Secure. Detect. Protect.
The scam doesn’t look like a scam. Until you look properly.
Wardnox is a configurable Discord security and anti-scam platform. It ships with no hardcoded scam phrases. What it catches is a rule you wrote, or a combination of weak signals it can account for to you afterwards.
Starts in monitor mode · Enforces nothing until you say so
A message, as a member sees it
What Wardnox found
- A word broken up by a character with no width
- A letter borrowed from another alphabet
- Support phrasing pushing people into direct messages
- A link arriving alongside both
Removed before anyone read it, and the sender timed out.
The thesis
Four principles, in priority order.
Every design decision traces back to one of them. Where two conflict, the higher number gives way.
Undo the disguise first
Attackers beat naive filters by writing the same thing a different way. Wardnox resolves a message past its disguises before any rule looks at it, and keeps the original untouched, because the original is the evidence.
Combine signals
No single weak signal, not a link, not a new account, not one alarming word, causes enforcement on its own. Detectors return weighted evidence, and the engine only escalates when a genuine pattern appears rather than a coincidence.
Explain every decision
Every action carries a reason your moderators can read: what fired, what it matched, and how the result was reached. No black boxes, and nothing you cannot argue with.
Administrators keep control
The profile, the sensitivity, what each outcome does, and every rule are yours to change. The example rules ship clearly labelled as examples, so nobody mistakes them for a curated ruleset doing the real work.
Evidence, not verdicts
Twenty detectors. None of them can act alone.
Each one returns weighted evidence under a ceiling it cannot exceed, so no single signal, and no pile of weak ones, can quietly add up to a removal nobody sanctioned. Your moderators see what fired and why. Nobody else does.
Restraint by default
A security bot that starts deleting the moment it is invited, on rules the administrator has never seen, is a worse outcome than one that watches quietly for a day.
Monitor mode is the default
A new server scans and logs everything and enforces nothing. You read a day of real decisions against your own traffic, then switch enforcement on deliberately.
It says nothing when it joins
Wardnox posts no setup card and greets nobody. An earlier version once introduced itself inside a server’s verification gate, in front of every arriving member. A security bot’s first act should not be to talk in a channel nobody invited it into.
A rule that misfires gets pulled
If one of your rules starts matching far more than it should, it stops enforcing and your moderators are told, before it becomes a mass deletion.
Guard rails
Promises to your members, not preferences.
An administrator can make Wardnox stricter in a thousand ways. They cannot make it punish somebody for being new. That floor is in the code, not in a setting.
Being new is never enough
Wardnox will not act against somebody for having a new account or having just joined. Those are context for a decision, never the reason for one, and that floor is in the code rather than in a setting somebody could turn off.
AI never decides alone
An AI opinion cannot enforce anything by itself, and the most serious outcomes are kept out of its reach entirely, whatever else it is agreeing with.
You are told what was held back
When a guard rail removes an action, it says so. An administrator who switched something on and saw nothing happen is told why, rather than left concluding it is broken.
Blocking is broader than allowing
Blocking a domain covers everything beneath it. Allowing one covers only what you said. Neither is ever fooled by a familiar name buried inside an unfamiliar one.
One failure is not an outage
If any single part of the analysis fails or times out, its opinion is dropped and the rest still runs. The bot does not fall over because something else did.
Testing changes nothing
Trying a rule out runs it for real but touches no state and reaches nothing, so testing can never make somebody look like they were flooding.
Questions
The things people actually ask.
What is Wardnox?
Wardnox is a configurable Discord security and anti-scam platform. It resolves messages past the disguises attackers use, weighs evidence from twenty independent detectors across four stages, and applies only the response an administrator configured, with a readable explanation behind every decision.
Does Wardnox come with a scam blocklist?
No, and that is deliberate. It ships with no hardcoded scam phrases that block anything on their own. What it catches is either a rule you wrote or a combination of weak signals it can account for to you. The example rules are clearly labelled as examples so nobody mistakes them for a curated ruleset.
Will it start deleting messages as soon as I add it?
No. It starts in monitor mode, which scans, scores and logs everything while enforcing nothing. You read a day of real decisions against your own traffic before switching enforcement on deliberately. The bot also says nothing in your server when it joins.
How does it handle disguised scams?
A filter that only reads what was typed loses to anyone willing to type it differently. Wardnox resolves each message past the common families of disguise before any rule looks at it, covering look-alike characters, invisible ones, text broken apart, and content wrapped in other content. Your moderators are told which form of a message a rule matched, so a catch is never unexplained.
Can a bad rule of mine take down my server?
No. Patterns are checked for dangerous constructions before they can be saved, and run isolated and time bounded so a bad one cannot stall anything. A rule that starts misfiring at scale is pulled automatically and your moderators are notified, before it becomes a mass deletion.
What data does Wardnox store?
Clean messages are never stored. The overwhelming majority of traffic is examined in memory and written nowhere. It never stores direct messages, voice, presence, typing, Discord access tokens at rest, or the contents of attachments. Turning message content storage off entirely is fully supported and does not affect how well it detects anything.
Does anything leave my server?
Nothing leaves the deployment by default. Link resolution, threat intelligence and AI review are each off until you set both an environment variable and a server setting. When enabled, what leaves is limited to what is needed to ask the question, and never user IDs, usernames, channel IDs or guild IDs.
Is Wardnox self-hosted?
Yes. There is no Wardnox-operated service, no telemetry and no phone-home. Whoever runs the deployment is the data controller. It is MIT licensed.

Watch quietly first. Enforce when you’re ready.
Wardnox is opening to servers in batches. Leave your email and we will get in touch when yours can be added, starting, as always, in monitor mode.