Edge
Pre-origin defense
The Edge WAF filters hostile traffic before it reaches WordPress.
Arximus Architecture
Arximus combines Edge WAF protection, local endpoint enforcement, cloud intelligence, managed policy, verified recovery, and tamper-evident audit into one coordinated platform.
Hybrid defense
The Edge WAF handles malicious traffic, bots, exploit attempts, protocol anomalies, and rate limits before PHP and WordPress load.
The local agent sees WordPress context the edge cannot fully know, including roles, routes, plugins, themes, admin actions, uploads, file changes, database signals, backup state, and restore readiness.
Cloud coordination
The cloud layer provides managed policy, threat intelligence, vulnerability intelligence, bot reputation, malware intelligence, event correlation, storage governance, and restore verification.
Cloud responses are signed structured data. The plugin does not download or execute remote code.
System layers
Arximus is not a single firewall component. It is a coordinated security and recovery system.
Edge
The Edge WAF filters hostile traffic before it reaches WordPress.
Origin
Signed edge headers, bypass detection, and origin shielding help prevent attackers from going around the edge.
Local
The WordPress agent applies policy with local context and continues emergency protection if cloud connectivity fails.
Cloud
Arximus Cloud scores risk, manages policies, correlates incidents, and distributes signed structured decisions.
Recovery
Encrypted offsite backups, signed manifests, restore planning, and restore drills prove recoverability.
Audit
Local hash chains, cloud checkpoints, operator logs, and signed reports preserve accountability.
Architecture outcome
The architecture is built to do more than block attacks. It gives operators a controlled path from threat to verified recovery.
Prevent
Edge rules, local rules, virtual patches, hardening, identity defense, and rate limits reduce exposure.
Detect
Malware, file integrity, database integrity, cron monitoring, and incident correlation expose compromise indicators.
Contain
Containment playbooks can tighten policy, freeze deletion, revoke access, and preserve evidence.
Prove
Signed proof reports, audit chains, restore drill results, and incident timelines give customers evidence.
Built as a system
Arximus is designed to combine both approaches and add verified recovery, audit, and proof.
Next step
We can map how Edge WAF, the local agent, backups, and storage governance would apply to your WordPress stack.