THE STROM CORPORATION/ONYXOPERATIONAL
System online · 59,767 members under watch

One person,
however many accounts

It recognizes the same person even when they switch accounts, devices or networks, and decides what to do. Every decision is saved and can’t be edited or erased. It starts on Discord, but it doesn’t stop there.

nodes0284links01207sweep062queue009
System designation
The Strom Corporationoperator
└─ ONYXsystem
   └─ AXISdiscord unit
      └─ 2.4.4 ATLASrelease
ONYX // telemetryAXIS 2.4.4 ATLASoperational
0
Members watched
0
Servers guarded
04
Languages
24/7
Uptime target
Recent activityconnecting…
  • Loading live activity…
SEC-01EXPLORESee it work

Six seconds, start to finish

A raider joins with a VPN and a two-day-old account, spams six channels, and trips a trap. Watch what your staff would see — and what they would not have to do.

#security-log
    CORRELATION SCORE
    0 / 4
    Account age+1
    Anonymous network+2
    Spam pattern+1
    Honeypot trap+3
    Linked account+2
    WatchingNo single signal is proof.
    Not a video — this is how the system actually scores, signal by signal. On its own, each signal is normal: plenty of people use a VPN, and every account was new once. But all of them together inside 24 hours are no coincidence. You set the limit, and until you turn on automatic action, the system only warns.
    SEC-02THE RECEIPT

    Being banned should come with a receipt

    Right now, on any platform, if you get banned you cannot prove what happened — and neither can they. In July, Discord wrongly banned around 8,200 accounts and nobody could show anything either way. Here, every decision comes with a piece of paper you can check yourself.

    What happenedPermanent ban
    ServerExample Server
    When5 Aug 2026, 21:14
    Reasonsame connection as an account banned 3 days ago
    The hourly signature is valid
    This decision was already in the log at that moment
    The text on the receipt matches what was recorded
    The receipt does not say who moderated you — that is on purpose, a receipt should not become a target. And the check does not depend on us: the same file can be verified on your own machine, with the log itself published outside our server.
    SEC-03ARCHITECTURE

    Discord is a connector, not the product

    What actually decides everything — measuring a connection, matching it against what it already knows, reaching a verdict and saving it — does not depend on Discord. Discord only comes in at the end, to apply the decision: give or take a role.

    ONYX
    The core
    Identity, correlation, ledger and rules. It doesn’t connect to any platform.
    └─
    Connectors
    The last step: they take an identity in and return a decision.
    └─
    Surfaces
    The API, the panel, the docs and the signed receipts.
    CNX-01AxisDiscordin service
    What it can doidentityeventsgrant accessremovenotify
    CNX-02WebAny site with accountsin service
    What it can doidentitynotify
    There’s exactly one connector today, and the page doesn’t pretend otherwise. Showing six “coming soon” logos would sell better, but it would be a lie. Building it this way means adding the next one costs a file, not a rewrite of the engine. And the list below is checked against the real code: it can’t promise something that isn’t there.
    SEC-04Features

    Built for communities that get attacked for real

    Most security bots do one thing well. Axis does the whole job — and keeps the evidence.

    Ban evasion that actually holds

    Airplane mode, a router restart, a neighbour’s wifi — the IP changes, the device doesn’t. And the fingerprint is matched PIECE BY PIECE: switching browser or monitor no longer turns you into someone else. If the connection claims one country and the browser says another, no VPN fixes that either. IP (IPv6 prefix), device fingerprint, security cookie, TOR, VPN, proxies and virtual machines.

    Anti-nuke — including your own staff

    Mass delete and ban protection, role hardening, and full backups. Guardian mode watches trusted admins too, because that is how servers actually die. And if something breaks, it can be undone: the deleted channels and roles come back, with their permissions. And you can rehearse the recovery whenever you like, without touching a thing: it tells you whether your backup could actually be restored today — and it warns you by itself the day it could not.

    Anti-raid that reads intent

    Join-wave detection plus behaviour scoring. It acts on what someone does — invites, mass mentions, coordinated copy-paste — never on "you are new and you type fast".

    Forensics, not just logs

    Every deleted or edited message, with a copy of its images, video, audio and stickers. Deleting it does not erase it.

    The whole story on one screen

    A member dossier: who invited them, how many they brought, sanctions, name history, alt accounts, and everything they have done.

    Every server is an island

    Blocks live only in the server that issued them. Nobody pushes bans into your community from outside, and you can always undo one.

