# Abatised

*/Startups/Abatised*

## Startup Overview

Organizations expose massive attack surfaces through their external API perimeters, leaving them vulnerable to automated scraping, credential stuffing, and persistent bot networks. This system transforms passive defense into active deception by deploying dynamic decoy payloads directly across these pathways. When hostile traffic queries an endpoint, it receives fabricated but structurally valid data that wastes attacker compute and corrupts their targeting datasets.

Traditional edge protections like Cloudflare Bot Management, Akamai Edge DNS, or static WAF configurations rely on rigid rule sets that modern automated threats easily bypass. Instead of demanding constant manual blocklist tuning, this architecture operates fully autonomously to generate, inject, and rotate decoys in real time. The commercial model aligns directly with defensive efficacy, charging organizations strictly for verified threat diversions rather than total traffic volume.

## Startup Founding Hypothesis

**Approach**: that deploys dynamic decoy payloads across external API perimeters
**Competitors**:
- [Cloudflare Bot Management](/Competitors/Cloudflare_Bot_Management)
- [Akamai Edge DNS](/Competitors/Akamai_Edge_DNS)
- [static WAF configurations](/Competitors/static_WAF_configurations)
**Differentiator2x2**: fully autonomous in deploying decoys and priced strictly on verified threat diversions

## Startup Solution Coordinate

**Solution**: [API Decoy Agent](/Agents/API_Decoy_Agent)

## Startup Position2x2

```mermaid
quadrantChart
    x-axis Manual Configuration --> Fully Autonomous Decoys
    y-axis Traffic and Subscription Pricing --> Priced on Verified Diversions
    Static WAF Configurations: [0.15, 0.15]
    Akamai Edge DNS: [0.55, 0.30]
    Cloudflare Bot Management: [0.80, 0.35]
    Abatised: [0.90, 0.85]
```

