Discord security and verification
PulseGuard
Configure deterministic detection, raid containment, browser verification, retention, and optional local AI.
Open PulseGuardGetting started
PulseGuard works with deterministic protection first. AI and external scanners stay optional.
Deploy the stack
Configure Discord credentials, Auth.js, MySQL, and the shared service tokens, then run migrations and the seed command.
Invite the bot
Place the bot role high enough for moderation and containment actions, then confirm the dashboard can see the guild.
Review trusted administrators
Limit trusted-admin configuration to people who should be exempt from permission escalation and containment checks.
Enable modules deliberately
Start with deterministic detection and conservative thresholds, then add verification, cross-server sharing, OCR, ClamAV, or local AI as needed.
Protection modules
Signals combine content, behavior, permissions, and account context.
Raid and nuke detection
Monitors action velocity, permission escalation, destructive changes, and coordinated behavior.
Content detection
Checks scams, suspicious links, invite spam, mass mentions, floods, custom keywords, regex rules, QR codes, OCR text, and attachment hashes.
Containment
Quarantine and lockdown actions limit damage while backup and restore tools preserve recoverable configuration.
Optional local AI
Ollama can add scam judgment, summaries, and a moderation assistant without requiring a hosted AI account.
Member verification
PulseGuard is the central verification product across the Pulse ecosystem.
Browser challenge
New members can complete a local proof-of-work challenge with confidence scoring and moderator review for uncertain cases.
Network signals
Trusted networks and locally refreshed hosting, proxy, VPN, and Tor ranges contribute risk signals instead of acting as a single automatic block.
Reverse proxy safety
Only enable TRUST_PROXY when the real proxy overwrites X-Forwarded-For. An append-only proxy lets clients spoof their address.
Product ownership
PulseRP no longer runs a separate verification gate. Verification configuration and member review belong here.
Configuration and privacy
Discord commands and dashboard forms use the same guild-scoped configuration contract.
Discord configuration
Use /config and /automod for retention, velocity, trusted admins, invite allowlists, lockdown behavior, and content rules.
Dashboard configuration
The guild configuration page exposes the same settings with security scores, timelines, and quarantine management.
Retention
Choose raw-content retention intentionally and keep private evidence only as long as moderation operations require it.
External data
Malware and CSAM hash tables ship empty. Operators must supply legally authorized feeds and reporting infrastructure.