Behavioral Engine
Play is scored against each player’s own baseline rather than a global average, so the outliers in your game stand out within seconds - not after the raid is over.
waves.ac scores behavior on your game's own servers, against each player's own baseline. Evidence is attached to every verdict. Start in shadow mode, watch it work, then enforce on your terms.
Play is scored against each player’s own baseline rather than a global average, so the outliers in your game stand out within seconds - not after the raid is over.
A real-time operations room for your game: streaming events, the review queue, ban history and audit trail. One dashboard, every decision in context.
Recursive identity linkage connects returning offenders across accounts using legitimate platform signals, surfacing suspected alts as reviewable cases.
A cheater confirmed across the network is banned from every waves.ac-protected experience at once, so being caught in one game is not a free move to the next. The bar to reach the network is corroborated machine evidence - no single owner can push a name onto it.
Every player carries a private standing that decides how much benefit of the doubt the engine gives before it reacts. Fair players get trusted; cheaters do not. You choose the minimum standing your game admits - the score itself, and what feeds it, stay with waves so they can’t be farmed.
Ban, warn, look up and decide anti-cheat flags right from your Discord server, with role permissions you control on the dashboard. Every action lands in the console instantly, and live flags post to your channel with one-click decisions.
Launch the demo console: browse the review queue, identity cases, configuration and audit log, and click through every page. No account needed.
The Luau SDK runs in a server Script only, never on the client, and streams HMAC-signed behavioral events through a fail-safe queue. Its guard modules (SpeedCheck, RemoteGuard, EconomyGuard) report through the same pipeline. A typed REST API lets you pull events and cases into your own tooling. Strict TypeScript on the backend, typed Luau in the SDK: the contract cannot drift.
Every verdict carries the signals, baselines and confidence behind it. Reviewable before anything is enforced, auditable forever after.
signalswhat fired, and how much each one countedbaselinemeasured against this player, not a global averageconfidencean honest probability - a heuristic is labelled a heuristiccontextthe session, server and history around the momentevidencemachine-readable, exportable, kept for the recordoutcomewhat waves did, and how to undo itStreaming events, the review queue and the ban stream arrive over WebSocket the moment they happen, so staff act on live state instead of stale exports.
Suspected evasion opens a case: how strong the link is, what it rests on, and the banned account it points back to. Evidence laid out for a human decision.
Remote traffic is judged on the server, where an exploiter cannot forge what we read. Sensitivity is yours to tune per game from the console.
The response is sized to the confidence behind it, and uncertainty always downgrades it. Every rung below a network ban is reversible, and every one is audit-logged.
Every tier includes audit logging, the global auto-ban network and the shadow-first rollout. Want to try it first? The live demo is one click away, no account needed.
Turn on enforcement, with every action reversible and logged.
The full identity graph, premium heuristics and live ops.
Unlimited scale with advanced identity tooling.
Everything you need to know about waves.ac.
Full visibility from the first event, and nothing is enforced until you flip the switch yourself.