## Startup Customer Journey

```mermaid
flowchart LR;A[Terraform Registry]-->B[IaC Decoy Module];B-->C[Decoy API Payload];C-->D[Single API Gateway];D-->E[External API Perimeter];E-->F[Autonomous SOC Catalog];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 30-day deployment on a single high-value authentication endpoint to prove dynamic decoy generation captures active credential stuffing without interfering with legitimate user traffic.
- 14-day shadow-mode deployment on a public-facing API to validate the accuracy of the threat classification engine before enabling active diversion and usage billing.
**Target Metrics**:
- Target: 100% diversion rate for identified credential stuffing attempts.
- Aim: 0ms latency increase for authenticated, legitimate API requests.
- Target: 0 misrouted authentic requests (maintaining the absolute separation guarantee).
- Aim: 100% cryptographic verification for every billed threat diversion log.
**Target Case Studies**:
- Target: A mid-sized fintech provider. Transformation: Diverting 100% of volumetric credential stuffing attacks away from their primary authentication API into dynamic honeypots without adding latency to legitimate customer logins.
- Target: An enterprise e-commerce platform. Transformation: Misdirecting zero-day checkout logic attacks into decoy schemas during peak holiday traffic, safely wasting attacker resources while maintaining absolute separation from authentic transactions.
- Target: A healthcare data API provider. Transformation: Rerouting sophisticated injection attempts to decoy payloads and generating cryptographically verifiable logs of the diverted threats to inform their broader security posture.
**Testimonial Targets**:
- Target Role: Chief Information Security Officer. Target Sentiment: Relief that zero-day logic attacks are actively absorbed and wasted by dynamic decoys rather than slipping past static WAF signatures.
- Target Role: VP of Engineering. Target Sentiment: Confidence in the traffic separation guarantee, confirming that legitimate API requests experience zero added latency or misrouting.
- Target Role: DevSecOps Lead. Target Sentiment: Satisfaction with the usage-metered billing model, specifically appreciating that they only pay for verified malicious diversions and not for harmless passive scrapers.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Customers dispute the definition of a verified threat diversion, breaking the outcome-based billing model and causing severe revenue leakage. · Mitigation Status: unmitigated
- Severity: high · Description: The autonomous decoy engine introduces unacceptable latency or instability into production API gateways, triggering immediate enterprise churn. · Mitigation Status: in-progress
- Severity: high · Description: Dominant edge providers like Cloudflare or Akamai replicate decoy injection capabilities at the CDN level and bundle it into existing enterprise tiers. · Mitigation Status: unmitigated
- Severity: moderate · Description: Enterprise CISOs block deployment due to the expansive IAM permissions required for the engine to autonomously alter external API perimeters. · Mitigation Status: in-progress

## Startup Competitors

- [Cloudflare Bot Management](/Competitors/Cloudflare_Bot_Management) — Incumbent
- [Akamai Edge DNS](/Competitors/Akamai_Edge_DNS) — Incumbent
- [Static WAF Configurations](/Competitors/Static_WAF_Configurations) — Status Quo
- [Traceable AI](/Competitors/Traceable_AI) — API Security
- [Illusive Networks](/Competitors/Illusive_Networks) — Deception Tech
- [Salt Security](/Competitors/Salt_Security) — API Security

## Startup Business Definition

**Name**: Block Malicious API Traffic for SaaS Infrastructure Providers
**Layers**:
- **Thesis**: Headless SaaS
- **Template**: api-business
- **Buyer Chain**: B2B -> SecOps Engineer -> Automated Firewall Agent
**Vision**:
- **Vision**: SaaS Infrastructure Providers no longer carry the cost of block malicious api traffic; the work runs reliably in the background, and the team that used to do it is free for higher-leverage work in saas infrastructure provider.
- **Mission**: ship the API surface that solves block malicious api traffic for SaaS Infrastructure Providers.
**Industry**: SaaS Infrastructure Provider
**Coord Href**: /Startups/Abatised
**Processes**:
- Name: Customer Intake · Owner: startup-cs-onboarding · Category: core · Description: Capture a new customer's signup or sales hand-off and route them into onboarding. · Added By Layer: operate-baseline
- Name: API Request Lifecycle · Owner: delivery-platform-engineer · Category: core · Description: Each API call lands, is served, is observed against SLOs. · Added By Layer: thesis
