Opaque server sessions
Session secrets are stored as hashes in PostgreSQL and delivered through HttpOnly cookies.
Hexa Shield focuses on application-layer filtering, abuse controls, tenant isolation, secure account access, and operational visibility. It does not claim perfect security or unlimited volumetric DDoS absorption.
Session secrets are stored as hashes in PostgreSQL and delivered through HttpOnly cookies.
API-key secrets are shown once and only the hash plus a display prefix are stored afterward.
Domain, rule, DNS, analytics, and security-event handlers resolve resources through the authenticated owner.
Security-event storage avoids retaining sensitive request headers in plain form.