Designed as a 48-hour window
One window per verified domain, no card, no review step, when that entitlement is actually live. Public production is in outage; do not treat this page as a live 48-hour offering.
CAPABILITIES
Emergency
It’s 2:25 AM. Credential stuffing is hammering the login route, stored value is draining, and your team is awake because the pager went off. You do not have time for a demo call.
The night-one path is built to get a verified domain enforcing in about 30 minutes: an account with no card, one DNS record, one middleware line, fail-closed on the routes that are bleeding.
Not live yet. Public production is currently in outage. This page describes the lane and its limits; it is not a window you can start tonight. The signup below opens on the MANDATE dashboard when production is back.
Time estimates are honest, not marketing-round. Domain verification is the step most likely to eat the budget.
No card, no sales gate, no review queue in this lane. It assumes you do not have time for any of those.
One DNS TXT record. Enforcement stays locked until ownership passes; that check is what keeps a free emergency tier from becoming an attacker’s tool.
One middleware line on each attacked route. Your site secret is shown once, at issuance.
Fail-closed on whatever is bleeding: login, redemption, checkout, recovery. The rollback control sits above the mint button, not behind it.
A 48-hour countdown, a one-click end, and the option to verify your work and move to hosted verification.
The window is the wedge and the proof in one mechanism. It is one per verified domain; a tourniquet you can re-arm indefinitely is just a free product with extra steps.
One window per verified domain, no card, no review step, when that entitlement is actually live. Public production is in outage; do not treat this page as a live 48-hour offering.
A report, not a cliff, is the contract we are building to: what the attack looked like, what your normal traffic looks like, and the next actions we would take. It is a design contract, not a shipped artifact.
Verify your work to unlock hosted verification on the attacked route, or drop back to observe on that path and decide from the evidence. The tourniquet does not renew for the same domain.
Night-one enforcement is an offline tourniquet token: verified in your backend with your site secret, no call to MANDATE in the request path. That is why it is fast to deploy and why it is not the product.
This is the tourniquet, not the full product. Hosted, cross-referenced verification is the cure; the tourniquet exists so you survive long enough to adopt it.