**Workflows**:
- Name: On New Customer Signup · Description: Event-driven: a new customer signs up → kick off onboarding + record the founding-OKR KR event. · Added By Layer: operate-baseline
- Name: On SLO Breach · Description: API SLO budget breach → escalate to API reliability + capture incident. · Added By Layer: thesis
**Departments**:
- Id: delivery-headless-saas · Code: DEL · Name: Delivery (Headless SaaS — API/Platform) · Description: Delivery primitives for a Headless SaaS Thesis (ADR 0034 §3 + §4 graduation exception). API/platform + DX Positions are Startup-internal pre-graduation because the product IS the software it ships. · Added By Layer: thesis
- Id: startup-operate · Code: OPS-S · Name: Operate (Startup-specific shared services) · Description: Per-Startup operate functions — Customer Success, Marketing, Revenue/Sales, Customer Ops. The Studio default carries portfolio-wide bookkeeping/AP/AR/tax/legal-prep (#239); this overlay adds the Startup-specific operate Positions that have to exist in every operating company. The four-layer specialization (Thesis/Template/spine/Buyer-Chain) then shapes these seats to the Startup's actual shape — additions/overrides happen in those layers, not here. · Added By Layer: operate-baseline
**Description**: An operating company shipping an API/platform that solves block malicious api traffic for saas infrastructure providers.
**Founding Okr**:
- **Period**: First 90 days
- **Objective**: Prove the wedge — first saas infrastructure providers pay for block malicious api traffic solved.
- **Description**: The founding OKR — every key result is a concept-stage TARGET (no operating history claimed), aimed at validating the Founding Hypothesis against the assigned wedge.
**Generated By**:
- **Generator**: C1
- **Generator Version**: 1.0.0
**Inherits From**:
- **Base**: STUDIO_DEFAULT_ORG
- **Version**: 1.0.0
- **Schema Version**: 2.1.4

## Neighborhood

### Candidate solutions

- [Bindery Equipment Injury Claims](/Problems/Bindery_Equipment_Injury_Claims) — candidate solution for · Problems

### Competitors

- [Cloudflare Bot Management](/Competitors/Cloudflare_Bot_Management) — competes with · Competitors
- [Static WAF Configurations](/Competitors/Static_WAF_Configurations) — competes with · Competitors
- [Akamai Edge DNS](/Competitors/Akamai_Edge_DNS) — competes with · Competitors
- [Traceable AI](/Competitors/Traceable_AI) — competes with · Competitors
- [Salt Security](/Competitors/Salt_Security) — competes with · Competitors
- [Illusive Networks](/Competitors/Illusive_Networks) — competes with · Competitors
- [VelocityEHS](/Competitors/VelocityEHS) — competes with · Competitors
- [Heidelberg Prinect](/Competitors/Heidelberg_Prinect) — competes with · Competitors
- [Retroactive CCTV Review](/Competitors/Retroactive_CCTV_Review) — competes with · Competitors
- [SafetyCulture](/Competitors/SafetyCulture) — competes with · Competitors
- [VelocityEHS Software](/Competitors/VelocityEHS_Software) — competes with · Competitors
- [SafetyCulture Reporting App](/Competitors/SafetyCulture_Reporting_App) — competes with · Competitors
- [VelocityEHS Safety Software](/Competitors/VelocityEHS_Safety_Software) — competes with · Competitors
- [Physical Safety Interlocks](/Competitors/Physical_Safety_Interlocks) — competes with · Competitors
- [SafetyCulture audits](/Competitors/SafetyCulture_audits) — competes with · Competitors
- [Retroactive CCTV](/Competitors/Retroactive_CCTV) — competes with · Competitors
- [VelocityEHS Incident Logs](/Competitors/VelocityEHS_Incident_Logs) — competes with · Competitors
- [Retroactive CCTV Reviews](/Competitors/Retroactive_CCTV_Reviews) — competes with · Competitors
- [VelocityEHS Incident Management](/Competitors/VelocityEHS_Incident_Management) — competes with · Competitors
- [SafetyCulture Compliance Software](/Competitors/SafetyCulture_Compliance_Software) — competes with · Competitors
- [Heidelberg Prinect Telemetry](/Competitors/Heidelberg_Prinect_Telemetry) — competes with · Competitors
- [VelocityEHS Incidents](/Competitors/VelocityEHS_Incidents) — competes with · Competitors
- [Retroactive CCTV Logs](/Competitors/Retroactive_CCTV_Logs) — competes with · Competitors
- [CCTV footage review](/Competitors/CCTV_footage_review) — competes with · Competitors
- [Manual Spot Checks](/Competitors/Manual_Spot_Checks) — competes with · Competitors
- [Fastly Next-Gen WAF](/Competitors/Fastly_Next-Gen_WAF) — competes with · Competitors
- [Manual WAF Configuration](/Competitors/Manual_WAF_Configuration) — competes with · Competitors
