Website access rules: open your site to the right people, close it to the rest
A partner slowed down by your own protection, an admin area the whole world can reach, a staging site a search engine has found: a badly set door costs you. Klacos applies your access rules in front of your site, and each one takes a single step in the console.
Badly set doors cause the everyday incidents
A partner held up
Your uptime monitor or the audit you commissioned is mistaken for a bot. The alerts go quiet, and the report is worthless.
A door open to everyone
An admin area reachable from anywhere, a staging site in search results: nothing protects them before your server.
A rule nobody remembers
An exception added years ago, with no reason and no end date. Nobody dares remove it.
Those who need to get through do, without waiting
Your uptime monitor, the agency testing your site, the provider that confirms your payments: they need to get through every time, whatever their pace. An allowance lets them in without bot management slowing them down or checking them, and without them hitting the limits of rate limiting.
An allowance is either permanent, with the reason behind it, or temporary, with an end date: the audit commissioned for a week loses its access at the end of the week, without anyone having to remember. A payment provider can be allowed on the paths you declare for it, and nowhere else.
What only concerns you stays closed
Your admin area doesn’t need to be open to the world. Keep its path for your own addresses: everyone else is refused before they reach your server. A country where you have neither customers nor partners can be closed off for the whole site, or for just part of it.
A staging site is protected by a password, on the whole site or on a path, so passers-by and search engines stay out. It’s a staging lock, not a sign-in for your users, which remains your application’s job. All of it travels over an encrypted connection, with certificates that renew themselves, as part of your site’s protection.
Try a rule before you enforce it
A rule can run in observation first: it refuses nothing, and the console counts the requests it would have caught. A country filter that would have shut out customers shows up before you close the door on them. Before publishing, you simulate a request to see what would happen to it. Every version is kept, and the previous one comes back in one step if a rule gets in the way of someone it shouldn’t.
Simple rules to open and close your site
Allowlists
Temporary access
Payments and webhooks
Reserved paths
Country filter
Protected staging
A reason for each rule
Tested and reversible
Questions about access rules
Does the staging password replace a user sign-in?
No. It’s a lock that keeps a staging site away from passers-by and search engines. Your users' accounts are still managed by your application.
Can I allow a security audit for a few days?
Yes. A temporary allowance has an end date and disappears on its own when it is reached.
Can the location filter target a city?
No. It stops at country level, for the whole site or for a path.
What does a refused visitor see?
A clear refusal, shown on your site’s own error page if you have set one up.
See who a rule would catch, before it applies
Request early access, or talk to us about the partners, tools and private areas of your site.