Licensing security
Why we're building Aegis, a new licensing security tool
Layered defenses turn suspicious authentication activity into a clear, actionable signal.
By System Locker 4 min read
No single control can carry the whole job. A check in the client can be bypassed; a server-side rule can be misconfigured; an otherwise legitimate key can be copied. That's why cybersecurity experts talk about "defense in depth," a strategy that accepts that individual controls can fail and makes sure another layer can still limit the damage.
For software licensing, that can mean combining reliable authentication, hardware-based rules where they fit your product, audit logs, and a way to review or respond to suspicious activity. The goal is not to promise an unbreakable client. It is to make abuse harder, more visible, and easier to address.
Look for behavior, not one-off events
A single failed login or hardware change is not necessarily a problem. Patterns are more useful: a small number of keys appearing across an unusual number of machines, a reseller account used from conflicting locations, or repeated authentication from known VPN infrastructure.
That is the reactive side of licensing security. Preventative controls lack the broader context necessary to see patterns; reactive controls give you a chance to investigate when those controls encounter behavior that does not fit the normal use of your product.
With our Aegis tool, we're empowering developers with all of the necessary context to investigate suspicious activity.
Put automatic responses under your control
But that's not all. Aegis is designed to do more than point at a suspicious event. Developers can enable VPN detection, choose a lower or higher sensitivity, and decide what should happen when activity matches the configured policy. That makes the feature useful for different products and different risk tolerances instead of forcing every developer into the same response.
The automatic action can be graduated: freeze a key, ban it, block the request, or block the associated hardware ID. A higher sensitivity can identify more VPN-like activity, but may add latency, so it is a setting to choose deliberately rather than a switch that is always better turned all the way up.
These controls also keep the decision understandable. You can start with detection and a restrained response, watch how it fits your customers' normal behavior, and increase enforcement only when the evidence supports it.
Respond with context
Aegis analyzes user and reseller activity for patterns associated with key sharing, reseller account sharing, and VPN use. Between automatic responses and detailed logs, no other tool provides the same level of insight as System Locker's Aegis.
For example, a developer may notice a cluster of authentications tied to only a few leaked keys. That can point to hardware ID spoofing or key sharing, giving the developer a reason to investigate, revoke access if appropriate, and ship an update through Invisible Folder.
Make your licensing system part of the response
Good licensing security gives you more than a pass-or-fail answer. It helps you understand what happened, decide without guessing, and protect legitimate customers along the way. Start with the controls that fit your application, keep an eye on the logs, and treat unusual patterns as a prompt to investigate.
Ready to see how layered security can help your product?
Create a developer account to explore System Locker, or talk through your setup with us on Discord.