The platform
Every defense your sites need — running quietly inside them.
Install it once and let it run. Policies, alerts, and reports do the work — your sites stay protected without asking for your attention.
NormalizeEvaluateDecideEnforceTelemetry
Everything it does
A complete WAF — not a plugin with a few rules.
Everything ships in the same install — the standard protections, plus what only an in-stack firewall can do.
OWASP CRS rule engine
SQLi, XSS, RFI/LFI, command-injection and path-traversal inspection from the OWASP Core Rule Set.
›For the technical reader
Anomaly scoring
Decisions rest on accumulated evidence, not a single string match. Rules contribute weighted scores, and low-confidence observations are recorded for review instead of blocking anyone.
›For the technical reader
Full request-body inspection
Deep inspection of JSON, REST and GraphQL payloads.
›For the technical reader
AI & bot defense
Classifies and blocks automated clients — scrapers, scanners, credential bots.
›For the technical reader
Brute-force & login protection
Rate-limits and locks down login endpoints against credential-stuffing.
›For the technical reader
Geo-blocking
Allow or block by country, tuned per site.
›For the technical reader
Five-stage pipeline
Every request normalized, evaluated and decided before your app runs.
›For the technical reader

Geo-blocking — per-site country rules
Custom rules
Write your own tenant rules on top of the managed set, per site.
›For the technical reader
Instant policy sync
Change a rule in the dashboard and it's enforcing on the site in seconds — not on the next scheduled check.
›For the technical reader
IP allow & blocklists
Allow or block by IP or CIDR range, with temporary bans that expire on their own.
›For the technical reader
Rate limiting
Per-endpoint throttling backed by atomic counters.
›For the technical reader
Fingerprint blocking
Block repeat attackers by client fingerprint.
›For the technical reader

Custom rules — tenant rules on top of the managed set
File-upload protection
Blocks malicious uploads before your app touches them: dangerous extensions, disguised file types, embedded code.
›For the technical reader
Two-factor authentication
Dashboard-wide control — coming soon
Authenticator-app codes with backup codes on protected login flows.
›For the technical reader
Login audit log
Every login attempt recorded — hashed IP, country, user agent — with one-click unlock of locked-out IPs.
›For the technical reader
Never locked out
A firewall that can lock out its own admin is a liability. If it ever happens here, there's always a way back in — no FTP required.
›For the technical reader
Security headers
Turn on hardened response headers per site — enforced in Protect mode.
›For the technical reader

Live events feed — a blocked SQLi attempt
What running inside unlocks
Capabilities an edge firewall cannot reach — because it never gets inside the site.
Coming soon
Virtual patches that auto-update
Patch the vulnerable plugin from inside the site. A proxy can't reach it; we run where it lives.
Coming soon
Vulnerability & malware scanning
Continuous scanning for known-vulnerable components across every site you manage.
Coming soon
Headless-WordPress support
Protection for decoupled WordPress front-ends.
Coming soon
IP & network reputation
Score requests by ASN and network history before the rules even run. ASN already shows in every event for visibility; enforcement is what's coming.
Secure by design
Protecting your sites — and your visitors' privacy.
Site data stays scoped to your account. What reaches your dashboard is hashed with a key that never leaves the site — so even we can't turn it back into a real visitor.
Signed policies
Every rule set is cryptographically signed; the site verifies it before applying.
›For the technical reader
Privacy by design
IPs and user-agents are hashed per site with a key that never leaves the site. A leaked database reveals no raw IPs.
›For the technical reader
HMAC-SHA256 where the secret never leaves the site, replacing plain unsalted hashing.
Audited IP reveal
IPs are hashed by default — but when an investigation needs the real address, reveal it with one click. Every reveal is recorded, capped, and the raw IP deletes itself on the schedule you choose.
›For the technical reader
Full inspection, minimal retention
Every request is read in full — but only field names, rule IDs, paths and hashed IPs are stored. Raw request bodies are never written to disk.
›For the technical reader
Coming soon
Audit-ready by default
Every security event on every site is logged with a timestamp, rule ID and outcome — exportable whenever a client asks.
›For the technical reader
Fail-open by design
If the firewall ever errors, your site stays up.
›For the technical reader
MySQL → SQLite → file) keeps it running across hosts.
Works through outages
If our control plane vanished tomorrow, your sites would keep enforcing the last signed policy — indefinitely. Even a brand-new install that has never connected still blocks with its built-in signed baseline rules.
›For the technical reader
For developers, freelancers & agencies
Your clients see you. We stay behind you.
Run every client’s protection from one dashboard, under your brand, at a margin you set.
Fleet dashboard — every client site behind one login: policy, live events, down detection.
Set policy once — apply rules fleet-wide, stage in Monitor, enforce when you’re sure.
Co-branded reports and block pages — “Secured by Domain Dome · Managed by [Your Brand].”
clientco.com/wp-login.php

403 Forbidden
This request was identified as a potential threat and stopped before it reached the site.
Secured by Domain Dome · Managed by [Your Agency]
Ray-ID: 7f3a91c2e4
Reason: sqli_rule_942100
What your client's visitor sees — your brand, our engine.
How it works
Every request, inspected in five stages.
Every request is decoded, evaluated and decided on before your application runs. Allowed, challenged or blocked — the verdict is reached inside your site.
Any platform
One core. A thin adapter per platform.
One core does the security work. A thin adapter connects it to each site and every site reports to one dashboard.
Platform-agnostic core
Does all the security work
Thin adapter
WordPress, WooCommerce, and more
One dashboard
Every site, one control center
Live now
WordPress
Live
WooCommerce
Live
Coming soon
Custom PHP
Coming soon
Node.js
Coming soon
APIs
Coming soon
Need a platform we don't list yet?
›For the technical reader
request provider, response enforcer, storage, telemetry, identity, policy loader, geo resolver and ASN resolver. WordPress is the first adapter (a must-use plugin); a universal-PHP adapter is planned to cover Laravel, Drupal, Magento and other PHP apps. Non-PHP runtimes are on the roadmap.See it running on your sites.
Book a demo, or grab early access.
No DNS changes. No rerouting. Installs in minutes.