Skip to main content
Use $avraapi->security() for the two released Security operations. Both methods return an ApiResponse. A false signal means the configured provider did not classify the value for that signal; it is not a standalone allow or block decision.
Every Security operation can use the shared one-request privacy control: $avraapi->security()->withPrivacyMode()->checkVpn('IP_ADDRESS'). It sends X-Privacy-Mode: 1 only for that next request, then clears automatically. Privacy Mode keeps normal routing, billing, and usage tracking while suppressing request and response payload storage.

Check VPN, proxy, and IP risk

checkVpn(string $ip): ApiResponse evaluates one permitted IPv4 or IPv6 address for VPN, proxy, Tor, relay, and hosting signals. SDK function
Copy the SDK call
Read IP-risk signals

Response

Some network fields can be null. Combine the returned signals with your own risk policy and only submit IP addresses that you are permitted to process. For field and error details, read Check VPN, proxy, and IP risk.

Check a disposable email address

checkBurnerEmail(string $email): ApiResponse evaluates one email address for syntax and configured disposable-domain signals. SDK function
Copy the SDK call
Use a disposable-email signal

Response

is_disposable: false means the configured lists did not contain a matching domain. It does not verify ownership, inbox reachability, or user trust. Process only email addresses you are permitted to use. For the complete contract, see Check a disposable email address.

Handle Security errors

Security methods throw typed SDK exceptions for API failures. Keep $exception->getRequestId() with your support record, avoid exposing provider diagnostics to a browser, and follow the common handling pattern in PHP Overview and setup.
Last modified on October 1, 2026