Capability highlights from recent ShieldWall engine and platform work — what you can use, not how it's wired under the hood.
Detection & siteverify
Richer answers when you redeem a response token on your backend.
Reason codes on siteverify
Siteverify responses can now include structured detection signals alongside the verdict — so your app can log why a check passed, was challenged, or was rejected without reverse-engineering opaque scores.
Clearer signal language for integrators
Documentation and response fields emphasize capability-facing reason codes you can act on in policy engines, fraud queues, and support tooling.
Challenge experience
When traffic needs an extra step, the fallback stays fresh and usable.
Managed challenge rotation
Escalation challenges rotate on a managed cadence so bots can’t memorize a fixed puzzle set, while humans still see a short, accessible code path.
Behavioral intelligence
Stronger continuity across visits — without turning verification into a puzzle.
Cross-session behavioural profiling
ShieldWall can learn high-level interaction patterns across sessions so repeat humans stay low-friction and anomalous automation stands out earlier — privacy-minded and policy-tunable.
Console & portal
Invite-gated beta access and self-serve account recovery.
Self-service invite requests
Prospects can request beta access from the marketing site. Ops reviews requests and issues invites — tenants never mint their own.
Password reset for console accounts
Forgot-password and reset flows land in the console so invitees can recover access without waiting on a manual reset.
Invite-gated private beta
Console signup stays invite-only. Valid invites unlock registration; Google sign-in and password signup share the same gate.
Observability
See what the engine is deciding — in near real time.
Sentinel analytics depth
The Sentinel dashboard covers traffic overview, score distribution, behavioural views, PoW performance, geographic and regional breakdowns, threat attribution, event log, actions, and alerts — so operators can tune policy with evidence.
Edge protection
Cheap filters before requests hit your origin.
JA4-aware bot pre-filter
The edge layer can correlate TLS fingerprints and apply lightweight bot pre-filtering with fail-open behaviour when edge state is unavailable — less junk traffic, same availability posture.
Sites can opt into memory-hard Argon2id proof-of-work alongside the default SHA-256 chain — raising the cost of GPU farms without changing the checkbox UX.
Accessible authentication
Verification that respects WCAG-minded alternatives.
WebAuthn / passkey path
When an extra check is needed, users can verify with platform authenticators and passkeys — a first-class alternative to typing codes, aligned with accessible authentication goals.