OPEN SOURCE
Committed to open source
Vallum is built on open source technology and committed to giving it back. We intend to open source the majority of the Vallum proxy within the next few months, once ongoing testing and security audits are complete.
Apache 2.0
license on every SDK package
9 packages
published on npm and GitHub
In progress
proxy core testing and audit
THE PROXY CORE
Opening the majority of the proxy
The detection engine and response jambling path that sit in front of your origin are being prepared for public release. We would rather ship it audited than ship it early, so the work is gated on testing and third-party review rather than on a launch date.
WHAT WE ARE WORKING THROUGH
—
Hardening the request path under sustained adversarial load
—
Third-party security review of the detection and jambling engine
—
Separating the operated edge network from the self-hostable core
—
Documentation and reproducible builds for self-hosters
SDKS
Every SDK package is public and installable
Install the release from npm or explore the source, tests, and package history on GitHub. Every SDK is available under the Apache 2.0 license.
CORE RUNTIME
The decoding path itself, with no framework attached.
@liteeagle226/client
Establishes the admitted session, signs protected requests, and reconstructs transformed responses into an ordinary Response.
ANY BROWSER
PUBLIC ON NPM
View repository
@liteeagle226/browser
Zero-build bundle for plain HTML and JavaScript. No build step, no framework.
NO BUNDLER
PUBLIC ON NPM
View repository
FRAMEWORK BINDINGS
Idiomatic lifecycle ownership for each frontend framework.
@liteeagle226/react
Lifecycle-safe bindings. Context-provided init state and protected fetch, plus render-only values that never enter the DOM.
REACT 18+
PUBLIC ON NPM
View repository
@liteeagle226/nextjs
Client boundary and admission route handlers. Server-only admission code never reaches the browser bundle.
NEXT 13.4+
PUBLIC ON NPM
View repository
@liteeagle226/vue
One per-application session through a Vue plugin, with readonly reactive state and Composition API helpers.
VUE 3.3+
PUBLIC ON NPM
View repository
@liteeagle226/svelte
Readable lifecycle controller, component context helpers, and an opt-in action for render-only values.
SVELTE 5
PUBLIC ON NPM
View repository
@liteeagle226/angular
Standalone bindings in Angular Package Format, with DI providers and signals for lifecycle state.
ANGULAR 22
PUBLIC ON NPM
View repository
SERVER + EXPERIMENTAL
Backend admission issuing and display-only helpers.
@liteeagle226/admission
Ed25519 admission grant issuer. Holds the private-key path, so it must never enter a browser bundle.
NODE, SERVER ONLY
PUBLIC ON NPM
View repository
@liteeagle226/render
Display-only visual encoding helpers. Visual obfuscation, not a security control.
EXPERIMENTAL
PUBLIC ON NPM
View repository
© 2026 Vallum by Mosco Holdings LLC
Privacy
Terms
PROTECTING AGAINST AI THREATS ●