Skip to main content

Limitations

Dhal is not a complete security platform.

Not a DDoS shield

Dhal runs after traffic reaches your Node process. It cannot stop upstream bandwidth exhaustion.

Use CDN, cloud, or network-level DDoS controls.

Not an auth system

Dhal does not replace authentication, authorization, session management, or password security.

Not input validation

Dhal detects suspicious request patterns, but your app must still validate and sanitize input according to business rules.

Not a guarantee

No WAF guarantees complete protection. Treat Dhal as one layer in a defense-in-depth strategy.

Alpha caution

Dhal is pre-1.0. Pin versions and test policy changes before enforcement.