Skip to main content
Use AvraAPI::security() for the two released Security operations. Both return ApiResponse. A false signal means the configured provider did not classify the value for that signal; it is not a standalone allow or block decision.
Every Security operation supports the shared one-request privacy control: AvraAPI::security()->withPrivacyMode()->checkVpn('IP_ADDRESS'). It sends X-Privacy-Mode: 1 only for the next request, then clears automatically. Privacy Mode keeps normal routing, billing, and usage tracking while suppressing request and response payload storage.

Check VPN, proxy, and IP risk

checkVpn(string $ip): ApiResponse evaluates one permitted IPv4 or IPv6 address for VPN, proxy, Tor, relay, and hosting signals. SDK function
Copy the SDK call
Read IP-risk signals in Laravel

Response

Some network fields can be null. Combine the signals with your own risk policy and only submit IP addresses you are permitted to process. See Check VPN, proxy, and IP risk.

Check a disposable email address

checkBurnerEmail(string $email): ApiResponse evaluates one email address for syntax and configured disposable-domain signals. SDK function
Copy the SDK call
Use a disposable-email signal in Laravel

Response

is_disposable: false means the configured lists did not contain a matching domain. It does not verify ownership, inbox reachability, or user trust. Process only email addresses you are permitted to use. See Check a disposable email address.

Handle Security errors

Security methods throw typed SDK exceptions for API failures. Keep $exception->getRequestId() with the support record, do not expose provider diagnostics to a browser, and use the shared Laravel pattern in Laravel Overview and setup.
Last modified on October 1, 2026