    It knows who let them in

    Which invite each member used and who created it. Nickname and username history. Ghost pings. Voice activity. Boosts.

    Tickets and appeals

    Automatic transcripts as a Discord-style web page, and an appeal system — because automated systems get it wrong sometimes.

    A web panel that investigates

    Search every event, filter, export, moderate, and read a full dossier. Granular permissions per staff role.

    Something for the members, not just the staff

    A public profile card anyone can pull up: verified, how long they have been around, and badges they actually earned — Veteran, Clean record, Endorsed, Pioneer. It shows only the good: never warnings, cases or risk. New arrivals get theirs the moment they verify, in front of the whole server.

    Evidence you can hand to someone outside

    When a case leaves Discord — harassment, threats, fraud — what do you hand over, forty screenshots? A case file gathers everything about one person, signed, with proof that each event was in the log that day. Anyone can verify it without asking you for anything. No other people’s data, no IPs.

    Why is there no global ban network? Because with one, a stranger’s bad call in a server you have never heard of could get your members thrown out of your own community. Your moderation stays yours.
    SEC-05How it works

    A banned user tries to get back in

    One check is easy to beat. Fifteen, stacked, are not. Each layer catches exactly what the one before it can’t — and the last one isn’t even code.

    ConnectionIP · IPv6 /64
    Same IP or same network block? Caught. On IPv6 we match the whole /64, so rotating inside it does nothing.
    Anonymous networksTOR · VPN · PROXY
    Hiding behind TOR, a VPN or a datacenter proxy? Caught — those are exactly what an evader reaches for first.
    Device fingerprintCANVAS · WEBGL · GPU
    New IP from airplane mode or a friend's wifi, but the same phone? Caught. The connection changed; the device didn't.
    Security cookiePERSISTENT MARK
    VPN and an anti-detect browser, so IP and fingerprint both look new? If the cookie survived, still caught.
    Linked accountsSTEAM · SPOTIFY · …
    Same verified Steam or Spotify on a “new” Discord account? Caught. That link survives a new house and a new laptop.
    Computational costADAPTIVE PoW
    Bot farms that solve CAPTCHAs for a fraction of a cent still burn real CPU. Difficulty rises when risk signals stack — young account, VPN, bad inviter.
    Who invited youINVITER TRUST
    A clean alt invited by someone who already brought a cluster of young accounts? The graph gives them away — not the alt alone.
    Invite graphVELOCITY · VANITY
    Sudden invite spikes, vanity URL swaps, inviters with a trail of throwaways — caught before the raid lands.
    Shared networksCGNAT · CAMPUS
    Hundreds of legitimate people can share one mobile IP. Actionable links use device and cookie, not the carrier — no collateral.
    Fake verifiedROLE GATE
    Someone with Manage Roles hands the verified role to an alt and skips the portal? Caught. Only grants the bot itself made count.
    BehaviourINTENT SCORING
    Fresh IP, fresh device, a bought account — nothing to recognise. But a raider acts like a raider, and that can't be faked.
    Account ageYOUNG ACCOUNTS
    A two-day-old account is not proof of anything alone — but stacked with VPN, no fingerprint and a bad inviter, it stops being coincidence.
    Fingerprint, piece by piecePARTIAL MATCH
    Changed browser, monitor or resolution to stop being yourself? The fingerprint is compared piece by piece: 8 of 9 still matching is still you. To stop matching you have to change everything at once — and that costs money.
    When the story does not add upCONNECTION vs BROWSER
    A VPN running on your own machine changes the IP and nothing else: the clock, the language and the keyboard still belong to their owner. IP in Amsterdam, clock in Madrid — no VPN fixes that. This never looks at your operating system: Linux is not a signal, evading is.
    Discord phone verificationYOUR MOVE · NOT CODE
    The wall that costs real money. A phone number isn't free; an IP is. Turn it on and evasion stops being worth it. Game over.
    The movePlain IP banAxis
    Change wifibypassedcaught · same device
    Airplane mode / mobile databypassedcaught · same device
    VPN, proxy or cloud IPbypassedblocked · datacenter ranges
    TOR networkbypassedblocked
    New account, same computerbypassedcaught · cookie + behaviour
    New account, new house, new laptopbypassedcaught · linked Steam/Xbox
    Automated signup, no real browserbypassedstopped · proof-of-work
    Innocent on a shared/mobile IPbanned toosafe · no collateral
    A VPN running on your own machinebypassedcaught · the clock says otherwise
    Switching browser, monitor or resolutionbypassedcaught · matches on 8 of 9
    No security tool is a perfect wall — anyone who claims otherwise is selling you something. The goal isn’t "impossible". It’s making evasion cost more time and money than it’s worth. Fifteen layers do exactly that.
    SEC-06The panel

