Skip to content
ZEROWARN
How it is validated

Not claimed, demonstrated: every figure has its own experiment behind it

SHIELD is validated on two fronts: real attacks executed against a real server —every capability with its own scenario, not simulations— and real traffic from production sites, with the applications and plugins that are actually served out there. In total, 2.6 million real files and events put through the same detection path that runs on the server. Everything below is measured, not estimated.

47validation scenarios on a real server, not on simulations
1,421automated tests, not a single failure
6 / 6planes tested end to end
0shortcuts: every capability built and wired
Measured, not promised

What was measured, over what, and with what result

None of these numbers comes from a model in isolation: they are measured through the same detection path that runs on the server, over 2,087,314 legitimate files —content-manager code, plugins, themes and libraries— and 554,801 events of real traffic from the most widely deployed CMSs and shops in the world, and against attacks actually executed. The zero false positives are a consequence of the design, not of luck: acting requires a certainty signal, and across those two million legitimate files not one reached it —those that raised a hand stayed at warning, without touching the service a single time—. All of it reproducible on your own traffic during the pilot.

What was measured, over what, and with what result
What is measuredOver whatResult
Wrong actions on legitimate files2,087,314 files from content managers, plugins, themes and libraries0 containments
False positives on real traffic554,801 events from the most widely deployed CMSs and shops in the world, running0
Malware the system had never seenHeld-out corpus, from a source outside the training set86.9% detected
Brand-new families recognised by intentCode fragments at the instant they execute96.6%
Attacks actually executed against the serverRCE, local and remote inclusion, gadget deserialisation, webshell drop100% detected and contained
Decision latencyBehaviour check, measured in the agent itself32 ns
Cost on the serverAgent running, hour after hour≈50 MB RAM · <1% of one core
The questions we always get

The usual doubts, answered straight

"What if it takes down a legitimate site?"

By design it cannot happen lightly: containment requires a certainty signal, and a suspicion stays a warning. And if you were wrong anyway, everything is reversible: a neutralised file carries how to restore it and the account is released instantly. Across more than two million legitimate files from real sites, none reached containment. Not one.

"What will it cost me in performance?"

A single binary, with no external engines to load and no cloud lookups. The per-event decision resolves in microseconds —the behaviour check in 32 nanoseconds— so you keep your accounts-per-server density and your margins.

"Do I have to touch my stack?"

No. No proxy to insert, no interpreter extension to install and maintain version after version, nothing to recompile. A self-contained installer, one configuration file and any distribution. You install a new PHP version and SHIELD recognises it and calibrates itself, with no restart.

"What if the attacker tries to switch it off?"

It only obeys signed orders with an increasing sequence number, verifies its own integrity and, if it loses contact with control, returns to its safe state on its own. And if it ever stopped seeing because of saturation, it does not let things through: it denies. What cannot be observed is not allowed.

"And against what nobody has seen yet?"

That is exactly its ground. There is no signature to wait for: SHIELD judges by what the code does when it runs. On completely new malware families its intent engine recognises 96.6%, and the whole system catches 86.9% of malware from an outside source it had never seen.

"Does my customers' code leave my server?"

No. SHIELD decides inside the server, with the intelligence embedded in the binary itself. No code is sent to any cloud, yours or ours.

Every capability on this page is implemented and verified in the source code, and every figure reproduces with one command over the captured traffic —and over your own during the pilot—. No testimonials and no third-party references are used. Last verified: August 2026.

See it on your own data

Deploy the agent on three servers and leave it in observation mode. Within days you will have the figures for your own traffic: what it would have detected, what it would have contained and with how much noise. Turning on blocking is a later configuration change, and it is your call.