Security engineering

Secure and reliable by default

Defendy processes production events with explicit contracts, idempotency, backpressure and observability.

Event-driven contracts

Versioned NATS JetStream events and explicit ConsumerConfig.

Idempotency

Nats-Msg-Id, Redis dedupe and unique constraints prevent duplicate processing.

Backpressure

Pending limits, timeouts and retries only for transient failures.

Least trust

Secrets stay outside Git; Telegram initData and administrator rights are validated.

Observability

Structured logs, correlation IDs, health checks and runbooks.

Safe rollout

Feature flags, shadow mode, canaries and fast rollback.

Event path

From Telegram to a clear admin message

01Telegram eventmember join or message
02Policy checkthe group's enabled rules
03Actiondelete, warn or restrict
04Log chatreason and applied policy

Permissions in the default add link

Delete messagescore filters
Restrict memberscaptcha and penalties
Ban usersviolation escalation
Pin messagesmanagement workflows
Some workflows, including topics and invite-link management, require additional permissions.