Two paths: a free start for a single site when it launches, or Enterprise for multi-tenant, highly-available deployments.
For a single site — measure before you block, without touching the app.
The full gate — multi-tenant, highly available, self-learning across all your domains.
Every protection runs in Shadow first. We treat a false positive as a product failure.
Not before you decide. Every layer runs in Shadow first — it logs what would have been blocked without blocking — so you catch false positives in the log, not in production.
No. StarkGate ships as native systemd services, cross-compiled for Linux, and is easy to run alongside existing sites.
It doesn't have to. Run the AI rule-assist fully local with Ollama — nothing leaves your network. Cloud providers (Anthropic, Groq) are also available, and receive structural signal only.
Yes. Deploy in parallel on a dedicated IP at zero risk, watch the log, then migrate traffic by DNS — gradually and reversibly.