    Investigate from your browser

    Every event, searchable. Every member, on one screen. A full dossier: who invited them, their alts, their history — the tools an investigation actually needs.

    axis · /admin — member dossier
    unknown_user
    Account age · 2 days  ·  RISK: HIGH
    2 alts
    4
    Warnings
    1
    Sanctions
    2
    Alt accounts
    37
    Actions
    INVITED BY
    nova_gate · code aX9f2
    RECENT ACTIVITY
    Alt account bannedsame device
    Ghost ping caught#general
    Nickname changed
    Joined the servervia nova_gate
    A mock-up of the real panel. Search, filter and export every event; open a full dossier on anyone; moderate without leaving the browser — with granular permissions per staff role.
    SEC-07FOR YOUR OWN SITE

    It stopped being a Discord bot

    Ask ONYX, from your own signup form, whether this visit is somebody you already blocked. It answers with a signed verdict and you decide what to do. No Discord account involved anywhere.

    A console, not a command line

    Sign up with an email, create a key, and the quickstart fills itself in with that key — in curl, PowerShell, Node or Python. Nothing to install.

    argos.is-a.dev/account
    Overview
    API keys
    Quickstart
    Verify a verdict
    ACCOUNT
    your company
    KEYS
    1 / 5
    CALLS TODAY
    4,102
    SYSTEM
    ONYX ATLAS
    curlPowerShellNodePython
    curl -H "Authorization: Bearer onx_live_…" \
      https://argos.is-a.dev/api/v1/me

    Three calls. That is the whole integration.

    1

    Ask for a check

    POST /api/v1/identity/challenge

    From your backend, with your key. You get back a one-use URL.

    2

    Send the person to that URL

    GET /check/{nonce}

    A redirect or an iframe. Connection, browser and device get measured in about a second — and the person is told nothing.

    3

    Ask for the verdict

    GET /api/v1/identity/verdict/{nonce}

    Signed with Ed25519. Check it yourself: the public key travels in the same response.

    And the answer is one of three
    allowNothing known against it. Let them in.
    reviewMatches somebody already seen on your site. You look at it.
    denyMatches somebody your site blocked.
    What ONYX never gets
    • Your users’ names or emails
    • Your database
    • Any power over your site
    A deny means blocked on your site. Never on somebody else’s: what one customer blocks does not travel to the next, because a shared blocklist is one mistake away from banning a stranger everywhere at once.
    SEC-08ONX-09 · QUORUM

    The blocklist nobody can abuse, because it is not a list

    Ask whether other sites have blocked this same person — without telling us who you are asking about, and without anyone’s block ever becoming yours.

    Everybody picks one of two bad options

    Share nothing

    Every site starts from zero. Somebody who has been hopping from shop to shop for six months is a stranger at the seventh, even though the other six have them on file.

    Share a blocklist

    Now one stranger’s mistake — or one angry admin — shuts a door on you at a site where you have never done anything. And you will never find out why.

    So it shares a number instead of a list

    It can never say deny

    At most it moves an allow to review — «take a look». Turning somebody away stays the decision of the site where something actually happened.

    Two independent sites, or it does not count

    Below two, nothing is returned and nothing is counted. One site’s opinion does not exist here — that is what stops a single mistake from travelling.

    We cannot know who you asked about

    You send the first three characters of a mark and get back the whole bucket; you find yours on your own machine. Not a promise not to look — we cannot. Same trick Have I Been Pwned uses for passwords.

    Undo a block, undo the contribution

    Unblock somebody and your contribution is withdrawn everywhere. Otherwise a mistake would keep counting against them on other people’s sites forever.

    What crosses the wire
    you ask →GET /api/v1/identity/quorum/067
    ← you get back
    { "entries": [
        { "suffix": "045fb…", "sites": 3 },
        { "suffix": "0a91c…", "sites": 2 },
        … 14 more in this bucket
      ] }
    Off by default, and switching it on says exactly what it stores: a global mark of the identities you block — no name, no reason, nothing about the person. With it off nothing is stored: it is not kept-and-ignored, it is not calculated.
    SEC-09Commands

    Every command

    95 commands. Names and descriptions appear in your own Discord language — and /help explains all of it without leaving the app.

