LuauVanguard LuauVanguard
Sign in Start free
Enterprise protection for Luau

Enterprise Luau protection

A controlled build pipeline for teams that own their Luau. Virtualization when the compiler allows it, encrypted pools when it does not — designed for operators, not demos.

VM-firstBytecode path when eligible
Pool cipherShort encrypted fragments
StudioBuild in the browser
Engineered for executors · Session auth · Role-based limits · Discord onboarding

Capabilities that stay out of the way

Clear controls, predictable output, and a protection stack you can explain to a teammate in one minute.

Virtualization

Eligible scripts compile to an internal instruction stream and run through an interpreter — source is not left as plain text when the path succeeds.

Control structure hardening

Branches and loops are reshaped so static reading no longer mirrors the original control graph.

Integrity & environment checks

Runtime probes and integrity seals designed for real executor sessions, not frozen sandboxes.

Encrypted constant pools

Payloads leave as short cipher fragments in structured tables — not one giant dumpable string.

Pricing

Request access. Scale when your pipeline needs unlimited builds.

Starter

$0
  • 2 protected builds
  • Full Studio access
  • Standard protection stack
Create account

Documentation

Full operator manual for LuauVanguard — accounts, Studio, protection pipeline, API, and operations.

1. Overview

LuauVanguard is a hosted protection pipeline for Luau source used in Roblox executor environments. You submit readable source; the service returns a protected artifact with a comment banner, optional anti-tamper material, and a virtualized or encrypted runtime body.

The product focuses on three outcomes: hide structure from casual reading, raise the cost of automated dumpers, and keep builds operable in real executors. It is not a claim of absolute secrecy and not a tool for bypassing platform rules.

Primary surfaces: public marketing site, authenticated Studio, HTTP API, and a restricted admin console.

2. Audience

Intended users are developers and small teams who already own the scripts they protect. Operators should understand Luau basics, how their executor loads scripts, and the difference between Studio (editor environment) and live executor sessions.

Not intended for: stealing third-party code, mass malware distribution, or claiming “undetectable” status to customers.

3. Threat model

Assume the protected file can be saved, shared, and analyzed offline. Common attacker tooling includes string dumpers, simple pattern matchers looking for loadstring, long Base64 blobs, and public “deobfuscator” scripts.

LuauVanguard reduces those signatures by using short cipher fragments, pool tables, reconstructed loader names, integrity seals, and a bytecode path when compilation succeeds.

A skilled reverse engineer with a live hook on the loader can still recover behavior. Protection is about friction and time, not mathematical impossibility.

4. Architecture

Frontend: single-page shell (index.html) with client routing for landing, docs, pricing, auth, overview, Studio, and admin.

Backend: Express-style API on Vercel Node. Auth via HTTP-only cookie + JWT. Users stored in MongoDB when MONGODB_URI is present; otherwise a file store for demos (ephemeral on serverless).

Engine modules: validation/lex, anti-tamper prefix, pool-style emitter, optional IR bytecode VM, encrypted envelope fallback, comment banner.

5. Accounts

Register with username, email, and password (minimum 8 characters). Login accepts email or username. Sessions last seven days unless logged out.

Default role is Starter/Skidder with two successful builds. Elite removes the cap. The reserved operator username qyrex can open /admin.

Banned accounts cannot build. Password hashes use bcrypt. JWT secret must be set in production via JWT_SECRET.

6. Studio workflow

1. Sign in and open Studio from the sidebar.
2. Paste Luau or load a .lua / .txt file.
3. Leave protections enabled unless you have a deliberate reason to disable one.
4. Click Build protected script.
5. Copy or download the artifact.
6. Run it inside an executor that provides a loader when the envelope path is used.

After every platform deploy, generate a fresh artifact. Mixing old clients with new crypto layouts causes integrity failures.

7. Build options

Anti-Tamper — integrity material and soft environment probes prefixed to the payload.

Strings — string material is not left as obvious plaintext in the protected path.

Control-flow — reshapes branch structure where the pipeline applies it.

Virtualize — prefer VM / pool emission over plain source.

Maximum — enable the full practical stack.

Polymorphic — vary noise and layout across builds.

Minify — compress token spacing on paths that still expose token streams.

8. Plans & limits

Starter — free, two successful builds, full Studio, standard stack.

Vanguard Elite — unlimited builds, Discord sales/onboarding.

Source size is capped (on the order of hundreds of KB). Oversized bodies return HTTP 413. Rate limits apply to auth and build endpoints to reduce abuse.

9. Output format

Artifacts start with a multi-line comment banner (ASCII mark + product line). Comments are ignored by Lua and never execute. The runtime body follows as a functional program, typically return(function(...) ... end)(...).

