Features Architecture Enterprise Pricing Start free
Feature catalog

Everything StarkGate does — built and shipping today.

One pipeline that terminates TLS, routes to any origin, and inspects every request — negative and positive security, traffic policy, AI, full visibility and high availability.

Reverse proxy at the edge

The first hop; forwards clean traffic to your origins.

TLS termination + SNI

Serves the right certificate per hostname.

Automatic certificates (ACME)

Let's Encrypt issuance & renewal, or upload your own.

Upstream routing & balancing

Per-domain routing and load balancing across backends.

Backend health monitoring

Live up/down status per origin in the console.

Multi-IP listening

Run in parallel on a dedicated IP; migrate by DNS.

Real client IP behind CDNs

Trusted-proxy aware — sees the true visitor, not the edge.

Multi-hostname domains

example.com and www.example.com treated as one site.

Curated rule catalog

SQLi, XSS, traversal, command injection, SSRF, scanners and framework exposures.

Per-rule Shadow or Enforce

Trial any rule on live traffic at zero risk, then promote in one click.

Policy templates

Start from a sensible bundle (e.g. WordPress) instead of a blank slate.

RE2-safe matching

All patterns compile to a linear-time engine — no catastrophic backtracking.

Ordered, first-match rules

Per-domain or account-wide (global).

Conditions

Source IP/CIDR, country (GeoIP), and string matchers on path, URL, host or extension.

Actions

Route to a WAF policy, block (403), drop, switch backend, or rate-limit.

Negation ("not in")

For allow-by-exception patterns, with AND/OR grouping between matchers.

Three policy profiles

Basic (rules) · Balanced (+URL allowlist) · Strict (+URL regex & params).

URL learning

Aggregates the paths your real visitors hit and proposes an allowlist.

Parameter learning (private)

Records each parameter's name, type and size — never the values.

Gradual maturation

A path is trusted only after enough sightings across enough distinct hours.

Auto-learn

Scheduled passes that mature and promote candidates — or approve yourself.

Enforcement modes · fail-open

Off / Shadow / Enforce for URLs and params. An empty model never blocks.

Proposals from your traffic

AI proposes new rules from a structural-only summary of suspicious traffic.

Review → Shadow first

Every proposal is validated and RE2-safe; approving adds it in Shadow.

Choice of provider

Anthropic, Groq (cloud), or Ollama (local — free and private).

Automatic tech detection

Fingerprints your stack and suggests matching rule packs.

Overview dashboard

Traffic, blocks and trends at a glance.

Event log of every decision

Search by ID, decision, IP, host, policy, path, rule and time window.

Decision Replay

Re-run any logged request through the live pipeline, stage by stage.

Attackers + one-click block

See the worst offenders and block an IP instantly, in real time.

Per-policy logs

Jump straight from a policy to its own traffic.

Audit trail

Operator actions are recorded.

Email alerts

On attack spikes, unhealthy backends, or failed cert issuance.

SMTP or PingMail

Sent via SMTP or the PingMail HTTPS API — no mail server required.

HA / config sync

F5-style node pairing; push, pull, or auto-accept for continuous sync.

Disaster recovery

Automatic daily backups with retention, restore, download and upload.

Graceful degradation

A down backend disables only its features; the gate keeps serving.

Self-healing startup

Waits for datastores after a reboot instead of latching into a degraded state.

Kill switch & live reload

Disable enforcement or apply config changes without dropping traffic.

Role-based access (RBAC)

Super-admin and tenant-admin roles.

Multi-tenant, multi-domain

Protect many customers' sites from one console.

Two-factor auth (TOTP)

Works with any authenticator app.

Brute-force lockout

Account lockout on login after failed attempts.

Ready to see it?

Deploy in parallel, watch the log, promote what's clean.