By Outcome — Veri ve Erişim Güvenliği

Protection built for the AI era

Classical WAAP stops yesterday's attacks. AI-era attackers operate at machine speed, run OCR on screenshots, and look like real users. TR7 adds the layers built for what they actually do — and that combination is unique in the WAAP category.

The threat model has moved. Vision language models read your screen as well as a human reads it. AI agents browse your application, click your links and submit your forms at scale. Scraper farms drift their tempo to look human. None of this is what classical WAAP rules were built to catch — signature databases and bot fingerprints assume yesterday's threat. TR7 ships the next layer: anti-OCR rendering that makes screen-grabbing unreliable for AI pipelines, agent-aware traffic handling that tells helpful AI from harmful AI, scraper-class behavior detection at the 11-factor scoring engine, and forensic watermark that travels with every served page. Each piece sits on TR7 WAAP. The combination is unique.

5 unique
Layers built specifically for the AI era — combination available only on TR7
Same WAAP
Runs inside TR7 WAAP — no separate AI-defense product to license
Operator-visible
11 named scoring factors, anti-OCR settings and watermark logs all inspectable — not a black box

The attack model has changed faster than classical WAAP rules

Classical WAAP assumes the attacker is a script or a hand-driven session. Signatures match known payloads. Bot fingerprints catch obvious automation. That work is still essential, and TR7 WAAP keeps doing it. But the modern attacker is different. Vision language models — GPT-4V, Claude Vision, Gemini and their open-source descendants — read rendered pages as well as a human reads them. AI agents drive browsers at scale, click through application flows, submit forms, harvest content. Scraper farms randomize cadence, rotate identities and drift their behavior toward something that looks like a real user.

The defenses other WAAP vendors offer for this surface are incomplete. Most don't have anti-OCR at all. Bot management products treat AI traffic as another bot family — useful, but blind to the screen-grab path. RBI products that exist are usually cloud-only and not integrated with the WAAP that protects the underlying service.

TR7 takes the new threats one by one and adds the layer that addresses each. Anti-OCR rendering for the screen-grab path. Agent-aware classification for AI traffic that is sometimes good (search indexing) and sometimes hostile (training-data theft, automated abuse). Scraper-class behavior detection in the 11-factor scoring engine. Forensic watermark that travels with every served page, so a leaked screenshot still points back to a session. All of it on the same platform that already runs your WAAP — the layers engage where the service needs them.

Five layers built for the AI era — only on TR7

These layers sit on top of TR7 WAAP. They are designed for the threats classical WAAP rules don't see. The combination — anti-OCR + agent-aware + scraper detection + forensic watermark + WAAP integration — exists in no other WAAP product.

Anti-OCR rendering — built for screen-grab AI pipelines

Modern attackers capture the rendered page and run vision language models or OCR engines to extract the underlying text. TR7's anti-OCR rendering shapes the output to resist automated extraction — text is delivered as visual elements that look right to a human and break automated pipelines. A human reading the page sees normal, readable content. A machine running OCR or VLM extraction on the screenshot finds recovery unreliable.

Agent-aware traffic handling — good AI vs harmful AI

Not all AI traffic is hostile. Search engine indexing crawlers, accessibility assistants and legitimate enterprise agents have a place. Training-data scrapers, automated account takeover agents and credential testers do not. TR7 classifies AI agent traffic distinctly from human users and from classical bot families, and policy decides per use case — allow, throttle, challenge or block.

Scraper-class behavior detection in the 11-factor scoring engine

Modern scraper farms randomize cadence, rotate identities and drift behavior. The 11-factor scoring engine — already used for bot management across the platform — recognises scraper-class signatures: sequential traversal patterns, atypical request timing rhythms, content-following access paths. Operator-visible weights and tunable thresholds; no black-box ML.

Forensic watermark that survives screenshots

Every served page carries an embedded marker — visible or steganographic — tied to a session, user identity and timestamp. The watermark is shaped to survive screenshot, OCR re-extraction and AI rewriting. When sensitive content surfaces outside the application, the trace points back to where the leak originated.

Integrated with WAAP — not a separate product

All four layers above run inside the same TR7 WAAP that already protects the application. One vService, one policy framework, one operator console. The classical WAAP foundation is still there for yesterday's attacks; these layers handle the AI-era part. No separate AI-defense appliance to license, no second policy engine, no second audit trail.

What TR7 brings together for AI-era protection

Every capability below is part of TR7's WAAP platform. The combination — not any single feature — is what makes it unique.

Anti-OCR rendering against vision language models

Output is shaped to resist OCR and VLM extraction pipelines. Text is delivered as visual elements that read normally to a human but fail under automated OCR. A page that survives a competitor's scraper survives a competitor's vision model too.

