$avraapi->security() for the two released Security operations. Both
methods return an ApiResponse. A false signal means the configured provider
did not classify the value for that signal; it is not a standalone allow or
block decision.
Every Security operation can use the shared one-request privacy control:
$avraapi->security()->withPrivacyMode()->checkVpn('IP_ADDRESS'). It sends
X-Privacy-Mode: 1 only for that next request, then clears automatically.
Privacy Mode keeps normal routing, billing, and usage tracking while
suppressing request and response payload storage.Check VPN, proxy, and IP risk
checkVpn(string $ip): ApiResponse evaluates one permitted IPv4 or IPv6
address for VPN, proxy, Tor, relay, and hosting signals.
SDK function
Copy the SDK call
Read IP-risk signals
Response
null. Combine the returned signals with your own
risk policy and only submit IP addresses that you are permitted to process.
For field and error details, read Check VPN, proxy, and IP risk.
Check a disposable email address
checkBurnerEmail(string $email): ApiResponse evaluates one email address for
syntax and configured disposable-domain signals.
SDK function
Copy the SDK call
Use a disposable-email signal
Response
is_disposable: false means the configured lists did not contain a matching
domain. It does not verify ownership, inbox reachability, or user trust.
Process only email addresses you are permitted to use. For the complete
contract, see Check a disposable email address.
Handle Security errors
Security methods throw typed SDK exceptions for API failures. Keep$exception->getRequestId() with your support record, avoid exposing provider
diagnostics to a browser, and follow the common handling pattern in
PHP Overview and setup.