- [Palo Alto Networks](/Competitors/Palo_Alto_Networks) — competes with · Competitors
- [Cloudflare WAF](/Competitors/Cloudflare_WAF) — competes with · Competitors
- [Akamai API Protector](/Competitors/Akamai_API_Protector) — competes with · Competitors
- [EFI Pace](/Competitors/EFI_Pace) — competes with · Competitors
- [Static Physical Guards](/Competitors/Static_Physical_Guards) — competes with · Competitors
- [Manual Floor Sweeps](/Competitors/Manual_Floor_Sweeps) — competes with · Competitors
- [SafetyCulture iAuditor](/Competitors/SafetyCulture_iAuditor) — competes with · Competitors
- [Manual Floor Walkarounds](/Competitors/Manual_Floor_Walkarounds) — competes with · Competitors
- [Vector Solutions](/Competitors/Vector_Solutions) — competes with · Competitors
- [VelocityEHS Platform](/Competitors/VelocityEHS_Platform) — competes with · Competitors
- [Vector Solutions EHS](/Competitors/Vector_Solutions_EHS) — competes with · Competitors

### Embodies

- [Agent](/Theses/Agent) — embodies · Theses
- [Headless SaaS](/Theses/Headless_SaaS) — embodies · Theses

### What it offers

- [API Decoy Agent](/Agents/API_Decoy_Agent) — offers · Agents
- [Blade Sentry](/Agents/Blade_Sentry) — offers · Agents
- [Blade Sentry Agent](/Agents/Blade_Sentry_Agent) — offers · Agents
- [Edge Enforcement Engine](/Agents/Edge_Enforcement_Engine) — offers · Agents

### Composed of

- [Blade Proximity Agent](/Agents/Blade_Proximity_Agent) — composes · Agents
- [Guard Bypass Agent](/Agents/Guard_Bypass_Agent) — composes · Agents
- [Hazard Intercept Service](/Services/Hazard_Intercept_Service) — composes · Services
- [Platen Sensor API](/Software/Platen_Sensor_API) — composes · Software
- [Guillotine Relay SDK](/Software/Guillotine_Relay_SDK) — composes · Software
- [Guard Bypass Monitoring Agent](/Agents/Guard_Bypass_Monitoring_Agent) — composes · Agents
- [Blade Clearance Agent](/Agents/Blade_Clearance_Agent) — composes · Agents
- [Active Hazard Interception Service](/Services/Active_Hazard_Interception_Service) — composes · Services
- [Edge Proximity Vision Engine](/Software/Edge_Proximity_Vision_Engine) — composes · Software
- [Machine Relay Trigger API](/Software/Machine_Relay_Trigger_API) — composes · Software
- [Edge Spotter Agent](/Agents/Edge_Spotter_Agent) — composes · Agents
- [Reaction Time Engine](/Software/Reaction_Time_Engine) — composes · Software
- [Kinematic Vision API](/Software/Kinematic_Vision_API) — composes · Software
- [Hazard Logging Agent](/Agents/Hazard_Logging_Agent) — composes · Agents
- [Station Rotation Manager](/Services/Station_Rotation_Manager) — composes · Services

### What it addresses

- [Block Malicious API Traffic](/Problems/Block_Malicious_API_Traffic) — addresses · Problems

### Who it serves

- [SaaS Infrastructure Provider](/CompanyTypes/SaaS_Infrastructure_Provider) — serves · CompanyTypes
- [Commercial Print Facilities](/CompanyTypes/Commercial_Print_Facilities) — serves · CompanyTypes
- [Commercial Print Facility](/CompanyTypes/Commercial_Print_Facility) — serves · CompanyTypes

### Entrant in opportunity

- [AI Bindery Safety for Print Shops](/Opportunities/AI_Bindery_Safety_for_Print_Shops) — is entrant in · Opportunities
- [Vision Guard Monitoring for Print Shops](/Opportunities/Vision_Guard_Monitoring_for_Print_Shops) — is entrant in · Opportunities
- [AI Fatigue Monitoring for Binderies](/Opportunities/AI_Fatigue_Monitoring_for_Binderies) — is entrant in · Opportunities

### Similar Startups

- [Magpot](/Startups/Magpot) — similar · Startups
- [Apimuri](/Startups/Apimuri) — similar · Startups
- [Abhominable](/Startups/Abhominable) — similar · Startups
- [Storm](/Startups/Storm) — similar · Startups
- [Surgestrike](/Startups/Surgestrike) — similar · Startups
- [Sentrypost](/Startups/Sentrypost) — similar · Startups
- [Firmsabatement](/Startups/Firmsabatement) — similar · Startups
- [Forgouble](/Startups/Forgouble) — similar · Startups
- [Sociphan](/Startups/Sociphan) — similar · Startups
- [Advetection](/Startups/Advetection) — similar · Startups
- [Filtercoin](/Startups/Filtercoin) — similar · Startups
- [Embergate](/Startups/Embergate) — similar · Startups
- [Traditional WAF Rules](/Startups/Traditional_WAF_Rules) — similar · Startups
- [Filternode](/Startups/Filternode) — similar · Startups
- [Zerosurge](/Startups/Zerosurge) — similar · Startups
- [Abaxial](/api/md.md/Knowledge/Raw_HTML_Pages/Problems/Anti-Bot_Defense_Evasion/Startups/Abaxial) — similar · Startups
- [Abrasiveridge](/Startups/Abrasiveridge) — similar · Startups
- [Actiondomain](/Startups/Actiondomain) — similar · Startups
- [Asgard](/Startups/Asgard) — similar · Startups
- [Apiload](/Startups/Apiload) — similar · Startups