AI agent classification

Traffic from AI agents is classified distinctly from human traffic and from classical bot families. Known good agents (search indexing, accessibility tools, legitimate AI assistants) can be allowed. Hostile agents (training-data scrapers, automated abuse) can be blocked, throttled or challenged. Per-vService policy controls the decision.

Scraper-class behavior detection

11-factor scoring engine recognises sequential traversal patterns, content-following access paths, abnormal request rhythms and other signatures of scraper farms — even when each individual source looks like a real user. Operator can see which factors contributed; weights are tunable.

Forensic watermark that survives screenshots and OCR

Watermark is shaped to remain identifiable after screenshot capture, OCR re-extraction or AI-based content rewriting. A leaked artifact still points to the originating session, user and timestamp.

ZeroLeak server-side rendering for sensitive services

Sensitive services that warrant it run through the ZeroLeak isolation gateway — application renders on the TR7 platform, browser sees only the rendered output. Combined with anti-OCR rendering, the screen-grab path becomes unreliable for sensitive data.

Endpoint security signal integration

Device-trust signals from TR7's endpoint security layer feed agent and access decisions. A request from a known managed device with healthy posture scores differently than a request from an unmanaged endpoint that looks suspiciously script-like.

Content-aware traffic rules including JSON body values

Rate-limit, challenge or block AI traffic based on any traffic attribute — including values parsed from JSON request bodies. Throttle agent traffic by claimed identity, by data volume requested, or by access pattern.

CWE, CAPEC and MITRE ATT&CK mapping for AI-era detections

AI-era detections map to the same security taxonomy as the rest of WAAP — SIEM correlation, incident response and compliance reports see AI attacks in the language your security team already uses.

Pair with the Anti-OCR capability deep-dive

For the technical mechanism behind anti-OCR rendering — how text is shaped, how OCR pipelines fail, how the human reading experience stays uncompromised — see the Anti-OCR capability page in Features.

Same console, same operator view, same audit trail

AI-era detections, anti-OCR engagement, agent classification decisions and watermark events all log to the same console used for WAAP, ADC and ZTA. One operator view across the whole platform.

On-prem — your data and AI defenses stay in your own network

Anti-OCR rendering, agent classification, scoring and watermarking all run on your hardware. No third-party AI defense in the path of your sensitive data.

BW model — blocked AI traffic doesn't count

AI scrapers throttled, training-data crawlers blocked and abusive AI agents dropped are all excluded from the bandwidth meter, like everywhere else on the platform.

What's unique here — and why other WAAP vendors don't have it

This is the place to be specific. The combination below is the unique-to-TR7 cluster — not any one feature, but the five together as one platform.

01

Anti-OCR rendering for screen-grab AI pipelines

TR7 is the only WAAP vendor that ships anti-OCR rendering as a product feature. Cloud-only RBI products focus on browser isolation; classical DLP products focus on endpoint agents. Neither addresses the AI pipeline that screenshots a rendered page and runs OCR/VLM extraction on the image. TR7 does.

02

Forensic watermark on web content

Watermarking that survives screenshot, printing, copy and AI-rewriting — embedded in every served page, tied to session and user. No other WAAP vendor offers this. The closest comparison is in DRM products for media, which solve a different problem.

03

Agent-aware traffic classification

Most bot management products treat AI agents as a new bot family or a single category. TR7 separates known good agents from hostile agents and applies different policies — useful for organizations that want indexing to work while training-data theft is blocked. The classification is operator-visible, not a black-box model output.

04

Transparent 11-factor scoring extended to AI traffic

Most competitor bot scoring is opaque ML. TR7's scoring uses 11 named factors with operator-tunable weights — the same engine that scores classical bots also scores AI agents and scraper farms. The factors are inspectable, and the weights can be tuned for a specific application's normal AI traffic profile.

05

All of this on the same WAAP — not a separate product

Other WAAP vendors that want AI-era coverage point to separate products: a bot management service, a browser isolation product, a fraud-detection platform. TR7 ships these layers inside the same WAAP that already protects the application. One vService, one policy view, one audit trail.

Where this outcome shows up

Sensitive content under AI-era screen-grab attempts

Admin panels, customer-data dashboards and regulated portals where attackers screenshot and run OCR/VLM to extract text. Anti-OCR rendering makes the extraction pipeline unreliable; ZeroLeak isolation ensures the rendered page is the only artifact reachable from the client.

Publishers and content businesses under AI scraping

Articles, product catalogs and structured content harvested at scale by AI training scrapers. TR7 classifies the agent class, the operator decides whether to allow, throttle, license or block. Forensic watermark identifies the source if content reaches places it shouldn't.

Public sites with mixed AI traffic — wanted and unwanted

Some AI agents you want (search indexing, accessibility assistants, partner integrations). Some you don't (training-data theft, automated account abuse). Agent-aware classification lets the same policy framework give a different answer to each.

