Documentation
Security operations documentation
What BastionHub does
BastionHub is a Discord-native cybersecurity monitoring platform. The security engine watches for threats around the clock — phishing, scams, raids, privilege abuse, webhook attacks, and configuration drift — from members through staff. Your team operates from the BastionHub dashboard so they don't have to live in Discord for delegated security work. You define the rules. BastionHub enforces them.
What we monitor
Six threat classes monitored continuously within Discord's granted access. Message content scanned in memory — never stored. Audit records keep action, IDs, and reason codes only.
PHISHING
Phishing & scam links
Malicious links detected as messages arrive — including edited messages and embed text. Message removed, attacker queued for ban review. Hostnames logged; content never stored.
FRAUD
Fraud & social engineering
Fake giveaways, staff impersonation, seed-phrase requests, advance-fee scams. Attacker timed out, message deleted, ban decision queued for your approval.
IMPERSONATION
Impersonation & lookalikes
Names mimicking your owner, staff, Discord titles, or brands — including homoglyphs. Caught on join and rename. Account contained and flagged.
RAID
Join-burst raids
Sudden new-member spikes flagged with counts and severity. Optional auto invite-pause stops the inflow while your team responds.
BOT_SPAM
Bot spam & floods
Rapid repeated messages from single accounts or coordinated patterns detected and rate-limited. Only action and IDs logged.
STAFF_PRIVILEGE
Staff privilege abuse
Permission changes, role grants, webhook creation, Administrator grants monitored. Suspicious clusters correlated as potential compromise and escalated.
How we keep your server secure
Server-side only
The browser never controls Discord. Auth, policy, and execution enforced server-side.
Fail closed
If state can't be verified or Discord is unreachable, dangerous operations don't run.
Tenant isolation
Your server's data is scoped to your server. Enforced at app layer and database layer.
Bounded authority
The bot requests Administrator so every feature executes. BastionHub never grants Administrator to staff — nobody exceeds their mapped role.
Verify after execute
Discord API success isn't done. Resulting state confirmed against intent. Drift is an incident.
Tamper-evident audit
Every security action logged with who, what, when, why. Retained per your plan tier.
Permissions the bot requests
Discord's authorization screen shows this list before you confirm. BastionHub requests Administrator once at install so nothing it advertises hits a permission wall.
Moderation & security
- Kick, Ban & Moderate Members — server-side security response and timeout actions
- Mute, Deafen & Move Members — voice-channel containment during incidents
- Manage Messages & Read Message History — detection and approved message removal
Server management
- Manage Roles, Channels & Nicknames — the Server Redesign role, category, and channel editor
- Manage Server & Events — approved server policy and event operations
- Manage Webhooks & View Audit Log — configuration and staff-security monitoring
What data we store
Stored on AWS (US-West-2) via Supabase managed PostgreSQL. Encryption at rest (AES-256) and in transit (TLS 1.2+).
What we store (metadata only)
- Discord IDs — Server, user, channel, message, role IDs
- Display names — Username, display name (anonymized on erasure)
- Threat metadata — Type, severity, action, reason, hostname
- Audit records — Actor, action, timestamp, target server
- Server metadata — Name, member count, configuration flags
- Billing records — Stripe customer ID, subscription, plan tier
- Exposure findings — Breach name, date, severity (no emails)
- Auth metadata — Encrypted TOTP secrets, sealed session cookies
What we never store
- Discord message bodies, embeds, or attachments
- Seed phrases, passwords, or credentials
- Raw webhook tokens
- Discord OAuth tokens (in-memory only, never persisted)
- Individual email addresses from breach data
- Payment card numbers (Stripe only)
- Member IP addresses (Discord doesn't expose them)
Compliance and audit
Audit trail
Every action — detection, containment, approval, export, deletion, config change — logged with who, what, when, why. Separate compliance audit events for search, export, legal hold, view, and delete. Retained 90 days (Basic), 7 years (Pro), contract (Enterprise).
Step-up MFA
Tenant wipe and subject erasure require a recent MFA challenge, not just 2FA enabled. Prevents stolen sessions from deleting compliance data.
