Axis
— LEGAL

Changelog

Axis · Updated October 2026

What keeps changing

Every release, what it brings and why. It comes from the same place the bot reads, so it cannot go stale.

2.6.2BASTIONcurrent release2026-09-30

Stopping webhook raids while they are being set up, an anti-nuke that does not wait when one action is already the nuke, and everything in one panel.

  • **/antinuke panel**
  • Everything in one place: overview with a security score, detection, trust (people, roles and bots from menus), webhooks, bots, risks and emergency. /webhooks is now the Webhooks section.
  • **Webhook raids, cut before the first message**
  • Axis now sees webhooks being created, instantly. If one account creates 3 or more in 2 minutes, they are all deleted and the creator is disarmed. A single new webhook from someone who is not trusted gets a warning with «Delete» / «Trust it» buttons.
  • A webhook that was just created by someone who is not trusted, or an old silent one that suddenly posts a link, is deleted on its first @everyone or scam. Webhooks that impersonate the owner, Axis or Discord, and the same message sent through several webhooks, are cut too.
  • **Alert mode**
  • When any defence sees an attack, the whole server goes on alert for 30 minutes: thresholds are halved and new webhooks from anyone untrusted are deleted at once.
  • **Anti-nuke: one action is enough**
  • Administrator given to a role, or dangerous permissions given to @everyone, are reverted on the first try. Stealing the vanity URL, pruning 10+ members or giving moderation powers to @everyone also disarms whoever did it. An admin setting up their mod role is only logged.
  • Alerts now have buttons: «Undo damage», «Ban the attacker», «It was a mistake: give roles back» and «End alert». Only admins can press them. The owner also gets a DM.
  • **Risks and emergency**
  • Risk review: which roles can do damage, whether @everyone has dangerous permissions, which bots have Administrator and what Axis is missing, with one-click fixes that can be undone. «Webhook shield» cuts everything at once.
  • **Radar**
  • The unblock confirmation is now a proper window in the radar style, with a notice when it is done.

2.6.1EGIDA2026-09-30

Verifying without the struggle, a lockdown that really silences, and migration in order.

  • **Verification in two taps**
  • «Verify me» now gives a personal link as a button: no Discord login on the web, no password and no 2FA on your phone. It lasts 10 minutes and works in one browser only.
  • Detection is exactly the same: connection, device and browser are still checked on the page. Servers that want the Discord login can keep it with /verification enable entry: Discord login.
  • Captcha can now be automatic: only people with a risk signal see it (new account, shared connection or device, unusual browser, lockdown). It is 4 digits and «Show another code» does not use up an attempt.
  • When you finish, the page takes you back to the server and the message in Discord changes to «✅ Verified». The Discord login no longer fails with «link expired» when it comes back in another browser.
  • /verification view shows where people stop: how many open the link, pass the captcha, get verified or get blocked, and the most common block reasons.
  • **Migration in order**
  • /verification migrate now starts with the most recent joiners and goes backwards (or the oldest first, if you choose). The preview shows when each one joined.
  • **A lockdown that really silences**
  • /lockdown now also removes the permission to talk from every role in its own settings, and the channel permissions that let a role talk anyway. Only administrators can still talk. When it ends, every role gets back exactly what it had.
  • **Fixes**
  • The verify buttons are acknowledged before anything else, and a failed reply is now logged and retried instead of disappearing.
  • During a lockdown, or when most attempts are being blocked, verification switches back to the Discord login on its own. A big event with thousands of people does not trigger it. The automatic captcha also triggers when the browser was used by another account or several new accounts start from the same connection.
  • The verification log now also lists linked accounts that left the server or were only seen elsewhere with Axis. They are for information only: they never cause a ban, a quarantine or any other action.
  • **No more false alts from common phones**
  • Phones of the same model (especially iPhones) have identical device fingerprints, so strangers showed up as «100 % the same device». A common fingerprint no longer links, blocks or bans anyone on its own; only what belongs to the person does (browser, linked account, a home IP). A blocked IP shared by many people (mobile data, schools) no longer bans whoever joins through it either.
  • «Re-verify the group» button on alt alerts (and /verification migrate group): everyone goes through the portal again, and accounts that share a browser come out confirmed while those that only share a phone model are ruled out. «View the map» shows the group as a graph in /radar (also the 🗺️ Map button on each blocked row).
  • The /radar «Unblock» button now works: it unblocks the IP shown on the row even if that account has moved to another network, rows without an account can be unblocked too, and an error is shown instead of doing nothing. «My server» only lists blocks of servers you have access to.