Account takeover by AI agents

AI-driven account-takeover agents browse login pages, solve simple CAPTCHAs and abuse high-rate credential testing. Scraper-class behavior in the 11-factor scoring catches the pattern that single-IP rate limiting misses.

Post-incident forensic traceability for leaked screenshots

When a sensitive screenshot surfaces — on social, in a news story, on a security forum — forensic watermark identifies which session and which user produced it. The investigation starts with evidence, not guesswork.

Government and regulated portals with data residency

AI-era threats meet data residency requirements. TR7's AI-era layers run on your hardware — no third-party AI defense service in the path of citizen or regulated data.

5 features

Features that implement this solution

Capabilities referenced by this solution — the technical pieces that compose the controls described above.

Anti-OCR Protection

TR7 ZeroLeak
AI-Era ProtectionData Leakage PreventionHIPAA Compliance

Server-rendered pages with pixel-level modifications — readable on screen for the user, nonsense to OCR engines and AI vision models when extracted as an image.

Healthcare· Financial Services· Government· Education

Remote Browser Isolation

TR7 ZeroLeak
AI-Era ProtectionData Leakage Prevention

Run the protected app inside a fully isolated session on the platform — the user sees only the rendered pixels. No HTML, no JavaScript, no cookies on the endpoint.

Healthcare· Financial Services· Government

Text Cipher

TR7 ZeroLeak
AI-Era ProtectionData Leakage Prevention

Letters on the page are silently swapped with visually-similar siblings; the area around the cursor reveals the originals. The human reads naturally — an AI fed a screenshot reads different words.

Healthcare· Financial Services· Government

Forensic Watermark

TR7 ZeroLeak
AI-Era ProtectionData Leakage Prevention

A visible per-user watermark plus an invisible trace ID embedded into the pixels — when a screenshot leaks, the source can be identified even after cropping, scaling, or being photographed.

Healthcare· Financial Services· Government

Browser Context Isolation

TR7 ZeroLeak
AI-Era ProtectionData Leakage Prevention

Every user session runs in its own isolated browser context — no shared cookies, storage, or process state — with a strict domain allowlist and rendering-level anti-automation defences built in.

Financial Services· Government

Common questions

Is this a separate product, or part of TR7 WAAP?
Part of WAAP, with the ZeroLeak isolation add-on engaged where sensitive services warrant it. Classical WAAP detection still handles yesterday's attacks. The AI-era layers — anti-OCR rendering, agent-aware classification, scraper detection, forensic watermark — engage on top of the same WAAP profile. One platform, one operator view, one audit trail. No separate AI-defense product to license.
What is anti-OCR rendering, technically?
The rendered output is shaped so that automated OCR engines and vision language models struggle to reliably recover the underlying text. Text is delivered as visual elements that a human reads normally; automated pipelines that capture a screenshot and run OCR or VLM extraction find recovery unreliable. The mechanism is designed for the AI-era screen-grab attack model — for technical detail, see the Anti-OCR capability page in Features.
How do you tell a good AI agent from a hostile one?
Identity claims (known indexing crawlers, partner integrations), behavior (request rhythm, page-traversal pattern, page-content correlation), and policy. Some AI agents you publish a welcome to — they identify themselves and behave well. Others arrive trying to look like a human while harvesting at machine speed. The 11-factor scoring engine separates them; per-vService policy decides what each gets.
Will this block real users?
No. Anti-OCR rendering is invisible to human readers. Agent classification distinguishes AI traffic from human traffic. Scraper-class behavior detection looks at access patterns, not individual requests in isolation. The combination is tuned for low false positives — and every action is inspectable in the operator console, so any unexpected block can be traced and tuned.
How does forensic watermark survive a screenshot?
The watermark is woven into the rendered content in ways that survive image capture, printing, OCR re-extraction and AI-based rewriting. It can be visible (e.g., a session-tagged overlay) or steganographic (embedded patterns invisible to casual viewing). The trace ties any leaked artifact back to the originating session, user and timestamp.
What WAAP vendors offer a comparable combination?
None, today. Cloud-only RBI products offer browser isolation but not anti-OCR or WAAP integration. Bot management products treat AI traffic as a bot family but don't address the screen-grab path. Classical WAAP vendors don't have anti-OCR, agent-aware classification or watermarking as product features at all. The TR7 combination — anti-OCR + agent-aware + scraper detection + watermark + WAAP integration — is unique.
Does this run on-prem like the rest of TR7?
Yes. Anti-OCR rendering, agent classification, scoring and watermarking all run on your hardware. No third-party AI-defense service in the path of your data. Audit trails stay in your own network.

The WAAP, evolved for the AI era — only on TR7

Request a live demo of TR7's AI-era protection. We'll run a vision language model against a TR7-rendered page, walk through agent classification on real traffic and show watermark tracing on a screenshot that's already left the application.