Capabilities

Every layer you need to stop evasion

Vidar combines network intelligence, device identity, account signals and cross-server history into one tunable, explainable system.

Alt & ban-evasion detection

Links a joining account to known members using hashed device fingerprints, exact-IP and network matches, and network-operator correlation — each link scored for confidence.

VPN, proxy & Tor intelligence

Live IP intelligence flags commercial VPNs, public and residential proxies, Tor exit nodes, and datacenter ranges, plus geo and ASN context.

Explainable confidence scoring

A bounded log-odds model turns evidence into a 0–100 risk score. Every verdict ships with the exact signals and weights that produced it.

Raid protection

Detects coordinated join-bursts via velocity, account-age clustering, shared networks/devices, and username patterns — with a hard floor so small organic waves never trip it.

Cross-server global checks

Optionally consult an anonymized, network-wide sighting index to catch accounts already flagged on other Vidar-protected servers.

Role automation

Choose the verified role assigned on success and an optional hold role while verification is pending. Vidar manages assignment through Discord's API.

Tunable policy

Approve/deny thresholds, blockable network types, minimum account age, verified-email requirement, and raid sensitivity — all per server.

Moderator alerts

Risky verifications and raid events are posted to your log channel with the full reasoning, so your team can act fast.

Audit & review queue

Every decision is logged. Held verifications land in a review queue where moderators can approve or deny with one click.

Privacy-respecting by design

No raw IPs, no message content. Only salted hashes and coarse network buckets, with short retention on the most sensitive values.

Fast & resilient

Verdicts in seconds. If IP intelligence is unavailable, Vidar fails open and scores on the remaining signals rather than blocking everyone.

Secure dashboard

Discord OAuth sign-in, per-server authorization checked against Manage-Server permission, and a hardened, CSP-protected web app.