Pricing
Pricing
Free tier includes 1 server with full protection.
Security & trust
Running this agent means granting it privileged access to your server — that's a real ask, and we don't take it lightly. Here's exactly what backs that trust in production:
- Open source
- The agent is MIT licensed. Audit every line before installing.
- Checks before it changes
- A read-only scan of the server runs before installation and every day. Web server changes and threat-list blocking stay off until you turn them on, and never happen where a hosting panel manages the configuration.
- What it reads
- To detect threats it reads system and web server logs, website files for the malware scan (including .env and configuration files), WordPress posts and users for the WordPress scan, and the server's DNS traffic and network connections.
- What it sends
- Security events only: attacker IP, type, time and the details needed to understand them — for a web attack the single log line that triggered it, for malware the file path and the matched text. Full logs and files never leave your server. No telemetry, no third-party sharing.
- Dedicated firewall chain
- All its rules live in its own INFRAFENCE chains, repaired automatically if another tool removes them. Your existing rules are never modified.
- Signed binaries
- Every release is built by GitHub Actions CI with Cosign signatures and build provenance attestation.
- Monitor mode
- Detect everything, block nothing — enable protection when you're ready.
- Clean uninstall
- One command removes the agent and everything it added: firewall chains, web server changes and the service.
