How AI Website Security Works | Web Security NZ | Moat AIS

Intelligence built
differently.

Most security tools defend against attacks they've already seen before. Moat AIS learns what your website is supposed to look like in the first place, then stops whatever doesn't fit that picture.

Your website is unique.
Your security should be too.

No two sites look the same under the hood. A blog's traffic bears almost no resemblance to an online shop's, and a news site runs nothing like a SaaS app.

We analyse your specific website to work out what legitimate activity looks like on it, then use that as the baseline. Anything that deviates gets evaluated. Anything that clearly doesn't belong gets blocked.

What you end up with is security shaped to your site alone, and you never had to configure a thing.

Live threat log · web1.example.com
✓ ALLOW 09:14:22 /products/shoes/
✓ ALLOW 09:14:23 /checkout/
✕ BLOCKED 09:14:31 /wp-config.php
✕ BLOCKED 09:14:31 /admin/login.php
✓ ALLOW 09:14:44 /about/
⚠ SCORED 09:14:51 /api/users?id=1 UNION SELECT
93.8% hit rate · 2 IPs auto-banned today

The Moat AIS intelligence stack

01
Site Intelligence

We build up a picture of what your website is supposed to look like: its structure, its patterns, how legitimate visitors tend to behave. This model is built for your site specifically, and only your site.

That picture gets sharper over time. Your dashboard shows you exactly what's permitted, and flags anywhere it needs your input.

02
Real-Time Threat Detection

Every request gets evaluated the moment it arrives, before it touches your server. Fits your site's profile? It passes through without friction. Doesn't fit? It gets assessed, tracked, and acted on.

Persistent or high-risk sources get blocked automatically, and you're not the one who has to step in and do it.

03
AI Pattern Analysis

On a rolling cycle, the AI looks back across recent activity for patterns a single request wouldn't reveal on its own: coordinated behaviour, slow enumeration, attacks spread across multiple sources over time.

It also keeps your protection current as your site changes. Legitimate visitors keep moving freely, things that don't belong get squeezed out, and every decision still runs through you.

Moat AIS vs traditional website security

Feature Moat AIS Traditional WAF IP Blocklist
Site-specific intelligence ✓ Yes ✕ No ✕ No
Zero-day threat detection ✓ Yes Partial ✕ No
No rules to write or maintain ✓ Yes ✕ No ✕ No
AI analysis on a continuous cycle ✓ Yes ✕ No ✕ No
Adapts as your site changes ✓ Automatic Manual ✕ No
Real-time blocking ✓ Yes ✓ Yes Partial
No performance impact on site ✓ None Some latency ✓ Yes
Multi-site dashboard ✓ Included Add-on ✕ No

What Moat AIS stops

Vulnerability scanners
Automated tools that probe for exploitable paths, config files, and outdated software versions.
SQL injection & query attacks
Malicious query strings crafted to extract, manipulate, or wipe out your database.
Path traversal attacks
Directory traversal sequences aimed at reaching files that sit outside your web root.
Zero-day probing
Mass exploitation attempts against newly-disclosed CVEs, blocked at the gateway since the paths they target were never on your site to begin with.
Coordinated & distributed scans
Attacks spread thin across many IPs to slip past simple blocklists. Our AI analysis is built around spotting exactly this kind of coordinated behaviour.
Known attack tools
Recognised scanner and exploitation frameworks, picked out by their signatures and how they behave.
Aggressive bot scraping
High-volume automated harvesting, flagged by known bot signatures and request patterns that don't look human. Rate limits apply to every source, no exceptions.

Website security FAQ

During setup, we register your IP as a training IP, and you just browse your site normally: click through pages, test your forms, use whatever features your visitors would use. We record every URL and query pattern from that session and show them to you to approve in the dashboard. Once approved, those become your site's blueprint. From there, the AI watches real traffic and suggests additions over time, and you can always add paths yourself.
Blocking real visitors isn't the goal here; blocking threats is. The model tells genuine browsing apart from malicious activity with high accuracy, and on the rare occasion something gets flagged wrongly, you can whitelist that path or IP from the dashboard whenever you need to.
No. Our team handles the technical setup for you, and once you're live the dashboard makes sense without a security background. You'll see what's being blocked, what's been stopped, and how things are performing, all in one place.
Yes, and nothing on your server needs to change. We sit in front of your existing server as a security gateway: traffic gets intercepted at the DNS level, filtered, and clean requests get forwarded on. Your CMS, platform, and server config stay exactly as they are, whether that's WordPress, Shopify, WooCommerce, Squarespace, or something you built yourself.
Most sites are live within an hour. DNS propagation is usually the only wait. Once your DNS record points to us, your TLS certificate gets issued automatically and traffic starts flowing through protection right away. We'll email you the moment you're live.
We automatically re-check your site on a weekly cycle to pick up new pages and content. You can also trigger an update yourself at any time from the dashboard, or add new paths straight to your whitelist.
No, and that's deliberate. Every new site starts in Passive Mode, where we score and analyse traffic exactly like we would in live operation, but nothing gets blocked. Threats get flagged in your dashboard as "earmarked" instead, so you can see what the system would have blocked before it blocks anything for real.

Once you're happy with what you see, usually after 24–48 hours of watching it, you flip to Blocking Mode with one click. Everything earmarked gets banned straight away, and new threats are blocked in real time from there. You can switch back to Passive any time you need to make changes safely.
Yes. Government portals, critical infrastructure, and large enterprise deployments come with different requirements: higher traffic volumes, compliance frameworks like NZISM or ISO 27001, data sovereignty, custom SLAs. We scope these individually instead of quoting a fixed price, and our team has spent 15 years managing government and enterprise web infrastructure, so we know what these environments need. Get in touch and we'll work through it with you.

See it in action on your website

Setup takes less than a day. Our team handles the technical side of it.

Get started from $35/month Speak to the team