Frequently asked questions

Practical answers about onboarding, accounts, monthly billing, DNS, API access, and the current security boundaries.

Do I need to move my website hosting?

No. Hexa Shield sits in front of your existing origin. You keep the application and hosting stack while DNS routes eligible traffic through the protection layer.

Can I keep my current DNS provider?

Yes. External-DNS onboarding is supported. You can also enable Hexa Shield authoritative DNS when that deployment feature is configured.

Are plans yearly or monthly?

The commercial catalog is monthly only. Visitor accounts are free until a paid monthly plan is activated.

When does a Visitor become a Customer?

Customer access is granted server-side after a paid checkout is independently verified with the configured payment provider. A browser redirect alone does not grant access.

Does Hexa Shield provide API keys?

Yes. Customer API keys are scoped, their secrets are displayed once, and only a hash plus display prefix are stored afterward.

Does Hexa Shield stop all DDoS attacks?

No. It provides application-layer filtering and abuse controls. A single deployment does not replace a large global volumetric DDoS scrubbing network.

How much analytics history is available?

The current live analytics API supports up to 168 hours (7 days) from Redis-backed hourly counters. Longer historical rollups are not claimed until implemented.

Can I use Discord to sign in?

Yes, when Discord OAuth is configured. Hexa Shield verifies the Discord access token server-side and requires a verified Discord email address.

Can users make themselves Admin?

No. Admin access is a platform role enforced by the backend. It is not exposed as a self-service setting.

Need help with your setup?

Review the documentation or contact the Hexa Shield operator for deployment and account assistance.