CAPABILITIES

Emergency

Under attack right now?

It’s 2:25 AM. Credential stuffing is hammering the login route, stored value is draining, and your team is awake because the pager went off. You do not have time for a demo call.

The night-one path is built to get a verified domain enforcing in about 30 minutes: an account with no card, one DNS record, one middleware line, fail-closed on the routes that are bleeding.

Not live yet. Public production is currently in outage. This page describes the lane and its limits; it is not a window you can start tonight. The signup below opens on the MANDATE dashboard when production is back.

What happens after you hit sign up

Time estimates are honest, not marketing-round. Domain verification is the step most likely to eat the budget.

  1. ~2 min

    Sign up

    No card, no sales gate, no review queue in this lane. It assumes you do not have time for any of those.

  2. ~5 min

    Verify your domain

    One DNS TXT record. Enforcement stays locked until ownership passes; that check is what keeps a free emergency tier from becoming an attacker’s tool.

  3. ~10 min

    Install

    One middleware line on each attacked route. Your site secret is shown once, at issuance.

  4. ~10 min

    Enforce on the attacked routes

    Fail-closed on whatever is bleeding: login, redemption, checkout, recovery. The rollback control sits above the mint button, not behind it.

  5. ongoing

    Watch

    A 48-hour countdown, a one-click end, and the option to verify your work and move to hosted verification.

02:47
account created, no card
02:51
domain verified (DNS TXT)
02:58
middleware line deployed
03:09
tourniquet enforcing on /login + /redeem
03:15
countdown running, rollback armed

Free, deliberately temporary

The window is the wedge and the proof in one mechanism. It is one per verified domain; a tourniquet you can re-arm indefinitely is just a free product with extra steps.

Designed as a 48-hour window

One window per verified domain, no card, no review step, when that entitlement is actually live. Public production is in outage; do not treat this page as a live 48-hour offering.

Hour 48 is designed to end with a baseline

A report, not a cliff, is the contract we are building to: what the attack looked like, what your normal traffic looks like, and the next actions we would take. It is a design contract, not a shipped artifact.

Then convert or drop to observe

Verify your work to unlock hosted verification on the attacked route, or drop back to observe on that path and decide from the evidence. The tourniquet does not renew for the same domain.

What the offline token does — and what it deliberately does not

Night-one enforcement is an offline tourniquet token: verified in your backend with your site secret, no call to MANDATE in the request path. That is why it is fast to deploy and why it is not the product.

What it does

  • Verifies locally in your backend with your site secret; no callback to MANDATE in the verify path.
  • Keeps enforcing on already-issued tokens while our edge is unreachable.
  • Short-lived (minutes), bound to one route class and one window, fail-closed exactly where you choose.
  • No network call in the request path.

What it does not do

  • Stateless: a captured token can be replayed inside its TTL.
  • No revocation: a leaked token lives until it expires.
  • No cross-referencing: no replay markers, lineage, or session trust. That is the hosted stack’s job.
  • It stops the bleeding. It is not the cure.

This is the tourniquet, not the full product. Hosted, cross-referenced verification is the cure; the tourniquet exists so you survive long enough to adopt it.