Web security gateway
In the dark, every requestlooks the same.
NYXR picks out the ones attacking you and stops them. Then it tells you why, and what to do next.
Move your mouse over the log to see what NYXR catches.Touch the log to see what NYXR catches.
01Your turn
Try toget through.
Pick an attack and watch it go through NYXR's nine checks. You will see which one stops it, and why.
Pick a request
GET /products?id=1' OR '1'='1 HTTP/2Host: my-shop.comUser-Agent: Mozilla/5.0 (X11; Linux x86_64)Stopped at step 9 of 9 · Attack filtering
Why : The id in the address hides SQL code meant to read your whole database. The standard rules recognise it, and the request never reaches your site.
- Rule
- OWASP CRS 942100
- What the attacker sees
- An 'Access blocked' page, with a reference number they can send you.
- Reference
- 9cb6bfa2e643457bce2ce8e45665c2d1
This is a replay, but every verdict is exactly what the real gateway returns.
02AI advisor
It blocks, and thenit advises you.
While you sleep, the AI looks into suspicious visitors and double-checks bans before they apply. It also notices when a rule starts blocking the wrong people. By morning, its fixes are waiting for your approval.
An example night on a small online shop.
Verdict
Ban · 24 h
Confidence 0.97
Category scanner
Reason
This address requested 41 sensitive paths in 2 minutes, including /.env, /wp-admin and /backup.zip, almost all returning 404. That is the behaviour of an automated vulnerability scanner.
The model of your choice · your own API keys · Reason written by the AI, in English and French.
03NYXR rules
When a flaw gets exploited,NYXR writes the rule.
We track the flaws attackers are exploiting and the attacks the standard rules let through. Every NYXR rule is tested on 1.04 million real requests before it reaches you.
01
Continuous watch
Flaws already under attack, published exploits, and whatever the standard rules miss.
02
In-house rule
Written to match the exact shape of the attack, so ordinary requests go through.
03
Tested
Tested on 1.04 million real requests. A rule that would get in a real visitor's way never ships as a blocking rule.
04
Shipped
On by default, visible in the console, off in one click.
NYXR rule registry
39 rules · 0 real requests blocked out of 1.04 million
React2ShellExploited
Takeover of a React or Next.js server
CVE-2025-55182
101400-1014010 mistaken blocks
SharePoint ToolShellExploited
Taking over SharePoint through crafted data
CVE-2025-53770CVE-2025-53771
101420-1014300 mistaken blocks
Next.js
Internal headers sent by a visitor
CVE-2024-46982
101440-1014410 mistaken blocks
Template injection
Code slipped into a Java template engine
CVE-2023-22527
1014500 mistaken blocks
XML external entities
Reading files through an XML document
101410-1014110 mistaken blocks
Cloud metadata
Theft of cloud access keys, over IPv4 or IPv6
1014600 mistaken blocks
Forged tokens
Tokens with no signature, or with their own key attached
101200-1012040 mistaken blocks
Cache poisoning
Headers that tamper with the page everyone is served
101100-1011040 mistaken blocks
Smuggled requests
A second request hidden inside the first
101000-1010030 mistaken blocks
Private pages in cache
A logged-in page stored as a public file
101300-1013010 mistaken blocks
Disguised attacks
Paths and commands disguised to fool the rules
101500-1015100 mistaken blocks
04Proof
We ran the tests.Here are the numbers.
Every time a rule changes, we replay real attacks and real traffic through the gateway, and we count the mistakes too.
- 0real requests blocked by the NYXR rules, out of 1.04 million
- 77automated tests: attacks, and innocent look-alikes
- 13possible responses, from letting through to blocking for good
Public data sets of real browsing traffic and real attacks, default settings, measured on 22 and 23 September 2026.
05Comparison
A classic firewall blocks.NYXR explains and advises.
Same attacks, two ways of handling them. The difference shows the next morning.
| When… | Classic firewall | NYXR |
|---|---|---|
| a request is blocked | A 403, no explanation | The reason in plain words, with the rule and a reference number |
| a case is borderline | The score decides alone | An AI weighs the whole picture and explains its call |
| a ban is proposed | Applied without review | Reviewed by the AI, which can only soften it |
| a real customer is blocked | Up to you to dig through the logs | NYXR names the rule at fault and proposes a fix |
| a new bot shows up | Fixed lists | Spotted in your traffic, submitted for your approval |
| a new flaw is exploited | Generic rules | In-house rules from our continuous watch |
| your site is flooded | A counter per address, shared with the rest of the stack | Counted in the gateway itself, on the address and the network and the page and the client signature |
| you have a question | Dashboards to interpret | An assistant that answers with your numbers |
06NYXR Challenge
Bots fail.Your visitors have nothing to do.
When a request looks suspicious, NYXR sends it its own challenge. No puzzle, nothing loaded from Google or Cloudflare, and the same challenge protects your own forms.
Nothing to click
No box to tick, no pictures to spot: a real visitor gets through in half a second without doing a thing.
No Google, no Cloudflare
NYXR serves the challenge itself: nothing loads from anywhere else, and your visitors' addresses go to no one.
For your own forms too
One key per application: sign-up, contact or login, your forms turn bots away as well.
Tested before it goes live
Each key has its own settings and a live test, so you see it working before you switch it on.
No visitor had to click anything.
07The console
Every decision,in plain sight.
See who was blocked, by which rule and why, with a button to undo it. In plain language, for all your services.
- Every version kept
- Undo in one click
- A reference on every block page
Attackers work nights.So does NYXR.
Put it in front of your site tonight. Tomorrow morning, you'll know who tried to get in, and why they didn't.
- Click-free challenge
- Your AI, your keys
- Every decision reversible