SYSTEM PATTERN DETECTION
Similarity across users, not just volume.
FloodGuard watches rate. SwarmGuard watches content. It compares messages across different users in a rolling window — when similarity exceeds the threshold, it flags the pattern as coordinated and suppresses the cluster.
This catches the attacks that rate limiting misses: slow, deliberate copy-paste campaigns from multiple accounts posting just under the rate limit.
Configure in dashboard → DETECTION CLUSTER ANALYSIS
Groups, not individuals.
SwarmGuard doesn't ban users one at a time. It identifies the cluster and acts on the group. Clean up a coordinated attack in one action instead of playing whack-a-mole.
FloodGuard → POSTURE CONFIGURABLE TEETH
Dial it up for hostile environments.
Default settings are tuned for normal live shows. If you're running a high-profile stream or expect coordinated interference, tighten the similarity threshold from the dashboard before you go live.
Dashboard → OPERATOR INCIDENT LOG
Cluster events are logged in full.
Every SwarmGuard trigger writes the full cluster to the incident log — messages, users, similarity score, timestamp. Useful for reporting and for tuning your thresholds post-show.
Incident Log →