    Security
    Moderation
    Intelligence
    Setup
    /verificationEntry portal: IP, device, TOR, VPN and captcha
    /behaviourCatches raiders by what they do, not who they are
    /antinukeMass delete/ban protection + Guardian mode
    /antiraidJoin-wave detection
    /automodSpam, scams, invites, mass mentions, caps
    /hardenStrips dangerous perms from every role
    /lockdownLocks the whole server, reopens it exactly as it was
    /backupFull snapshot: roles, channels and permissions
    /banipBans someone and every alt on their connection
    /channelPer-channel rules (images only, no links…)
    /ban · /unban · /tempbanWith reason, logged and appealable
    /kick · /mute · /unmuteTimeouts with readable durations
    /warn · /warningsWarnings with automatic escalation
    /isolate · /unisolateQuarantine, restoring their roles after
    /clearBulk delete, with filters
    /lock · /unlock · /slowmodeChannel control
    /give-role · /remove-roleRoles you allow, from Discord or the panel
    /note · /historyStaff notes and full record
    /saySpeak as the bot (helpers too)
    /escalationAuto-punishment by number of warnings
    /userProfile, risk level and known alts
    /watchlistAlerts you when someone does anything
    /surveil-allMirrors everything a person does to a staff channel
    /snipeThe last deleted message in the channel
    /transcriptChannel history as a Discord-style web page
    /reportReports with image and video evidence
    /serverStatus and security posture
    /panelLink to the web panel
    /configureRoles, channels, language, log level
    /verification setupCreates roles, channel and permissions for you
    /twitchAnnounces when a streamer goes live
    /syncImports sanctions from another bot
    /helpEverything, explained inside Discord
    SEC-10LIVE READ

    What this page already knows about you

    You did not fill in anything. You did not click anything. This is what any site — and therefore the verification portal — can read the moment you arrive.

    This will read your browser

    The sections below read things from your browser — screen, language, time zone, graphics card — and also give your graphics card two jobs and time how long it takes, to show you what any website can know about you without asking.

    It never leaves your screen: it is computed right here and is not sent or stored anywhere.

    LIVE READREADING…
    Time zoneREADING…
    LanguageREADING…
    ScreenREADING…
    CPU coresREADING…
    MemoryREADING…
    SystemREADING…
    Touch inputREADING…
    GraphicsREADING…
    ConnectionREADING…
    Do Not TrackREADING…
    Device signature
    ····················
    This value stays the same when you change your IP, and it is what catches someone who switches network but not device.
    Nothing on this panel left your browser. There is no request, no cookie and no record: it is computed here and disappears when you close the tab.
    SEC-11ONX-18 · ETHOS

    And this one actually measures your graphics card

    Above, your GPU name is a label: one line in the inspector changes it. Here nothing is asked — the chip is given two jobs and timed. What comes out cannot be edited.

    ONX-18 · ETHOSMEASURING…
    Claims to beMEASURING…
    ComputeMEASURING…
    Fill rateMEASURING…
    RatioMEASURING…
    Behaves likeMEASURING…
    MEASURING…
    The ratio is what survives heat and a patched clock: if the card is slow because it is hot, both timings rise together and the ratio does not move.
    Computed on your machine and it never left it. No request, no cookie, no record.
    SEC-12THREAT MAP

    Where the blocks come from

    Every dot is a country where Argos stopped an entry attempt. Only the country is counted — never who, never from which server, never an IP.

    THREAT MAPlast 7 days
    loading…
    This map is built from an aggregate count per country. There is no record tying any of these numbers to a person, an account or a server.
    SEC-13CERTIFIED

    Servers running it properly

    Having the bot is not the same as having it set up. These communities meet both bars: 5,000 members or more, and 95% of the protection actually enabled.

    loading…
    The badge is re-checked on every request. If a server turns something off, it stops appearing here — without anyone reviewing anything. Admins: run /protected view to see what your server is missing.
    SEC-14LANGUAGES

    Speaks your server’s language

    Commands, logs, the web panel and the verification portal — all of it. Axis picks up your server’s Discord language on its own. Change it any time with /configure language.

    SEC-15SETUP

    Running in two minutes

    Nothing to install, nothing to host. Add it and configure from Discord.

    Add Axis to your server

    It asks only for the permissions it actually uses — never Administrator. A bot that asks for everything is one you should turn down.

    Run /verification setup mode:web

    It creates the roles, the channel and the permissions. Your existing members are untouched — only new arrivals verify.

