AIPM Defense · Tier 2

Valve

One-click allow/deny for 40+ AI crawlers, applied to your CDN. Named stances. Continuous proof.

$499 / month
Start Valve → Back to overview

Stripe checkout coming this week. Onboarding includes CDN credential review call.

Everything in Observatory, plus policy

Observatory tells you who's crawling. Valve lets you do something about it. Per-vendor. Per-stance. With audit-log proof that the policy is actually applied — because we read the same log to confirm the block is firing.

Named stances (one click each)

Training Opt-Out

blocks: GPTBot, ClaudeBot, Google-Extended, CCBot, anthropic-ai, Bytespider, FacebookBot, Meta-ExternalAgent, Applebot-Extended

Keeps retrieval bots and traditional search. Denies the crawlers that feed future training sets. The stance most privacy-conscious brands actually want.

Retrieval-Only

allows: OAI-SearchBot, ChatGPT-User, PerplexityBot, ClaudeBot, Googlebot, Bingbot · blocks: training crawlers

AI assistants can cite you live at query time. Training crawlers don't ingest you. Useful for publishers and news outlets with IP concerns.

Pre-Launch Stealth

blocks: all AI crawlers · allows: Googlebot, Bingbot

Your product announcement ships next month. You don't want models trained today to "know" about it. Block training crawlers now; flip to Retrieval-Only on launch day. Audit log proves the exclusion window.

Full Blackout

blocks: everything AI · allows: traditional search bots

The nuclear option. Nothing AI-shaped sees the site. Traditional search still works. Some legal cases require this for discovery windows.

Custom

per-crawler rules

Allow Claude. Block ChatGPT. Challenge Perplexity with a CAPTCHA. Rate-limit Bytespider. Anything the CDN can express, we can automate.

CDN support matrix

CDNIntegrationVerified-bot primitiveAudit log
CloudflareNativecf.client.bot + Super Bot Fight ModeGraphQL, per-request
AkamaiManaged rulesBot Manager Premier (Known Bot Directory)Per-request
FastlyManaged rulesNGWAF + ACL via VCLPer-request
AWS CloudFrontOn requestWAF Bot Control (paid) or custom Lambda@EdgeCloudWatch, coarse
Azure Front DoorOn requestWAF managed rules + reverse-DNS LambdaLog Analytics, coarse
OtherForensics tierCustom engagementVaries

If you're on Cloudflare, onboarding takes one video call and the rule goes live the same day. Akamai and Fastly typically take a week end-to-end because of your ops team's change-control, not ours.

The workflow

  1. You pick a stance (or we build one with you).
  2. We push the rule to your CDN through a service account you own and can revoke.
  3. The audit log records the rule, the fires, and the exemptions.
  4. You get a weekly attestation: "Policy X was continuously enforced from date Y to date Z, N requests allowed, M denied."
  5. If anything drifts, Observatory alerts fire within the hour.

The Honest Version

We don't host your content. We don't sit inline. We hand your CDN a managed rule and read the log back. If you fire us, the rules stay; you just stop getting updates and attestations. The lock-in is the maintenance and the receipts, not the enforcement point.

Start controlling the valve

Includes one onboarding call, CDN-rule deployment, and 90-day rule maintenance. Cancel anytime.

Start Valve — $499/mo Need diagnostics? See Forensics →