ONX

Product

Protection that knows your business

Hotels fill rooms. Municipalities stay reachable. Shops keep selling. ONX decides on your server — and the contract stays in Europe.

01 / Hotels

ONX Hotel

Guests book. Bots don’t. ONX learns your reservation flow so rooms fill and reception stays with people, not scrapers.

02 / Public sector

ONX Municipality

The official site stays open. Citizens reach services, login and forms — on your server, in the EU, with a DPA legal can sign.

03 / Commerce

ONX E-shop

Prices, stock and checkout stay for customers. ONX learns your catalogue, search and cart so shoppers move — automated harvesting does not.

Detection

It learns the whole site — then the busy pages too

Most firewalls treat every request the same. ONX sits on your origin and learns the whole site — and already knows what a hotel, a municipality or a shop should look like.

  • Inspects every request that reaches PHP, not only forms
  • Catches injection and script probes before they hit the app
  • Notices when any known page is used the wrong way
  • Calms storms on login, booking and the rest of the site
A booking URL, learned
POST /booking/{id}
params: guests, date, notes
methods: POST 98% · GET 2%
notes_max_len: 400

Flagged when notes arrives at 8,492 characters.

How data moves

  1. The visitor reaches your server
  2. ONX decides on your server
  3. You get a clear picture in the EU console
  4. The DPA is written with you

EU compliance

Compliance that helps you win the deal

Protection stays on your server. The picture you need stays in the EU. We write the DPA together — hotels, towns and shops included.

  • Console and processing hosted in the EU
  • Only what you need to run protection — not a visitor dossier
  • Public-sector defaults your counsel can accept
  • A DPA tailored to this customer

Bots

Real search engines in. Fake ones out.

Google and Bing keep indexing. Scrapers and impersonators stop wasting the pages that sell rooms, services and products.

  • You choose which crawlers are welcome
  • Fake Google and Bing are checked, not trusted
  • Spoofed browsers lose the disguise
  • Doubtful traffic pays the cost — guests don’t
Crawler verification
User-Agent: bingbot/2.0
claimed crawler → reverse + forward DNS
IP matches Bing ranges
result → pass

Operations

Everything that makes it easy to own

The extras your partner and your team will actually use.

Quiet the rush

Booking and login stay usable. Scrapers get slowed down so your real traffic keeps the floor.

Forms that fight back

Hidden traps and proven checks stop the scripts that try to break login, contact and checkout.

One view for every site

See every hotel, town or shop you protect. Fix a mistake in one click. Sleep better.

Updates you approve

New protection arrives signed. You say when it goes live. Sites pick it up on their own.

A head start

A new hotel, municipality or shop is protected from day one — then ONX learns the details of this site.

A DPA you can take to legal

Every deployment includes the contract. Public-sector sites get the stricter path. We finish the details with you.

OWASP Top 10 · 2025

Coverage you can show a customer

ONX maps to the OWASP Top 10. You see the matches first — then you decide how tightly to close the door.

A01 Broken Access ControlPartialForced browsing, path traversal, sensitive file probes, parameter tampering and unusual API shapes.
A02 Security MisconfigurationPartialExposed config files, hidden paths and suspicious default admin routes.
A03 Software Supply Chain FailuresPracticeClient releases are signed and verified on every update.
A04 Cryptographic FailuresPracticeONX does not replace TLS. It helps keep transport headers honest.
A05 InjectionCoveredSQL, script, command, file and template injection — including the usual obfuscations.
A06 Insecure DesignPracticeDefense in depth. The application’s design remains yours.
A07 Authentication FailuresPartialSlows stuffing and brute force on login and booking.
A08 Software or Data Integrity FailuresCoveredSigned core releases, verified before a site accepts them.
A09 Security Logging & AlertingCoveredIncidents, an audit trail and a console your operator can read.
A10 Exceptional ConditionsPracticeAbnormal request patterns are captured. Safe error pages remain the application’s job.

Want this on your sites?

We’ll walk through the hotel, the municipality or the shop — and the DPA that goes with it.

Start a conversation

Why EU teams choose ONX