Limitations
Dhal is not a complete security platform.
Not a DDoS shield
Dhal runs after traffic reaches your Node process. It cannot stop upstream bandwidth exhaustion.
Use CDN, cloud, or network-level DDoS controls.
Not an auth system
Dhal does not replace authentication, authorization, session management, or password security.
Not input validation
Dhal detects suspicious request patterns, but your app must still validate and sanitize input according to business rules.
Not a guarantee
No WAF guarantees complete protection. Treat Dhal as one layer in a defense-in-depth strategy.
Alpha caution
Dhal is pre-1.0. Pin versions and test policy changes before enforcement.