diff --git a/docs/kratos/concepts/security.mdx b/docs/kratos/concepts/security.mdx index 6c3f01645..8d982f4cf 100644 --- a/docs/kratos/concepts/security.mdx +++ b/docs/kratos/concepts/security.mdx @@ -29,7 +29,7 @@ To detect bots and throttle suspicious IPs, Ory Network leverages the [Cloudflare Web Application Firewall (WAF)](https://www.cloudflare.com/en-gb/application-services/products/waf/) and [Cloudflare Bot Management](https://www.cloudflare.com/en-gb/application-services/products/bot-management/) services. These features are built into Ory Network and allow Ory to defend against automated threats without burdening users with unfriendly -CAPTCHAs. +CAPTCHAs, IP throttling, rate limiting, and IP blocking. When using Ory Network, these automated attack defenses are provided as part of the platform's security infrastructure. For self-hosted instances of Ory Kratos Identity Server, it's the responsibility of the administrator to implement and manage