Skip to content
Waffinnity
Get started
AURORA SECURITY INTELLIGENCE

Turn security signals into decisions with context.

Waffinnity connects what happens at the edge, inside applications and across security services. Aurora helps surface what changed, why it matters and where to investigate next — while the underlying technical evidence stays available.

Cross-signal contextExplainable evidenceGuided actions
AURORA / SECURITY OVERVIEWSecurity attention queue
LIVE
ENVIRONMENT POSTURE91/100
2 items need review
HIGH
ACCOUNT + BOTLogin abuse increased above baselineHigh request velocity and repeated authentication failures on /login.
Review →
MED
ORIGINDirect-origin exposure detectedThe origin is reachable outside the expected edge path.
Inspect →
OK
WAF + DDOSProtection operating within expected rangeNo significant policy or traffic anomaly requires action.
Healthy
Priority is derived from current application and security context; evidence remains available for investigation.
Security intelligence from signal to evidence-backed actionOBSERVECORRELATEPRIORITIZEACT
THE INTELLIGENCE FLOW

Reduce noise without hiding the technical reality.

Raw events are useful for investigation, but they are not the best starting point for every decision. Waffinnity keeps evidence intact while adding application context, related signals, severity and a guided next step.

01

Observe

Collect traffic, enforcement, health and security telemetry from the capabilities already protecting the environment.

02

Correlate

Connect related events around the same application, route, security layer or operational change.

03

Prioritize

Surface the items that deserve attention instead of making every detection look equally urgent.

04

Act

Open the relevant workspace with context and follow a controlled next step while keeping policy changes explicit.

CONNECTED SECURITY SIGNALS

Intelligence becomes stronger when signals keep their application context.

Waffinnity does not treat traffic, identity, workload and domain-security data as isolated dashboards. Each capability contributes evidence that can explain a broader security situation.

EDGE

WAF & Traffic

Request anomalies, blocks, rates, traffic shifts and application policy decisions.

WAF · Traffic Analytics · Events
AVAILABILITY

DDoS & Origin

Traffic bursts, mitigation activity, gateway health and origin reachability or exposure.

DDoS · Origin Health · Edge Path
AUTOMATION

Bot & Account

Automated request behaviour, login pressure, authentication failures and account-focused signals.

Bot · Login · Credential Abuse
WORKLOAD

WordPress

Health, update, security and performance telemetry from inside connected WordPress workloads.

Health · Security · Performance
DOMAIN

Email Security

SPF, DKIM, DMARC and sender evidence that shows domain posture and unknown sending sources.

SPF · DKIM · DMARC
OPERATIONS

Configuration & history

Policy state, operational changes and reportable evidence provide context around what changed and when.

Policy · Events · Reports
AURORA

An intelligence layer that explains before it recommends.

Aurora is designed to make the operational view easier to understand. It can highlight meaningful changes, explain why a finding matters and point to the safest relevant workspace — without replacing the underlying evidence or silently changing security policy.

01Evidence firstThe technical source remains inspectable.02Context awareAdvice stays tied to the affected application or domain.03Human controlledSecurity policy changes remain explicit actions.
AURORA EXPLANATIONWhy this needs attention
HIGH
CORRELATED FINDING

Login abuse increased after a traffic pattern change.

The /login route shows repeated failures from a concentrated set of clients while request velocity increased. Bot and account signals point to the same application window.

Evidence429 / 401 patterns · request velocity · login failuresAffected contextcustomer-portal.example · /login
SUGGESTED NEXT STEPReview Account Protection and Bot policy for this application.
Open workspace →
ACTION CENTER

Start with what needs attention, then drill into evidence.

The operational experience separates attention from healthy background state. Findings can carry severity, affected context, evidence and a next action so teams do not have to reconstruct every incident from raw logs first.

SECURITY ACTION CENTERNeeds attention
3 open
CRITICAL
WAF runtime unavailable on active gatewayapplication.example · Edge Protection
Restore runtime →
HIGH
Origin can be reached around the edgeshop.example · Origin Shield
Review exposure →
MEDIUM
New sender source needs classificationexample.nl · Email Security
Classify source →
FROM SUMMARY TO EVIDENCE

Executive clarity on top. Technical evidence underneath.

A security summary should make status understandable without becoming a black box. Open a finding to inspect the events, timings, routes, decisions and telemetry that support it.

Severity & priorityAffected applicationRelated signalsTechnical evidenceSuggested next stepOperational history
EVIDENCE / customer-portal.exampleCorrelated login-abuse finding
14:32 UTC
14:29:08BOT
Request velocity crossed behavioural threshold/login · concentrated client pattern
14:30:41ACCOUNT
Authentication failures increasedRepeated failures · same application route
14:31:16EDGE
Rate policy started mitigating requestsHTTP 429 · application policy
14:32:00AURORA
Signals grouped into one attention itemPreserves underlying events and application context
Evidence is presented as operational context; Aurora does not replace the source events.
REPORTING & GOVERNANCE

Turn operational security evidence into repeatable reporting.

Security reporting can summarize protection, incidents and activity for recurring review. This creates a bridge between day-to-day operations and the evidence stakeholders need for governance conversations.

01

Security Report

Customer-ready overview of protection state, security telemetry and relevant configuration history.

02

Protection Activity

Summarize enforcement and security activity so recurring review does not start from raw event exports.

03

Scheduled delivery

Use recurring reporting to keep operational evidence available for customers, teams and governance processes.

ONE INTELLIGENCE LAYER, DIFFERENT TEAMS

The same evidence can support different levels of investigation.

OPS

Operations teams

See environment health, current attention items and operational changes before drilling down.

SEC

Security teams

Open findings into request, threat and policy evidence for technical investigation and tuning.

MSP

Providers & Resellers

Prioritize customer environments and translate technical events into a clearer service conversation.

Resellers →
GOV

Governance stakeholders

Use recurring security reports and evidence-backed summaries for periodic review without requiring raw-log expertise.

AURORA SECURITY INTELLIGENCE

See what matters. Understand why. Keep control of the next action.

Start with Waffinnity Foundation and build an operational security view that connects protection, evidence and guided intelligence.