Architecture

Deploys in your path. Plugs into your stack.

Yod sits in front of your application as a transparent reverse proxy - and connects to the security tools you already run. Scroll to watch it slot into a real deployment, layer by layer.

Scroll to build it out

01 · Data plane

In your path, invisibly.

Yod deploys as a transparent reverse proxy in front of your application - no code changes, no SDK. Real users pass straight through; attackers are silently rerouted to an AI-generated chimera.

02 · Data plane

Behind your CDN.

Put Yod behind your CDN and it simply becomes your origin. Caching, TLS, and edge routing keep working exactly as they do today - every request just reaches Yod on its way in.

03 · Data plane

Around your WAF.

Keep your WAF - but put it on the clean leg, behind Yod. By the time traffic reaches it, attacker sessions are already gone, so it only ever inspects legitimate traffic. False positives are eliminated by construction, not tuned away.

04 · Control plane

Feeds your SIEM.

Every classification, redirect, and chimera session streams to your SIEM. All of Yod’s activity is available for central review, right alongside the rest of your security telemetry.

05 · Control plane

Drives your SOAR - and is driven by it.

Yod connects to your SOAR both ways. It can trigger smart, automated response, and it can itself be automated and orchestrated by your existing playbooks.

06 · Control plane

Generates intelligence. Ingests it, too.

Yod produces unique, first-party intelligence from real adversary behaviour in the chimeras - and ingests your threat-intel feeds to recognise known attackers and tune its deceptions.

07 · Control plane

Programmable to the core.

Everything Yod does is fully manageable by API and MCP - so your own automation, agents, and AI tooling can configure, query, and drive Yod directly.

control plane
Real User
normal browsing
Attacker
SQL injection attempt
Yod
detect · analyze · route
Your Real App
untouched · no false positives
AI Chimera
fake data · full logs
real users: completely unaffected
attacker sessions: no signal given
CDN
WAF
SIEM
central review
SOAR
automation
TIP
intelligence
AI / Other
API · MCP

Ready to stop signaling attackers?