Evaluris Solutions

Detect. Deceive. Confirm.

Evaluris ARACHNE

Catch autonomous AI agents mid-recon, then feed them believable decoys laced with canaries. When a decoy is touched, you get proof, not a guess, before they finish mapping your attack surface. Quantum-ready by design.

Watch Evaluris ARACHNE

See an agent walk into the trap.

In under two minutes: edge scoring, decoy responses, and the moment a canary fires. No slides. Just what defenders see when autonomous recon hits your surface.

Video coming soon

Drop your ARACHNE walkthrough here. 16:9 frame is ready.

How it works

Three steps from edge to evidence.

Click a step or watch the loop. Detection without deception is only half the story.

Edge online

Instrument your edge

Fail-open by design. If ARACHNE is slow or unreachable, real traffic still flows.

Signal flow: edge → score → decoy → canary

Why deception wins

Blocking alone is a dead end.

Traditional controls hope the agent goes away. ARACHNE turns contact into confirmation.

Traditional

Blocks and hopes

Evaluris ARACHNE

Deceives and confirms

Traditional

Learns nothing from a blocked request

Evaluris ARACHNE

Captures a fingerprint from every contact

Traditional

Alerts after the damage is done

Evaluris ARACHNE

Alerts the instant a decoy is touched

Traditional

One site, one defense

Evaluris ARACHNE

Every detection strengthens the whole network

Traditional

Static rule lists

Evaluris ARACHNE

Shared threat memory that compounds

Operator view

Watch the attack path form in real time.

A full session graph of what Evaluris ARACHNE sees: probe fan-out, decoy engagement, breadcrumb follow-through, and the canary that confirms the agent.

AgentHetzner · httpxEdgeARACHNE middlewaredemo.appprotected originGET /probe/robots.txtenumerate/sitemap.xmlenumerate/adminauth surface/.envcredential huntDecoy .envcanaries plantedDecoy users.jsoninternal dumpops-notesbreadcrumblegacy-keysbreadcrumbCanary hitcnry_… touchedAlertemail · Slack

Enumeration phase · observing

The cost of waiting

Autonomous agents do not wait 247 days.

Human-paced breach timelines assume attackers move like people. LLM tooling and agent frameworks hit web apps and APIs at machine speed. Recon that once took weeks can finish before your next standup. The market numbers below show what late detection already costs. The new risk is how fast that window is shrinking.

$4.99M

Avg. breach cost

Global average cost of a data breach

Source: IBM Cost of a Data Breach Report 2024

247 days

Time to identify & contain

Mean time to identify and contain a breach

Source: IBM Cost of a Data Breach Report 2024

1 in 4+

Breaches involving AI

Share of incidents where AI-related factors appear

Source: Industry breach analyses, 2024–2025

ARACHNE is built for that acceleration: score at the edge, deceive early, and confirm with canaries before an agent finishes mapping you.

Integration methods

Meet agents where they already arrive.

Choose the path that matches your edge. Detection and deception share one API. Transport and alert authenticity stay separately scoped.

Cloudflare Workers

CDN-edge Worker SDK with waitUntil ingest.

  • Deploy @evaluris/arachne-cloudflare where agent traffic already hits your CDN.
  • Ingest runs via waitUntil so origin latency stays low; active mode can serve decoys.
  • This path inherits Cloudflare’s hybrid post-quantum key exchange (ML-KEM, NIST FIPS 203) for transport, automatic, no extra config.
  • Ideal for sites already on Cloudflare Workers or wanting edge-first defense.

Post-quantum readiness

Two separate quantum-era controls, not one blanket claim.

Alert authenticity and edge transport are scoped independently, so you can verify each claim on its own terms.

Scoped. Verifiable. Distinct.

NIST FIPS 204

Alert authenticity

ML-DSA signed webhooks

Alert webhooks are signed with ML-DSA (NIST FIPS 204), verifiable independently of transport security.

NIST FIPS 203

Cloudflare transport

ML-KEM at the edge

Sites deployed via the Cloudflare Worker SDK inherit Cloudflare's hybrid post-quantum key exchange (ML-KEM, NIST FIPS 203) for transport.

Why this matters

Autonomous agents do not browse like humans. They enumerate paths, reuse tooling fingerprints, and move fast across environments. Most teams only notice after a scanner report or an incident ticket.

ARACHNE gives defenders an early signal at the edge: structured detection, deceptive responses, and canary triggers you control. You decide when to observe, when to deceive, and when to block.

Shared threat signatures are de-identified. Tenant domains and raw request bodies are not published into a global feed.

Pricing

Plans that scale with your edge.

Start free on one site. Upgrade for volume, retention, alert channels, and control. Enterprise and government teams get custom everything.

MonthlyAnnually· save 20%

Free

$0

Prove detection on a single site before you commit budget.

Forever free to evaluate

Includes:

1 protected site
1k events / month
7-day retention
3 canary tokens
Email alerts
Observe & deceive modes
Owner only (no seats)
Node + Cloudflare SDKs

Starter

$29/mo

For small teams that need Slack alerts and manual block workflows.

Billed monthly

Includes:

3 protected sites
50k events / month
30-day retention
Unlimited canary tokens
Email + Slack alerts
Manual block workflows
5 team seats
Standard support
Most popular

Pro

$99/mo

Production volume, webhooks, and full auto-block when you are ready.

Billed monthly

Includes:

15 protected sites
500k events / month
90-day retention
Unlimited canary tokens
Email + Slack + webhooks
Full auto-block controls
25 team seats
Priority support queue
Custom

Enterprise / Gov

Custom

Procurement-ready terms, custom limits, and deployment options for regulated teams.

Scoped to your environment

Includes:

Custom site volume
Custom event volume
Custom retention & residency
Custom canaries & profiles
All channels + custom routing
Policy-driven / custom block
SSO / SAML + SCIM seats
Dedicated SLA & compliance

All paid plans include core detection, decoy serving, and canary confirmation. Need a security questionnaire, MSA, or volume quote for Evaluris ARACHNE? Talk to us.

Talk to sales →

FAQ

Answers before you deploy.

Detection, deception, canaries, privacy, and how ARACHNE sits on your edge without breaking legitimate traffic.

Evaluris ARACHNE detects autonomous AI agent traffic at your edge, serves deceptive decoys when risk is high, and confirms intent when a canary token is touched.

Ready to catch agents early?

Deploy Evaluris ARACHNE on your first site in minutes. Upgrade when you need more coverage, retention, or alert channels.

Ecosystem

Built on standards the industry already trusts.

Infrastructure partners, security frameworks, and quantum collaboration behind Evaluris engineering, training, and defensive product work.

Infrastructure Ecosystem

Powered by industry-standard infrastructure used across modern security teams.

  • NVIDIA
    NVIDIA
  • AWS
    AWS
  • Cisco
    Cisco
  • Docker
    Docker
  • IBM
    IBM
  • GitHub
    GitHub
  • Cloudflare
    Cloudflare
  • Apple
    Apple

Cybersecurity Standards & Threat Frameworks

Globally recognized security standards and adversary frameworks used across our penetration testing and defensive security curricula.

  • NIST
    NIST
  • MITRE
    MITRE
  • IEC
    IEC
  • OWASP
    OWASP

Quantum Partner

Post-quantum collaboration with partners advancing quantum-safe cryptography and next-generation security research.

  • Qvanta
    Qvanta