploiting and the attacks the standard rules let through. Every NYXR rule is tested on 1.04 million real requests before it reaches you.

  1. 01

    Continuous watch

    Flaws already under attack, published exploits, and whatever the standard rules miss.

  2. 02

    In-house rule

    Written to match the exact shape of the attack, so ordinary requests go through.

  3. 03

    Tested

    Tested on 1.04 million real requests. A rule that would get in a real visitor's way never ships as a blocking rule.

  4. 04

    Shipped

    On by default, visible in the console, off in one click.

NYXR rule registry

39 rules · 0 real requests blocked out of 1.04 million

  • React2ShellExploited

    Takeover of a React or Next.js server

    CVE-2025-55182

    101400-1014010 mistaken blocks

  • SharePoint ToolShellExploited

    Taking over SharePoint through crafted data

    CVE-2025-53770CVE-2025-53771

    101420-1014300 mistaken blocks

  • Next.js

    Internal headers sent by a visitor

    CVE-2024-46982

    101440-1014410 mistaken blocks

  • Template injection

    Code slipped into a Java template engine

    CVE-2023-22527

    1014500 mistaken blocks

  • XML external entities

    Reading files through an XML document

    101410-1014110 mistaken blocks

  • Cloud metadata

    Theft of cloud access keys, over IPv4 or IPv6

    1014600 mistaken blocks

  • Forged tokens

    Tokens with no signature, or with their own key attached

    101200-1012040 mistaken blocks

  • Cache poisoning

    Headers that tamper with the page everyone is served

    101100-1011040 mistaken blocks

  • Smuggled requests

    A second request hidden inside the first

    101000-1010030 mistaken blocks

  • Private pages in cache

    A logged-in page stored as a public file

    101300-1013010 mistaken blocks

  • Disguised attacks

    Paths and commands disguised to fool the rules

    101500-1015100 mistaken blocks

04Proof

We ran the tests.Here are the numbers.

Every time a rule changes, we replay real attacks and real traffic through the gateway, and we count the mistakes too.

Attacks stopped

+5.3 points
OWASP CRS90.4%
NYXR95.7%

Higher is better

Real visitors blocked by mistake

3.4× fewer
OWASP CRS33.5%
NYXR9.9%

Lower is better

Public catalogue of 73,298 attacks

+19.2 points
OWASP CRS73.4%
NYXR92.6%

Higher is better

  • 0real requests blocked by the NYXR rules, out of 1.04 million
  • 77automated tests: attacks, and innocent look-alikes
  • 13possible responses, from letting through to blocking for good

Public data sets of real browsing traffic and real attacks, default settings, measured on 22 and 23 September 2026.

05Comparison

A classic firewall blocks.NYXR explains and advises.

Same attacks, two ways of handling them. The difference shows the next morning.

When…Classic firewallNYXR
a request is blockedA 403, no explanationThe reason in plain words, with the rule and a reference number
a case is borderlineThe score decides aloneAn AI weighs the whole picture and explains its call
a ban is proposedApplied without reviewReviewed by the AI, which can only soften it
a real customer is blockedUp to you to dig through the logsNYXR names the rule at fault and proposes a fix
a new bot shows upFixed listsSpotted in your traffic, submitted for your approval
a new flaw is exploitedGeneric rulesIn-house rules from our continuous watch
your site is floodedA counter per address, shared with the rest of the stackCounted in the gateway itself, on the address and the network and the page and the client signature
you have a questionDashboards to interpretAn assistant that answers with your numbers

06NYXR Challenge

Bots fail.Your visitors have nothing to do.

When a request looks suspicious, NYXR sends it its own challenge. No puzzle, nothing loaded from Google or Cloudflare, and the same challenge protects your own forms.

  • Nothing to click

    No box to tick, no pictures to spot: a real visitor gets through in half a second without doing a thing.

  • No Google, no Cloudflare

    NYXR serves the challenge itself: nothing loads from anywhere else, and your visitors' addresses go to no one.

  • For your own forms too

    One key per application: sign-up, contact or login, your forms turn bots away as well.

  • Tested before it goes live

    Each key has its own settings and a live test, so you see it working before you switch it on.

Contact form · latest attempts14:02:11  visitor  through in 0.4 s14:02:15  bot      failed the challenge14:02:19  visitor  through in 0.5 s14:02:26  bot      failed the challenge14:02:31  bot      failed the challenge3 bots stopped. 0 clicks asked.

No visitor had to click anything.

07The console

Every decision,in plain sight.

See who was blocked, by which rule and why, with a button to undo it. In plain language, for all your services.

  • Every version kept
  • Undo in one click
  • A reference on every block page

Attackers work nights.So does NYXR.

Put it in front of your site tonight. Tomorrow morning, you'll know who tried to get in, and why they didn't.

  • Click-free challenge
  • Your AI, your keys
  • Every decision reversible
Put NYXR in front of your siteOpen the console