Pool-style builds include a table of short tagged strings. Decoy entries may appear; only masked indices are decoded. Do not hand-edit the file.

10. Banner & comments

The banner is decorative and informational only. It identifies LuauVanguard builds and version. Removing or altering it does not improve security; altering the body below it can break integrity.

11. Runtime requirements

Executors must provide standard Luau/Lua libraries used by the payload (string, table, math, pcall). Envelope paths need a loader (load / reconstructed loadstring). Pure bytecode paths avoid a source loader when compilation succeeds.

Roblox Studio alone often blocks loaders; test in the same class of environment you ship to.

12. Virtualization

A subset of Luau (assignments, calls, simple control flow) can compile to an internal opcode stream plus interpreter. Complex metatable-heavy scripts may fall back automatically to the pool envelope.

13. Cipher pools

Multi-layer XOR, short alphabet-tagged chunks, index masking, checksum, table wipe after decode. Designed to frustrate dumpers that only inspect huge strings or a single obvious loader token.

14. Integrity

Decoded bytes are bound to a checksum of the original source. Soft probes validate native function presence and known sandbox identifiers. Failures should fail closed without freezing the host.

15. Build pipeline

Validate → optional anti-tamper prefix → pool-style emitter (preferred for maximum) → IR bytecode VM if pool unavailable → encrypted envelope fallback → comment banner + body → optional minify on non-virtual paths → response JSON with diagnostics.

16. HTTP API

Build (authenticated):

POST /api/obfuscate
Content-Type: application/json

{
  "source": "print(1)",
  "name": "my-script",
  "maximumSecurity": true,
  "antiTamper": true,
  "virtualize": true,
  "encryptStrings": true,
  "minify": true
}

Auth: POST /api/auth with action = login | register | logout.

Session: GET /api/me. Validate only: POST /api/validate. Health: GET /api/health (reports db: mongo|file).

17. Admin

Username qyrex only. Route /admin. List users, set roles (Skidder / Qyrex Elite / Admin), ban/unban, view aggregate stats. Default admin password is environment-overridable (ADMIN_PASSWORD, ADMIN_EMAIL).

18. Deploy & environment

Required: JWT_SECRET. Recommended: MONGODB_URI, Atlas network allowlist 0.0.0.0/0 for serverless. Optional: MONGODB_DB, MONGODB_COLLECTION, ADMIN_EMAIL, ADMIN_PASSWORD.

Without Mongo, user data may reset between serverless instances. Always use Mongo for production accounts.

19. Site security

HTTP-only cookies, SameSite lax, secure flag in production, nosniff, frame deny, referrer policy, HSTS when NODE_ENV is production. Rate limits on sensitive routes. Still: keep secrets in env vars, rotate JWT secret if leaked, and restrict admin credentials.

20. Troubleshooting

Login network error — open /api/health; hard-refresh after deploy; confirm API routes are live.

loader unavailable — executor must expose a loader for envelope builds.

integrity / rebuild failed — re-build with current deploy; do not edit the artifact.

Studio → home — session expired; sign in again.

db:file on health — Mongo URI missing or Atlas blocking Vercel IPs.

Free limit reached — upgrade via Discord sales or wait on a new policy from admin.

21. FAQ

Is it undetectable? No. It increases analysis cost.

Can I protect others’ scripts? Only with authorization.

Does Studio execution equal executor execution? Not always — loaders differ.

Why short strings? Many dumpers only inspect very long literals.

Can I remove the banner? Yes, but it does not improve security and may complicate support.

22. Changelog notes

v1.0.0 — pool-style emitter, IR VM path, Mongo optional auth, Studio shell, comment banner, role limits, admin console.

Always read this page after a major deploy; diagnostics fields and option names can evolve.

Terms

Use LuauVanguard only on code you own or are authorized to protect. Follow Roblox rules and applicable law.

Welcome back

Sign in to open Studio, review build usage, and continue your protection workflow.

  • Encrypted session cookie
  • Plan limits enforced server-side
  • Admin tools for operators

Sign in

Use your LuauVanguard credentials.

No account? Create one

Create your workspace

Free tier includes two protected builds. Upgrade when your team needs continuous output.

  • No credit card for starter
  • Same engine as paid tier
  • Browser Studio included

Create account

Less than a minute to get started.

Already registered? Sign in

Overview

Account status and recent usage.

Plan
Skidder
2 builds
Used
0
this account
All time
0
engine
Open Studio

Studio

Paste Luau, keep protections on, build a protected artifact.

Input0
Output0

Admin

Operator console

Building…