2.6.0ATENEA2026-09-27

Trust in plain sight: a status page with memory, incidents with reports, notices in your server, the staff shield and hardened bridges.

  • **A status page with memory**
  • /status now keeps 90 days per component, one bar per day. Outages are recorded even when Axis was down, and time covered by the backup node is shown apart.
  • Every incident has a timeline, and anything serious or longer than 15 minutes gets a public report within 48 hours. If it is late, the page says so.
  • Scheduled maintenance is announced ahead of time and does not count as downtime. Four languages, an Atom feed, and never any attack details.
  • **/status in Discord**
  • /status view, server, shield, history and notices. /system is now /status server.
  • Notices: pick a channel and a role; members opt in with a button, and an optional live board updates itself.
  • Shield: threat level, 24-hour alerts, blocks at verification, alt accounts, pending appeals and reports, and defenses that are off. Staff only.
  • **Safety guides**
  • /help safety: seven short guides to the traps that actually happen: fake Nitro, QR codes, stolen accounts, “try my game” files, fake bots and the console, fake staff, and two-factor authentication. Also on the website at /aprende.
  • **Hardened bridges**
  • The bridge to ONYX is end-to-end encrypted, account logins escalate penalties for brute force, and the server gets a hardened Caddy config and a Cloudflare-only firewall.

2.5.0PROMETHEUS2026-09-25

Total infrastructure shielding: tactical frequencies, anti-alt giveaways, and cryptographic quarantine protocol.

  • **Pillar 1: Dynamic Voice Hubs & Tactical Frequencies**
  • Automated tactical voice frequencies with temporary channel lifecycle, auto-cleanup, and complete interactive control panel (/frecuencia).
  • **Pillar 2: Tactical Anti-Alt Giveaways**
  • Provably fair giveaway engine (/sorteo) featuring anti-alt security requirements, server seniority checks, and full interactive management.
  • **Pillar 3: Immediate Quarantine & Cryptographic Anti-Nuke**
  • Immediate account quarantine (/cuarentena) with atomic administrative role stripping, audit channel emergency alerts, and rescue DMs.
  • Cryptographic server snapshots in SQLite WAL mode (/respaldo snapshot) with SHA-256 data integrity validation.

2.4.4ATLAS2026-09-12

Supporting a fair community with quiet participation, autoroles on join, and reaction role panels.

  • **Autoroles and Reaction Roles**
  • Autoroles assigns default server roles cleanly upon member join, strictly honoring role hierarchy and bot permissions.
  • Reaction roles control panel (/reactionroles config) inspired by Strombot with section navigation, dual emoji and button support, and categorized palette.
  • **Silent Moderation and Suggestions**
  • ATLAS gives every member a private overview of their moderation activity without exposing staff notes or anyone else’s data.
  • Members can submit and track suggestions without channel posts, mentions or automatic announcements; result DMs are strictly opt-in.
  • Moderators receive one private inbox combining suggestions, reports, appeals and open cases, plus quiet shift handovers.

2.3.0AEGIS2026-09-10

Responding to an incident without losing control or the server’s previous state.

  • Lockdown now takes a complete snapshot of every channel permission overwrite before touching Discord: @everyone, roles and individual members, including every allow and deny bit. Ending it restores the exact list instead of opening channels indiscriminately.
  • A repeated lockdown can no longer overwrite the original snapshot. The snapshot is written before the first channel is closed, and failed restores remain pending so they can be retried after fixing the bot’s permissions.
  • The private /corp console now includes a Kali-inspired operational terminal backed by the current Ubuntu process: live bot output, deploy history, global search, node and version state, command sync, health checks, deploy and restart through a closed command list.
  • Oracle and Railway now elect a single active node, replicate the same configuration and publish heartbeats. The reserve stays ready without answering the same Discord interaction twice.
  • Command publishing was separated from the bot heartbeat: the normal catalogue is global, the main guild receives an immediate catalogue, owner-only commands stay private, and a failed sync is retried instead of being recorded as successful.
  • Moderation results are readable cards again, with separate member, moderator, reason, severity and status. They now offer case, review, reason editing, appeal, trace and undo actions, and update the original card when its reason changes. Interactions are acknowledged before slow work to prevent Unknown interaction failures.
  • /corp remains the private AXIS owner console: every route requires a signed owner-bound session, attempts are rate-limited and access is written to the chained audit log.

