PLATFORM
Every response transformed. Only your app can read it.
Vallum is a reverse proxy that encrypts every protected JSON response to a short-lived browser session. Your frontend reconstructs the exact origin object through the SDK. Raw automation gets a plausible false one — and on protected routes never reaches your origin at all.
RESPONSE JAMBLING
Your API, unreadable without the session
The canonical JSON is encrypted to a short-lived session key. Raw clients get a type- and shape-preserving false view: valid, coherent, entirely fabricated.
BROWSER + VALLUM SDK
200 OK · reconstructed
{
"user_id": "usr_8f3k2",
"balance": 4820.55,
"currency": "USD",
"tier": "enterprise"
}
vs
RAW CLIENT
200 OK · transformed
{
"d7f2_meta": { "epoch": 7, "ct": "k9Ez…Qm4" },
"user_id": "usr_31c8f0",
"balance": 1290.40,
"currency": "USD", "tier": "standard"
}
✓ Layout & carrier rotation per response
✓ Honeytokens & false affordances
✓ Exact origin object via SDK
✓ Five route modes, per endpoint
ADMIT
Proof, not guesswork
Your backend issues a 30-second grant after its own login checks, and the browser signs every request with a non-extractable key. Replays are rejected atomically. A header claiming to be human is never evidence.
CONTAIN
A world that isn't yours
Failed authorization, an exhausted quota, or a tripped honeytoken is answered locally with a coherent synthetic workspace — services, credentials, jobs, all fabricated. The origin is never called.
DEPLOY
DNS, SDK, one route
CNAME the hostname, drop the adapter into your frontend, and mount the admission handler behind the login check you already have. That last one is the piece we can't do for you — only your app knows who is signed in.
Compatible with your existing stack
Cloudflare
Fastly
CloudFront
nginx
HAProxy
Envoy
Kubernetes
See it against your own traffic
30 minutes with an engineer. We'll scope your stack and quote flat.
Book a call
© 2026 Vallum by Mosco Holdings LLC
Privacy
Terms
PROTECTING AGAINST AI THREATS ●