Discord security platform

Security and incident response for Discord — not just moderation.

AEGIS treats your server like production infrastructure: deterministic threat detection, contained incidents, numbered cases, structured appeals, and an audit trail you can actually investigate. Explainable by design — every automated action shows its reasoning.

Command CenterIllustrative preview

Posture: elevated

Join-wave signal correlated · containment: slowdown active

  • critical

    raid.join_wave

    14 accounts joined in 60s

    2m ago
  • high

    link.phishing_domain

    flagged domain in #general

    9m ago
  • medium

    spam.mention_burst

    11 mentions in one message

    24m ago
  • low

    account.young_join

    account created 3d ago

    41m ago

Built for the failure modes Discord actually has

No tool prevents every attack. AEGIS narrows the window: detect fast, contain automatically within limits you set, and leave a trail good enough to learn from.

Sentinel detection engine

Scores every event against deterministic, explainable risk factors. No black boxes — every signal shows exactly why it fired.

Raid protection

Detects coordinated join waves by velocity, account age, and profile similarity, then applies your configured containment response.

Anti-nuke action budgets

Rate-limits destructive admin actions — channel deletions, mass bans, webhook spam — per actor, with automatic containment when a budget is exceeded.

Link & phishing protection

Checks posted links against known-bad domains and impersonation patterns. Suspicious links are flagged for review, not silently trusted.

Case management

Every enforcement action becomes a numbered case with subject, moderator, reason, expiry, and full history — searchable from the dashboard.

Incident response

Correlated signals open incidents with a lifecycle: detect, contain, investigate, resolve. Timelines record every step and actor.

Appeals

Subjects can appeal cases through a structured flow. Moderators review statements and decide with a recorded reason.

Audit integrity chain

Administrative and automated actions are written to an append-only audit log with correlation IDs, so investigations can be reconstructed.

How Sentinel scores risk

Sentinel is deterministic and explainable. Each event is evaluated against weighted factors; the factors and their contributions are recorded with the signal. The same input always produces the same score — so moderators can audit any decision, and false positives can be traced to a specific factor and tuned.

Thresholds map scores to actions you configure: log, flag for review, or contain. Sentinel never invents context it does not have.

Deep dive on the detection engine

Example factor breakdown

  • Account age < 7 days

    Created 2 days before join

    +25
  • Join velocity anomaly

    14 joins in 60s vs. baseline 0.4/min

    +30
  • Default avatar + no badges

    Profile matches raid cohort

    +10
  • Message contains flagged domain

    discord-nitro[.]gifts

    +20
Risk score85 / 100

high exceeds the contain threshold (60) in this example configuration

Incident-response lifecycle

  • Observe: Gateway and audit-log events stream in as structured, guild-scoped facts.
  • Detect: Events become scored signals with visible risk factors.
  • Contain: Mode-gated responses limit damage — slowdown, quarantine, lockdown — within budgets you set.
  • Investigate: Incidents collect signals, cases, and timeline notes into one reviewable picture.
  • Enforce: Actions pass hierarchy checks and become numbered, appealable cases.
  • Audit: Every step lands in a hash-chained, append-only audit log.
  • Improve: False-positive reviews and rule-execution records feed detection tuning.
  1. Observe
  2. Detect
  3. Contain
  4. Investigate
  5. Enforce
  6. Audit
  7. Improve
Observe
Gateway and audit-log events stream in as structured, guild-scoped facts.
Detect
Events become scored signals with visible risk factors.
Contain
Mode-gated responses limit damage — slowdown, quarantine, lockdown — within budgets you set.
Investigate
Incidents collect signals, cases, and timeline notes into one reviewable picture.
Enforce
Actions pass hierarchy checks and become numbered, appealable cases.
Audit
Every step lands in a hash-chained, append-only audit log.
Improve
False-positive reviews and rule-execution records feed detection tuning.

Security & privacy posture

Retention policies

Signals, evidence, and analytics are kept only for their configured retention windows, then purged. Retention is per data class, not one blanket setting.

Evidence access logging

Reading case evidence is itself an audited event. Investigators leave a trail just like the actions they investigate.

Role-based access control

Dashboard access mirrors the API's authorization model. The browser never decides what you can see — the API does.

Separation of duties

Appeal deciders are distinct from original case actors where configured, and automated actors are always labeled as automated.

Pricing

Plans are being finalized — pricing ships soon.

Community

coming soon

Core protection for smaller servers.

  • Sentinel detection
  • Raid protection
  • Case management
  • 30-day retention

Pro

coming soon

Full incident response for active communities.

  • Everything in Community
  • Incident timelines
  • Appeals workflow
  • Analytics
  • 90-day retention

Enterprise

coming soon

For networks and large operations.

  • Everything in Pro
  • Extended retention
  • Priority support
  • Custom review workflows