Aegis module: blocks XSS, template injection, command injection, path traversal, null bytes and other malicious input in query, body, headers and URL, with editable patterns.
Aegis module: a Content-Security-Policy header for the site and Nova, edited per directive from Nova, with report-only mode, strict validation and a policy-strength check.
Aegis module: rate-limits every IP per minute and bans abusers for hours with 429 and Retry-After, with IP and header exclusions and lock-out protection.