Practical answers about onboarding, accounts, monthly billing, DNS, API access, and the current security boundaries.
No. Hexa Shield sits in front of your existing origin. You keep the application and hosting stack while DNS routes eligible traffic through the protection layer.
Yes. External-DNS onboarding is supported. You can also enable Hexa Shield authoritative DNS when that deployment feature is configured.
The commercial catalog is monthly only. Visitor accounts are free until a paid monthly plan is activated.
Customer access is granted server-side after a paid checkout is independently verified with the configured payment provider. A browser redirect alone does not grant access.
Yes. Customer API keys are scoped, their secrets are displayed once, and only a hash plus display prefix are stored afterward.
No. It provides application-layer filtering and abuse controls. A single deployment does not replace a large global volumetric DDoS scrubbing network.
The current live analytics API supports up to 168 hours (7 days) from Redis-backed hourly counters. Longer historical rollups are not claimed until implemented.
Yes, when Discord OAuth is configured. Hexa Shield verifies the Discord access token server-side and requires a verified Discord email address.
No. Admin access is a platform role enforced by the backend. It is not exposed as a self-service setting.
Review the documentation or contact the Hexa Shield operator for deployment and account assistance.