Skip to content
Klacos
Protection

Website security: see what’s targeting your site, and stop it before your server

Every day, bots scrape your pages, scripts probe your forms for a weakness and bursts of requests tie up your server. Most of the time, nobody notices. Klacos analyses every visit in front of your site, stops what threatens it before it reaches your server, and lets your visitors through without a challenge by default. Every decision keeps its reason.

Illustration: a workstation protected by a padlock.
The problem

What a site open to the internet is up against

Bots helping themselves

They scrape your prices and content, create fake accounts and try stolen passwords on your login page.

Requests probing for a weakness

An injection slipped into a form, a published flaw in your CMS or a plugin: one request is all it takes.

Bursts that tie up your server

A script hammering the same expensive route, with your customers queuing behind it.

Doors left open

An admin area the whole world can see, a staging site in search results, a partner blocked by mistake.

You pay for all of it: a server busy serving bots, copied content, fake accounts to clean up, a flaw exploited before the update lands. And protection switched on in a hurry often blocks customers along the way, with nobody able to say why.

This traffic isn’t going away on its own: the tools that automate scraping, password attempts and the hunt for vulnerabilities are freely available, and a site doesn’t have to be well known to see them pass through. Better to know what they’re doing on yours before they cost you more.

Our approach

One read of every visit, shared by every protection

Klacos looks at every visit before your server does: how it connects, how it moves through your site, its pace, the network it comes from. Bot management, the web application firewall and rate limiting all work from that same read. An attack caught by the firewall makes its sender a suspect across your whole site; a verified bot gets through without being slowed down.

Observe first, decide next, enforce last

Every protection starts in observation. Before you enforce a setting, you replay it against your past traffic: the console tells you how many requests it would have caught, and how many of them came from visitors judged to be human. Then you switch it on, site by site, one step at a time.

No decision without a reason

Every decision keeps its reason and a reference. A blocked visitor can appeal, and you let them back in with one click.

One analysis

One view of each visitor, shared by every protection, and one console to manage it all.

No challenge by default

No CAPTCHA by default, no required script. One isolated clue isn’t enough to block anyone, and a visitor we know nothing about isn’t blocked on that basis.

The page on how detection works follows a visit from request to decision.

Bots

Bots, handled according to what they do on your site

Part of your traffic isn’t human, and not all of it looks alike. Bot management assesses each visit on its behaviour as a whole, across your site, and only slows down, checks or blocks what deserves it. By default, your visitors get no box to tick and no pictures to identify.

The bots your site needs get through: search engines, monitoring, link previews, payment providers. Verified bots are checked with their operator, and anything borrowing their name is caught out. AI crawlers are a category of their own: you decide whether they get in, site by site, and our guide on what to do about AI crawlers helps you make the call.

When someone is blocked, they know it and can appeal: every decision explains itself, and you let a visitor back in with one click.

Illustration: a checkpoint gate whose doors open onto a bright corridor.
Attacks

Attacks and bursts, stopped before your server

The web application firewall reads the content of each request and stops the ones probing for a weakness: SQL injection, XSS, file inclusion, a known flaw in software you run. It starts by watching, and an exception takes one click.

Rate limiting stops an address, a network or a script from wearing out your server, your forms or your API. An ordinary visit stays well below the limits; a burst gets a response telling it when to come back.

An attack that has been spotted counts against whoever sent it: that visitor gets a closer look across the rest of your site.

Illustration: blocks and modules stacked on a base.
Access

Who gets in, and over which encrypted connection

Access rules open your site to the people who should get in and close it to everyone else: a partner or a security audit allowed for as long as you set, a path kept for your own addresses, a country filtered out, a staging site behind a password.

SSL/TLS certificates for each of your domains are issued and renewed automatically, and the console warns you well before anything expires. The usual security headers are one click away.

Illustration: a lit server room with rows of racks.
Questions

Questions about protecting your site

Do I have to switch everything on?

No. Each protection is switched on site by site, and each starts in observation: you see its effect before it applies.

Will my visitors see a CAPTCHA?

Not by default. A doubtful visit is first slowed down, then checked without showing anything. A visible challenge exists, off by default: you decide whether it appears.

Do you protect against DDoS attacks?

Against attacks aimed at your website, yes: request floods, slow connections, password attempts in bulk, API abuse. A volumetric attack that saturates the network link before it reaches a web service is not covered: that is a job for your hosting provider or network operator.

Do I need to change my site or my server?

No. Klacos sits in front of your current server, which stays the origin. The protection adds nothing to your pages; the browser module and the analytics, both optional, add a script if you switch them on.

Opening early 2027

See what’s targeting your site before you block anything

Request early access: everything starts in observation, on your own traffic. Or tell us now what’s hitting your site: bots, attacks, request floods.