Aw

Anubis Web AI Firewall - Block AI Scraper Bots

AWS Networking

Anubis, a self hostable web AI firewall that stops abusive AI scrapers with a lightweight proof of work challenge, up and protecting your app the moment it boots.

Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

Anubis is an open source web AI firewall and reverse proxy that weighs the soul of every incoming request to keep AI scrapers and abusive crawlers off your site. It sits in front of your application, lets normal human visitors straight through, serves suspicious browsers a lightweight proof of work challenge, and blocks known AI crawlers such as Amazonbot, Bytespider, PerplexityBot and Scrapy outright, so aggressive bots stop hammering your site and running up your bandwidth. A single Go binary runs continuously under systemd and reverse proxies to an upstream you choose.

Why the cloudimg image

cloudimg ships Anubis fully patched and secure by default, behind an nginx TLS terminator, with no secret baked into the image: the ED25519 signing key and the TLS certificate are both generated uniquely on each instance's first boot. It boots protecting a bundled demo upstream so you can see the firewall working immediately, then you repoint the target at your own application. Paired with a step by step deploy guide and backed by 24/7 support.

Common uses

  • Shield a website, wiki, forge or docs site from AI scraper traffic
  • Put a proof of work firewall in front of an API or app
  • Cut bandwidth and compute costs driven by abusive crawlers

Key features

  • A self-hostable Web AI Firewall and reverse proxy that stops AI scrapers and abusive crawlers with a lightweight proof-of-work challenge, preinstalled and running under systemd behind an nginx TLS terminator within minutes of launch
  • Allow-by-default policy lets normal human visitors straight through while known AI crawlers such as Amazonbot, Bytespider, PerplexityBot and Scrapy are blocked or challenged, protecting a bundled demo upstream you can repoint at your own application
  • Secure by default with a unique ED25519 signing key and TLS certificate generated on first boot and never baked into the image, loopback-only Prometheus metrics, fully patched OS with unattended updates, and 24/7 cloudimg support

Description

This is a repackaged open source software product wherein additional charges apply for cloudimg support services.

Anubis is a self-hostable Web AI Firewall and reverse proxy that weighs the soul of every incoming HTTP request to stop AI scrapers and abusive crawlers before they reach your application. A single Go binary runs continuously under systemd, reverse-proxying to an upstream you choose while serving a lightweight, browser-transparent proof-of-work challenge, or an outright deny, to flagged AI-crawler user agents. Normal human visitors are allowed straight through by the default policy, so legitimate traffic is unaffected while known scrapers such as Amazonbot, Bytespider, PerplexityBot and Scrapy are blocked or challenged. This image delivers Anubis fully installed and running behind an nginx TLS terminator, protecting a bundled demo upstream out of the box, so a working firewall is answering within minutes of launch with no compilation and no configuration required to get started.

Unlike a bare deployment, this image is configured to be secure by default. There is no signing key or TLS certificate baked into the image: Anubis's ED25519 JWT signing key and the nginx self-signed certificate are both generated uniquely on this instance's first boot and never shipped inside the image. nginx terminates HTTPS on port 443 with the per-instance certificate and reverse-proxies to Anubis on the loopback interface, forwarding the real client address so policy decisions are accurate. Prometheus metrics are exposed on the loopback interface for monitoring, an unauthenticated health probe and an HTTP-to-HTTPS redirect are served on port 80, and the operating system ships fully patched with unattended security updates enabled. systemd manages the service for automatic restarts and clean logging.

To protect your own application, point the upstream target at your service and restart, or tune the built-in bot policy to widen or narrow what is challenged. Use Anubis to shield a website, wiki, forge, API or documentation site from the surge of AI-crawler traffic that drives up bandwidth and compute costs, all without blocking real users. The current release available is Anubis 1.25.0.

This is a repackaged open source software product with additional charges for cloudimg support services. Anubis is distributed under the MIT license. cloudimg is not affiliated with or endorsed by the Anubis project or Techaro. All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.

Related technologies

anubisweb ai firewallai scraperbot protectionreverse proxyproof of workanti scrapingcrawler blockerrate limitingcloudimg