How Zyre works
The model to understand before anything else: Zyre sits in front of your site, it is not installed inside it.
4 minUpdated
Zyre is a reverse proxy. You point your site's domain name at our servers; from then on, every visit goes through our firewall first, which inspects it, then passes it on to your server if it is legitimate.
There is nothing to install
No plugin, no extension, no module to add to your server, no configuration file to edit. Protection is switched on purely through a DNS change. Your site stays hosted exactly where it is today.
The path of a visit
Before Zyre
visiteur ─────────────────────────────▶ votre serveurWith Zyre
visiteur ──▶ Zyre (TLS + pare-feu) ──▶ votre serveur
│
└── attaque refusée, journaliséeYour server is called the origin throughout this documentation. It is the machine where your pages actually live, and it is where we relay traffic once filtered.
Three consequences to remember
- Your visitors notice nothing. Same address, same pages, a valid certificate. The only ones who see a difference are attackers.
- We are in your critical path. That is why a lapsed subscription never stops your site: it stops inspection, not relaying.
- DNS is the only switch. Connecting and disconnecting both happen at your DNS host, and it stays yours from end to end.
What Zyre does not do
Stated plainly so you do not go looking: Zyre does not host your site, does not back it up, does not clean an already-infected site, does not scan ports, does not block by country, and exposes neither a public API nor outgoing webhooks.
This page did not answer your question?
Contact us