    Turn on the layers you want

    /verification tor on · /verification fingerprint on · /behaviour enable action:flag

    Watch before you punish

    Leave behaviour detection on alert-only for a few days and read the alerts. Switch it to ban once you have seen it be right on your community.

    One thing Axis cannot do for you: Server Settings → Moderation → Verification Level → Highest (requires a verified phone). Phone numbers cost real money; IP addresses do not. That single toggle stops more alt accounts than any bot can.
    SEC-16PRIVACY

    Where the line is

    A security bot sees a lot. Here is what it never touches.

    IPs are never stored in plain text

    Connections, device fingerprints and the security cookie are stored hashed (HMAC-SHA256) and deleted automatically after 90 days.

    We do not touch what is not ours

    No files, no location, no DMs, no voice call audio. Public server content only, and only for security.

    It is all written down

    What is processed, why, for how long, and your rights — in plain language, not legal fog.

    SEC-17FAQ

    Straight answers

    The questions a server owner actually asks before adding a security bot.

    Do you store my members’ IP addresses?
    Only during web verification, and never in plain text. Your IP is turned into an irreversible hash (HMAC-SHA256), used to catch ban evasion, and deleted after 90 days. On IPv6 only the network prefix is processed, not your exact address. We never see or store a readable IP.
    Will it ban my new members by mistake?
    No. Verification only affects new arrivals — your existing members are never touched. Behaviour detection acts on intent (mass mentions, invites, coordinated spam), never on "you are new and type fast", and you can run it in alert-only mode for as long as you want before it takes any action.
    What permissions does it need, and why not Administrator?
    It asks for the 15 permissions it actually uses — ban, kick, timeout, manage roles/channels, view audit log, and a few more. It never asks for Administrator. A bot that demands full control is one you should turn down, and we are not going to be that bot.
    Is my data shared with other servers, or sold?
    Never. Every server is completely isolated: blocks and intelligence from one community are invisible to every other. There is no global ban list, nothing is sold, and nothing is used for advertising or to train AI.
    Is Axis open source?
    No — and on purpose. Its job is to stop attackers, and publishing exactly how it detects them would hand them the manual. The code is closed, but the Privacy Policy and Terms are fully public, so you always know what it does with your data.
    What happens if it gets something wrong?
    Automated systems do get it wrong sometimes — that is exactly why an appeal system exists. A wrongly-caught user can appeal, and any block can be lifted, which erases both the connection and the device tied to it.
    How much does it cost?
    Nothing. Axis is free to use. Add it, configure it, done.
    SEC-18ABOUT US
    EST. 2021 · A TECHNOLOGY HOUSE

    The Strom Corporation

    The Strom Corporation has been building since 2021. It works through three specialist studios under one roof — from games to artificial intelligence to security — that together form a single ecosystem. Axis is the flagship of that security work.

    It was not written to fill a feature list. It was written for a real community under attack, by people who had to sit and watch the logs at 3 AM. Every layer exists because something got through once — and we made sure it never would again.

    Designed & programmed by Iris  ·  StromStudios project  ·  The Strom Corporation
    — THE STUDIOS —
    StromStudiosMAKES AXIS
    GAMES · BOTS · TOOLS

    The studio behind Axis. It builds the group’s games and bots, and everything it ships to communities.

    StromAegis
    SECURITY · ANTI-FRAUD

    Defence against scams, fraud and threats inside communities. Its craft is what shapes how Axis thinks about attackers.

    StromConnect
    GROWTH · MARKETPLACE

    Reach and growth: a marketplace and asset store built to push projects and creators forward.

    — WHAT THE STUDIOS BUILD —
    20212025
    EST. 2021

    Strom Games

    by StromStudios

    Where it all started. Original titles built in-house — I.F.C., War Field and many more — on the studio’s own engine.

    EST. 2025

    Strom AI

    by StromStudios & StromAegis

    Artificial intelligence with a life of its own. StromBot and Aegis Bot don’t just answer — they build and run their own living worlds.

    EST. 2025

    Strom Security CURRENT

    by StromStudios & StromAegis

    The area that guards large communities. Home of Axis — anti-nuke, anti-raid and ban-evasion, battle-tested against real attacks.

    Home of Axis — join the studio
    JOIN THE STUDIO
    Come see what StromStudios is building
    Join our Discord
    ONYX // AXIS 2.4.4 ATLAS

    Put it in front of your door.

    Free, no premium tier, and every server stays isolated from every other. 59,767 members are already behind it.