Aegisify company logo
Aegisify WAF Configurations, Inventory and AI2026-08-12T03:08:33+00:00
Aegisify WAF — Configurations, Inventory & AI

Know What Your WAF Is Protecting Before You Ask It to Change

Aegisify WAF 1.20.13 combines local Configuration Scans, encrypted attack-surface inventory, verified WAF backup and restore, guarded recommendations, and optional redacted AI-assisted mapping through Aegisify Core.

Security configuration should be reviewable, recoverable, and tied to current evidence.
Aegisify separates deterministic findings from optional AI analysis, binds recommendations to current evidence, limits one-click changes to low-risk allowlisted controls, verifies writes, and preserves rollback.

1Scanlocal posture
2Reviewinventory + plan
3Changeverify + rollback

Protected Configuration Workflow

From Local Evidence to a Verified WAF Change

Each stage has a separate security boundary. Local scanning works without AI; AI requires explicit approval; automation is restricted; and restoration is validated before durable settings are replaced.

Click a stage to expand

01Back Updurable settings
Export the current durable WAF switches, rules, API policies, allowlists, and WAF-owned alert recipients before major tuning. Runtime evidence, licenses, temporary counters, inventories, and AI reports are intentionally separate.
02Scan Locallyno AI required
Run Scan Configurations to collect the supported WordPress/application inventory and evaluate local configuration posture. The deterministic report classifies rows as Risk, Review, or Strength and calculates a scan score.
03Store Securelyencrypted snapshot
Each inventory is encrypted locally, integrity-checked, versioned, linked to the previous snapshot, and compared for added, changed, and removed attack-surface items.
04Analyzeexplicit AI approval
If authorized, WAF creates a compact redacted planning dossier and sends one approved request through Aegisify Core. The full local inventory is not handed to AI as unrestricted site data.
05Apply Safelyallowlisted changes
One-click changes are limited to deterministic WAF-owned low-risk actions such as monitor/log-only, normalization, or compatibility-safe settings. Higher-impact enforcement remains manual.
06Verifyread back + rollback
Aegisify reads settings back after the change. Per-change rollback records and configuration restore snapshots provide recovery paths when a supported guarded change must be reversed.
Configuration Scan

Evaluate WordPress Posture and WAF Controls Locally First

The Configuration Findings workflow is deterministic. It does not need an AI provider to identify current settings, baseline differences, attack-surface conditions, and controls that deserve review.

The scanner combines current WAF settings with saved WordPress/application evidence, evaluates supported security and operational controls, then organizes them into Risk, Review, and Strength rows with a score and recommended state.

WordPress-side findings cover HTTPS, debug exposure, software updates, inactive code, file-modification policy, Application Passwords, writable paths, REST exposure, AJAX exposure, and other supported signals. The scanner does not silently update third-party software.

Security posture: the local scan makes configuration drift visible without granting an external service authority over the site. It creates an evidence-backed starting point for deciding which changes are safe, necessary, or intentionally different.
Encrypted Local Inventory

Build a Versioned Map of the WordPress Attack Surface

Each scan performs a bounded recollection, stores an encrypted snapshot, and compares it with the previous snapshot.

Environment

Runtime & Software Context

Inventory can include WordPress, PHP, database posture, plugin/theme state, scheduled hooks, application metadata, and current WAF coverage.

Application Surface

Routes, AJAX & Public URLs

The scanner can collect bounded metadata for application URLs, REST patterns/methods, AJAX actions, XML-RPC methods, post types, taxonomies, shortcodes, dynamic blocks, and observed APIs.

Change Tracking

Added, Changed & Removed

Snapshots include an inventory hash, previous-hash relationship, item counts, and deltas so an administrator can see how the supported attack surface changed between scans rather than treating every assessment as isolated.

Collection boundary: the scanner is designed not to read post content, request bodies, user records, passwords, tokens, cookies, private keys, database row contents, or source-code contents. Very large collections are bounded by safety caps and the saved report discloses when a collection was truncated.
Local Storage & Integrity

Encrypt the Evidence and Verify It After Writing

Aegisify stores inventory and AI-plan data in plugin-owned tables using authenticated encryption and integrity checks instead of treating configuration intelligence as disposable browser state.

