Enterprise Security — Included Free

Crypto audit logs, SAML 2.0, SCIM 2.0, and FLAC — all included at no cost. Competitors charge thousands per year.

SAML 2.0 SSO — Free SCIM 2.0 — Free Crypto Audit Logs — Free AI Bot Defense — Free Fail-Closed API — Free

What's Included (Free)

SHA-256 Chained Audit Logs

Every mutation is cryptographically chained. Tamper-evident, SOC 2 and GDPR compliant. Hashing is offloaded to Worker Threads — no main event loop impact.

Field-Level Access Control (FLAC)

Physically strips unauthorised fields from API responses at the database adapter level. Not just hidden in the UI — genuinely absent from the response.

SAML 2.0 Enterprise SSO

Connect Okta, Azure AD, and Google Workspace via BoxyHQ Jackson Hub. JIT provisioning included. No enterprise tier required.

SCIM 2.0 Provisioning

RFC 7644 compliant automated user lifecycle management. Create, update, and deactivate users from your IdP automatically.

Fail-Closed API Dispatcher

All 40+ API endpoints must be explicitly registered. Unmapped routes are denied by default — zero Shadow API vulnerabilities.

Self-Healing Load Shedding

At 90% heap pressure, mutation traffic is automatically rejected with a compressed 503 — read availability is always protected.

What Competitors Charge Extra For

Strapi and Payload require enterprise plans ($10k+/year) for features SveltyCMS includes free.

FeatureSveltyCMSStrapiPayloadDirectus
Crypto Audit Logs✅ FreeEnterprise PlanEnterprise PlanEnterprise Plan
SAML 2.0 SSO✅ FreeEnterprise PlanEnterprise PlanEnterprise Plan
SCIM 2.0 Provisioning✅ FreeEnterprise Plan❌ None❌ None
Field-Level Access Control✅ FreeEnterprise PlanPartialEnterprise Plan

Why This Matters: The CVE Record

In 2026, Directus published multiple critical CVEs (user enumeration, GraphQL DoS). Payload had XSS and SSRF vulnerabilities. SveltyCMS has a fail-closed architecture that prevents entire classes of vulnerabilities.

Directus 2026 CVEs

User enumeration, GraphQL DoS attacks. Relicensed from BUSL-1.1 to MSCL-1.0-GPL in June 2026.

Payload 2026

Published XSS and SSRF vulnerabilities according to the NVD and GitHub Advisory Database.

SveltyCMS: Fail-Closed Architecture

Entire classes of vulnerabilities are prevented by design — not patched reactively.

Active Threat Defense (May 2026)

SveltyCMS deploys a multi-layered defense grid that actively detects, blocks, and poisons malicious traffic — not just filters it.

AI Bot Fingerprinting

Proactive detection of 28+ AI crawler patterns (GPTBot, Claude, Perplexity, CommonCrawl, Bytespider) and recon tools (Nmap, SQLMap, Burp Suite).

Honeypot Grid

45+ decoy routes mimicking WordPress, Drupal, Joomla, and AWS metadata endpoints. Any probe triggers immediate IP blacklisting.

Progressive Tarpit

Randomized 5–15 second response delays waste bot resources. Fake JSON payloads poison scraper datasets instead of revealing real system info.

Cross-Origin Isolation

All API responses enforce COOP, COEP, and CORP headers — preventing Spectre/Meltdown class side-channel attacks.

Zero-Bias CSPRNG

Token generation uses rejection sampling to eliminate ~3.125% modulo bias, guaranteeing uniform CSPRNG distribution for session tokens and API keys.

TOTP Timing Attack Safe

2FA code verification uses `crypto.timingSafeEqual`, mathematically neutralizing nanosecond-level side-channel attacks.

Read Documentation Full Comparison