Fast firewall rules
Firewall rules are prepared before use so each request can be checked quickly.
Product plane / Security & WAF
Security & WAF
operationalHyx combines reputation, firewall rules, managed protections, visitor behavior, and connection identity in one decision. Each action is recorded clearly for incident review.
Core capabilities
Security decisions combine your rules with reputation and visitor behavior. Teams can block, verify, slow, label, or observe traffic from one service and one request record.
SEC-01 / compiled policy
3,000 rules / production
Policy input
rule / 942100
Action
BLOCK / 403
flag actor
Compiled execution plan
01 / Index
Resolve exact and range-backed conditions
02 / Fuse
Collapse adjacent comparisons into one pass
03 / Evaluate
Read normalized request and actor state
04 / Enforce
Block 403 · attach rule 942100
Evaluation
~9µs
3,000-rule production profile
Before compile
34µs
unfused policy path
Handling
one pass
request checked once
Firewall rules are prepared before use so each request can be checked quickly.
Write rules that match the URL, country, device, headers, request size, or a visitor's recent behavior.
Matching rules can block, challenge, rate-limit, bypass cache, tag a visitor, or suppress a known false positive.
Managed industry rules check each request for common web attacks.
The full rule set checks each request in about two millionths of a second.
Turn protection on with a switch, and quiet any single rule that's too noisy for your particular site.
How it works
Hyx checks policy before release, then distributes it to each location. Requests are reviewed locally so decisions stay fast and explainable.
SEC-02 / early client identity
before site content
Bot confidence
000
Human structure
Supported browser
Connection identity
recognized connection pattern
Moment
on connection
Method
combined evidence
Review reputation, location, connection details, and recent visitor behavior.
Apply your firewall rules and selected managed protections.
Compare several indicators before acting on suspicious traffic.
Block, verify, slow, allow, label, or observe, with the reason saved to the request record.
Operational detail
A concise list of what this part of Hyx provides. Roadmap items are labelled explicitly.
Fast firewall rules
Rules across request and risk fields
Seven ways to respond
Industry-standard protection, built in
Deep inspection, no slowdown
Managed rules, tuned your way
Known-malicious address blocking
Block or allow by country
Rate limiting that only slows abusers
Ban once, blocked everywhere
Browser verification challenges
Verified crawler allowlist
Browser security presets
Login attacks caught early
Repeat offenders stay flagged
Background behavioral signals
Connection identity
Pre-HTTP bot signals
Trusted and known-bot signatures
Fingerprinting across transport protocols
Additional transport signals
Browser and automation labels
Next system / AI engine
See how Hyx AI reviews 38 signals, learns safely, checks updates, and rolls back immediately.