Inventory and AI analysis records use AES-256-GCM encryption when available, with keys derived from WordPress authentication salts and purpose context. Inventory is SHA-256 hashed and read back after writing; an unverified row is removed instead of trusted.

The store retains version, scan type, timestamps, creator context, current/previous hashes, item counts, and deltas. Default inventory retention is 20 records, providing controlled history.

Backup, Restore & Recovery

Separate Durable WAF Configuration From Runtime Evidence

A configuration backup recovers policy—not logs, temporary attack state, licensing, or inventory history.

01 — Backup Scope

Durable WAF Settings

Exports include supported WAF switches, rules, API policies, allowlists, and WAF-owned alert-recipient settings. Aegisify Core credentials, inventory snapshots, AI reports, licenses, logs, counters, and temporary data are excluded.

02 — Restore Validation

Check Before Write

Restore validates product identity, schema, version compatibility, package structure, option manifest, allowed option groups, and SHA-256 checksum before writing.

03 — Enforcement Warning

Acknowledge Blocking Changes

If an incoming backup differs from current configuration and contains active block controls, the administrator must explicitly acknowledge that the verified restore can immediately reject traffic.

04 — Recovery Snapshot

Rollback Before Change

Aegisify snapshots the prior configuration before restore. If verification fails, it attempts to restore and verify that previous state.

AI-Assisted WAF Mapping

AI Can Recommend. It Does Not Receive Permission to Reconfigure WordPress.

AI review is optional, separately authorized, routed through Aegisify Core, and constrained by local deterministic policy.

Before analysis, Aegisify checks that the saved inventory and live WAF configuration remain consistent. If settings changed, the administrator must scan again, then explicitly approve one redacted AI request.

The planning dossier is minimized and redacted. It can contain finding IDs, setting paths, redacted states, WAF posture, candidate targets, hashes, and required attack-surface context. AI must use supplied targets and defer unsafe changes to manual review.

Automation boundary: the AI plan is restricted to supplied safe global paths and monitor-only target controls. It must not automatically enable blocking, authentication requirements, rate limits, DDoS changes, proxy trust, or arbitrary settings. AI output is treated as untrusted until Aegisify validates it locally.

Guarded Application

Only Low-Risk, Allowlisted Changes Get a One-Click Path

The product intentionally makes higher-risk configuration slower and more deliberate.

1Monitor FirstAI-created endpoint policies are kept log-only and API route controls remain monitor-only when automation is permitted.
2Exact TargetRecommended changes are tied to existing target IDs and the inventory/configuration snapshot used during analysis.
3Read BackAfter a guarded write, Aegisify verifies that the intended WAF value or policy actually persisted.
4Roll BackSupported one-click recommendations create an independent encrypted rollback record so the exact prior WAF value can be restored.

Build a Safer Configuration Baseline

Scan First. Back Up. Review the Evidence. Then Change.

Make WAF configuration auditable and recoverable instead of experimenting directly against production enforcement.

Configuration Intelligence FAQ

Common Questions About the Protected Workflow

Does Configuration Scan require AI?

No. Local Configuration Findings and encrypted inventory operate without AI. AI review is optional.

Does the inventory collect WordPress content or passwords?

The supplied 1.20.13 scanner explicitly excludes post content, user records, credentials, tokens, cookies, request bodies, database-row contents, private keys, and source-code contents from its supported inventory collection.

Can AI turn on blocking automatically?

No. The AI planning contract prohibits automatic blocking, authentication requirements, rate limits, DDoS changes, proxy trust, and arbitrary settings. Safe automation remains monitor/log-first and locally validated.

What happens if a restore cannot be verified?

Aegisify saves a rollback snapshot before the restore and attempts to put the previous WAF option snapshot back if the new state cannot be verified.

Configuration With a Recovery Path

Turn WAF Tuning Into a Controlled Security Workflow

Inventory the application, understand configuration posture, preserve a recoverable baseline, use AI only where it adds reviewable context, and verify every supported automated change before treating it as complete.