1.Most detectors advise. About thirty controls block out of the box.
On a fresh install from the quick start, about thirty distinct controls refuse a request: body-size limits, an identity check on every route, four layers of rate limiting, a WAF with nine built-in block rules, CSRF protection, and the AI gateway and MCP checks marked ENFORCING on the homepage. The MCP tool-call path is default-deny.
Much of the rest is advisory by design, and some controls that can block ship switched off. Threat-detection blocking is off in the shipped configuration, and the gateway guardrail policies log rather than block. You decide, control by control, what enforces in your deployment.
Source: Default-posture audit of a fresh quick-start install, September 2026.