Litigation hold
Pauses retention purge for your server. Expired records preserved until lifted. Hold state, timestamp, and actor recorded. Two levels: guild-wide and per-record.
SIEM auto-export
Pro+ ships threat metadata to your S3, Azure, or SIEM webhook on a schedule. HMAC-SHA256 signed. Cloud keys never stored in BastionHub — you run the collector.
Tamper-evident exports
Export bundles use SHA-256 hash chain, manifest hash, and HMAC-SHA256 signature. Archive manifests chain via sequenceNumber + previousManifestSha256.
GDPR & CCPA rights
Access, Portability, Erasure, Objection, and Restriction available via Owner Dashboard. Public form at /privacy-policy/request-deletion for data subjects (not just owners). CCPA Do Not Sell disclosed — BastionHub doesn't sell data.
Per-category retention
Configurable retention overrides per data category (threat metadata, audit, config snapshot, exposure finding). Plan-tier maximums enforced.
Data Processing Agreement
12-section DPA template available for legal review. Enterprise includes a signed DPA in contract.
Plans and entitlements
Entitlements unlock from verified subscription state. Payment truth from Stripe webhooks, never the browser.
Basic
$29.99/mo · One server, <500 members
Retention: 90 days
- 24/7 phishing, scam, raid, flood, impersonation monitoring
- Fraud hold with ban approval
- Owner + Staff Dashboard access
- Audit trail with export and deletion
- GDPR Right to Erasure
- Litigation hold
Not included: Exposure monitoring, SIEM auto-export, Server Redesign, Extended archive
Pro
$99.99/mo · One server, <500 members, advanced
Retention: Up to 7 years
- Everything in Basic
- Advanced staff privilege monitoring
- Exposure monitoring (domain-verified)
- SIEM auto-export (S3/Azure/SIEM)
- Evidence archive with SHA-256 manifests
- Server Redesign included
- 7-year compliance archive
Not included: Multiple server seats, Contract retention/residency
Enterprise
$499+/mo · Multiple verified server seats
Retention: Contract-defined
- Everything in Pro
- Multiple verified server seats
- Contract-defined retention (up to indefinite)
- EU data residency available
- DPA included
- Custom audit requirements negotiated
- Dedicated onboarding and escalation
Standalone Server Redesign
$49.99 one-time · One-time server restructure
Retention: N/A
- Guided restructure (roles, channels, permissions, AutoMod)
- Configuration preview before apply
- Security simulation before apply
- Post-apply verification and audit
Not included: Ongoing monitoring, Threat logs, Exposure monitoring
Your responsibilities as owner
Bot role position
If BastionHub's role is moved below one it manages, protection degrades and you're guided to fix it.
Don't hand out Administrator
The BastionHub bot requests it once at install — members should not get it through BastionHub or Discord unless truly needed. Staff with Administrator in Discord are still constrained by BastionHub role mapping.
Review pending approvals
Approvals expire. On expiry, no action is taken. Review before they lapse.
Use /security probe only
Never paste real phishing URLs or scam phrases to test. /security probe is the only safe synthetic test.
Honest Discord limitations
Message deletion not instant
Discord delivers messages after acceptance. Removal is as fast as the API allows; a brief flicker is possible.
No member IP addresses
Discord doesn't expose member IPs to bots. Same-IP cascade bans unavailable. Detected account only.
Privileged intents scoped
Message content, member info, presence depend on Discord's access rules. BastionHub degrades honestly if not granted.
Auto-export is BastionHub data
SIEM export ships BastionHub threat metadata, not Discord's audit log. Discord's native audit log stays under Discord's control.
Customer portals
Owner Dashboard (after bot + plan)
Verified Discord server owner only. Full BastionHub capability: security, approvals, staff, billing, audit, compliance, Server Redesign. Not Discord Administrator, not other servers.
Staff Dashboard (after bot + plan)
Staff access based on mapped Discord role. Staff see only what their BastionHub role permits — even if Discord allows more. Mapping never grants Administrator.