2.2.0FENIX2026-08-23

Recovering from an attack, and sanctions that no longer expire.

  • /backup undo: rebuilds the channels and roles an attack just deleted, permissions included. The structure is saved AT THE MOMENT of deletion, so even things that were in no backup come back — and only what was broken is restored, not the whole server.
  • SERIOUS FIX: the automatic backup NEVER ran on a bot that restarts. It was a 6-hour timer that reset on every boot, so a deploy or a crash restarted it before it ever fired. Owners had it switched on and had no backup at all. The date is now worked out from the last saved backup and survives restarts.
  • SERIOUS FIX: when recovering a channel, its permissions could be lost in silence and the channel came back OPEN TO EVERYONE — a nuke deletes roles before channels, and permissions were stored by role name. The id is now stored and reassigned to the rebuilt role.
  • Anything hanging off a sanction no longer expires: the privacy window erased a banned user’s alt trail, so waiting it out was enough to come back with another account from the same place. The window still applies to anyone without a sanction.
  • The /profile card now explains itself: "Trust" became "Credentials", with the five checks in plain sight (Verified, 6+ months, 1+ year, Clean, Vouched for) and saying outright that it measures neither activity nor popularity. And having the verified role now counts as verified, not just going through the flow.
  • The front page, in plain language in all four languages: no more going round in circles in the header or the architecture section.

2.1.0DOSSIER2026-08-22

The first feature built for the member, not for the staff.

  • /profile: a member’s public card. Verification, veteran standing, BADGES earned on their own — Verified, Veteran, Clean record, Vouched for, Booster, Pioneer, Staff — and a trust bar. It is posted in the channel so it gets seen, and it shows only the good: never moderation data.
  • Text prefix (default ".") and EVERY command reachable by prefix too, not just with "/". Each command’s permission lock is respected exactly the same.
  • Private-network anchoring: someone verifying on mobile data or a public network is not linked there — strangers share an IP like that. It waits for their home network to link their alts without false positives.
  • The leave log became a card: which roles they had, how long they stayed, and what the server dropped to.
  • FIXES: a Twitch live card could stay "LIVE" forever if closing it failed once — it now retries; network anchoring fired too often because of soft API labels; and the /admin panel was redesigned from scratch.

2.0.0LEDGER2026-08-07

No longer asking you to trust: now it can be checked.

  • THE RECEIPT. Whoever is sanctioned gets a paper they can verify themselves: what was decided, when and why, with proof that it was already written at that moment. It does not say who moderated — deliberately, so a receipt does not turn into a target.
  • The log is signed every hour and the signature is published OUTSIDE this server. Rewriting the past stops depending on having access to the machine: it requires contradicting a signature already sitting on someone else’s disk.
  • Merkle tree (RFC 6962): one specific event is proven with sixteen hashes, without showing anybody’s whole log.
  • ONYX is the system and AXIS becomes a connector. The second one, the web, already works: any site with accounts can ask "is this visitor the same person I already blocked?" — and the answer NEVER crosses from one tenant to another.
  • API v1 with narrow-scope keys, tied to a single server and stored only as a hash.
  • Threat model published, including the section on what is NOT covered. Writing it found two real bugs.
  • A SERIOUS BUG: each event’s identifier was four random characters after the millisecond. On a spike of events they collided, the row was lost in silence and the chain broke — the log accused itself of tampering because of its own id generator.
  • /receipt and /integrity: all that machinery, finally visible from Discord.

1.0.0PANOPTES2026-08-05

Taking away its blind spots: what the bot was not watching.

  • A bot marked as trusted was INVISIBLE to the anti-nuke: it was not counted, it did not trigger, and it did not add to the server total. Trust now raises the bar but has a ceiling.
  • The threat map only recorded one of the eight kinds of denial. The most serious ones — ban evasion by connection or device — appeared nowhere.
  • Bot blacklist, applied on join, on being added, and with a sweep of any already inside.
  • Webhook inventory and purge: the only way to cut off a leaked URL.
  • Automod repeat-offence ladder, with exceptions per channel and per rank.
  • VPN false positives: iCloud Private Relay no longer counts as evasion.
  • Encrypted backups (AES-256-GCM), visible from the console.

Back to the start