Unified Web Security Platform

NYXRNeutralize Your eXposure Risk

Put NYXR in front of any app or API and it stops attacks, bad bots and abuse before they ever reach you. Nine coordinated layers of defense, an AI that makes the final call, and full control you can explain and undo - all self-hosted.

ModSecurity WAFAI verdictFail-closedSelf-hostable
The engine

Nine layers. One verdict.

Every request flows through the full pipeline in order. A single bypassed control is never enough, and the final AI verdict is authoritative all the way down to the kernel.

Tap any layer to see exactly what it does.

Incoming request
9
Ordered defense layers
12
Verdict decision types
0
Per-request DB calls in the data plane
100%
Decisions explainable & reversible
Adaptive bot intelligence

It does not just block bots. It learns them.

NYXR continuously turns real traffic into service-specific baselines, fingerprint reputation and emerging campaign detections. The learner adapts without becoming a black box: high-impact rules wait for your approval, remain explainable and can be rolled back.

Fingerprint beyond the User-Agent

Correlate JA4, header order, client coherence and behaviour across rotating IPs to recognize the same automation stack.

Discover distributed campaigns

Cluster suspicious fingerprints, autonomous systems and attack ratios before a low-and-slow botnet becomes an incident.

Human-controlled enforcement

Learning runs continuously, but block and ban proposals stay reviewable. Approve, reject or roll back every learned rule.

nyxr.app/bot-intelligence
Bot Intelligence
Console/Defence/Bot Intelligence

Bot Intelligence

The adaptive bot-detection engine: learned traffic baselines, client fingerprint reputation, discovered campaigns and the learned-rule approval queue (shadow rules auto-promote for soft actions; block/ban land as proposals to approve).

OverviewProposalsRulesFingerprints
Proposals awaiting approval
Suspicious fingerprint clusterblock-tempfingerprint

Stable client stack observed across 38 IPs with a 91% attack ratio and incoherent browser signals.

confidence 96%support 38
ApproveReject
Distributed ASN campaignbancampaign

17 IPs from one ASN are targeting /wp-login.php across 6 services.

confidence 89%support 214
ApproveReject
1,842
Fingerprints
27
Learned rules
4
Proposals
Observe
Learn
Review
Enforce
The arbiter

When the rules are not enough, the AI decides.

Signatures and scores resolve most traffic. For the ambiguous remainder, an AI verdict engine weighs the full request context and returns a single, accountable decision the rest of the stack obeys.

Explainable

Every verdict carries the signals and the reasoning behind it - never a silent black box.

Authoritative

An AI "allow" lifts a behavioural auto-ban, and a block reaches down to the kernel nftables layer.

Reversible

Any decision can be overridden and rolled back from the console in one click.

nyxr.app/dashboard
Dashboard
Console/Overview/Dashboard

Overview

Real-time security posture, traffic and alerts across every protected service.

Requests (24h)
248,913
+12.4%
Threats blocked
5,172
+8.1%
Active bans
38
+3
p95 latency
41ms
-6ms
Traffic over timerequests / last 60 min
Console/Defence/Behavioural Enforcement

Behavioural Enforcement

Active bans and the AI verdicts that drive them. Enforcement and intelligence in one view.

Active bansAI verdicts
All verdicts All actions Refresh
TimeVerdictClient IPBeh.
14:32:07Ban96%203.0.113.7
14:31:52Challenge78%198.51.100.24
14:31:40Allow88%192.0.2.55
14:31:18Monitor61%45.83.0.12
14:30:59Ban99%203.0.113.99
14:30:41Allow93%192.0.2.8
Console/Defence/Logs Explorer

Logs Explorer

Search and stream WAF security events - filter by action, rule and client IP.

Events (1h)
3,418
Blocked
212
Challenged
96
Allowed
3,110
All actions Rule idLive+0 live Refresh
TimeActionSeverityRequestStatusClient IPRuleBeh.
Decision taxonomy
allowlogmonitorthrottlerate-limitchallenge-jschallenge-powturnstiletarpitblock-tempblock-permclose
NetBird integration

Self-host anything. Open zero ports.

Publish apps running at home or in a private network without a static IP, a port-forward or a hole in your firewall. NetBird joins them to NYXR over an encrypted WireGuard mesh, and only NYXR faces the internet.

PUBLICNATInternetNYXR edgeNetBird meshYour privatenetwork

Your private network

Your apps stay behind NAT. Each one dials OUT to the mesh, so nothing inbound is ever opened.

No inbound ports. No port-forwarding. No static IP.Tap a node to see its role.

Outbound only

Each app opens an outbound WireGuard tunnel to the mesh. No port-forward, no static IP, no inbound firewall rule.

Encrypted mesh

NetBird links peers over an end-to-end encrypted overlay, so your origin stays private and unreachable directly.

One public edge

NYXR is the sole internet-facing entry: it filters, runs the WAF, and reaches your app across the mesh.

Architecture

Fast at the edge. Safe by design.

The data plane reads compiled snapshots and never runs a per-request database query. The control plane versions, validates and atomically swaps every change, so a bad config can always be rolled back.

Control plane

The Hono API versions every config change, validates it, swaps it atomically and can roll it back. No edit ever ships unchecked.

Data plane

The OpenResty + ModSecurity gateway reads compiled snapshots locally and never runs a per-request database query. Fast and fail-safe.

Workers

Dedicated workers refresh threat feeds, process events, run backups and dispatch notifications, fully decoupled from the request path.

Observability

ClickHouse, Prometheus and Grafana feed a real-time, fully bilingual Astro console where every security decision is searchable and explainable, alongside live health for every container in the stack.

OpenRestyModSecurity v3OWASP CRSnftablesClickHousePrometheusGrafanaAstro console

Stop your exposure before it starts.

Self-hostable, fully observable, and reversible by design. Bring NYXR in front of any service and neutralize the risk at the edge.