Discord security platform
Security and incident response for Discord — not just moderation.
AEGIS treats your server like production infrastructure: deterministic threat detection, contained incidents, numbered cases, structured appeals, and an audit trail you can actually investigate. Explainable by design — every automated action shows its reasoning.
Posture: elevated
Join-wave signal correlated · containment: slowdown active
- critical2m ago
raid.join_wave
14 accounts joined in 60s
- high9m ago
link.phishing_domain
flagged domain in #general
- medium24m ago
spam.mention_burst
11 mentions in one message
- low41m ago
account.young_join
account created 3d ago
Built for the failure modes Discord actually has
No tool prevents every attack. AEGIS narrows the window: detect fast, contain automatically within limits you set, and leave a trail good enough to learn from.
Sentinel detection engine
Scores every event against deterministic, explainable risk factors. No black boxes — every signal shows exactly why it fired.
Raid protection
Detects coordinated join waves by velocity, account age, and profile similarity, then applies your configured containment response.
Anti-nuke action budgets
Rate-limits destructive admin actions — channel deletions, mass bans, webhook spam — per actor, with automatic containment when a budget is exceeded.
Link & phishing protection
Checks posted links against known-bad domains and impersonation patterns. Suspicious links are flagged for review, not silently trusted.
Case management
Every enforcement action becomes a numbered case with subject, moderator, reason, expiry, and full history — searchable from the dashboard.
Incident response
Correlated signals open incidents with a lifecycle: detect, contain, investigate, resolve. Timelines record every step and actor.
Appeals
Subjects can appeal cases through a structured flow. Moderators review statements and decide with a recorded reason.
Audit integrity chain
Administrative and automated actions are written to an append-only audit log with correlation IDs, so investigations can be reconstructed.
How Sentinel scores risk
Sentinel is deterministic and explainable. Each event is evaluated against weighted factors; the factors and their contributions are recorded with the signal. The same input always produces the same score — so moderators can audit any decision, and false positives can be traced to a specific factor and tuned.
Thresholds map scores to actions you configure: log, flag for review, or contain. Sentinel never invents context it does not have.
Deep dive on the detection engineExample factor breakdown
- +25
Account age < 7 days
Created 2 days before join
- +30
Join velocity anomaly
14 joins in 60s vs. baseline 0.4/min
- +10
Default avatar + no badges
Profile matches raid cohort
- +20
Message contains flagged domain
discord-nitro[.]gifts
high exceeds the contain threshold (60) in this example configuration
Incident-response lifecycle
- Observe: Gateway and audit-log events stream in as structured, guild-scoped facts.
- Detect: Events become scored signals with visible risk factors.
- Contain: Mode-gated responses limit damage — slowdown, quarantine, lockdown — within budgets you set.
- Investigate: Incidents collect signals, cases, and timeline notes into one reviewable picture.
- Enforce: Actions pass hierarchy checks and become numbered, appealable cases.
- Audit: Every step lands in a hash-chained, append-only audit log.
- Improve: False-positive reviews and rule-execution records feed detection tuning.
- Observe
- Detect
- Contain
- Investigate
- Enforce
- Audit
- Improve
- Observe
- Gateway and audit-log events stream in as structured, guild-scoped facts.
- Detect
- Events become scored signals with visible risk factors.
- Contain
- Mode-gated responses limit damage — slowdown, quarantine, lockdown — within budgets you set.
- Investigate
- Incidents collect signals, cases, and timeline notes into one reviewable picture.
- Enforce
- Actions pass hierarchy checks and become numbered, appealable cases.
- Audit
- Every step lands in a hash-chained, append-only audit log.
- Improve
- False-positive reviews and rule-execution records feed detection tuning.
Security & privacy posture
Retention policies
Signals, evidence, and analytics are kept only for their configured retention windows, then purged. Retention is per data class, not one blanket setting.
Evidence access logging
Reading case evidence is itself an audited event. Investigators leave a trail just like the actions they investigate.
Role-based access control
Dashboard access mirrors the API's authorization model. The browser never decides what you can see — the API does.
Separation of duties
Appeal deciders are distinct from original case actors where configured, and automated actors are always labeled as automated.
Pricing
Plans are being finalized — pricing ships soon.
Community
coming soonCore protection for smaller servers.
- Sentinel detection
- Raid protection
- Case management
- 30-day retention
Pro
coming soonFull incident response for active communities.
- Everything in Community
- Incident timelines
- Appeals workflow
- Analytics
- 90-day retention
Enterprise
coming soonFor networks and large operations.
- Everything in Pro
- Extended retention
- Priority support
- Custom review workflows