---
title: "What MYO already sees in non-human traffic"
description: "Before we talk about native detection, this is what MYO already ingests: non-sampled edge logs, WAF, bot, challenges, non-human activity. Seeing is not deciding. That gap is the rest of the season."
canonical_url: https://optimi.com/en/news/what-myo-already-sees-in-non-human-traffic
md_url: https://optimi.com/en/news/what-myo-already-sees-in-non-human-traffic.md
last_updated: 2026-09-22
---

# What MYO already sees in non-human traffic

Seeing is not deciding. We already sit on the logs. We do not yet detect as a native product — that is being built.

You have been promised “a single pane” before. Often it was a sampled export, three vendor consoles, and an analyst gluing CSVs. MYO is not that promise. It is smaller, and truer: non-sampled edge logs, pushed from the platform account, readable in near real time. WAF, bot, challenge, DDoS, firewall. Non-human activity is already in there. What MYO is not yet: a detection engine we own.

That honesty is what buys the right to talk about native detection later. Not before.

## A composite day

No customer names. A day that looks like the ones we read.

Morning: a challenge spike on checkout. The WAF is noisy. The vendor bot score moves. Conversion and 403s rise together. Nobody on the business side shares a timestamp.

Noon: a verified crawler enters through a US PoP. This is not an attack. It is Googlebot — or a peer — taking the route the network gives it. Without the log, SEO sees crawl “from the US” and security sees automation. With the log, you see *which*, *where*, *which rule touched it*.

Afternoon: a burst on `/login`. 401s that look like users. Stuffing, or an app campaign retrying. The User-Agent is clean.

Evening: a polite sweep across stock. GET, 200, no malicious payload. The WAF has nothing to say: it answers “is this request an exploit?” The scrape is not an exploit. It is a client nobody decided to allow.

Four scenes. One edge. Without non-sampled logs, they are four tickets. With MYO, they are a timeline.

## What the pane already shows

MYO ingests logs from the CDN account — Logpush on Cloudflare, the equivalent at the other vendors we orchestrate. Custom fields, real depth, not a marketing sample.

It shows:

- WAF, bot, challenge, CAPTCHA, DDoS events;
- bot / non-human activity reports;
- which PoP serves a search crawler — enough to advise a warmer, not enough to print as a public statistic;
- site performance and availability, next to security, not in another tool.

That is why we can already *see* the hostile / useful / internal split. Not because we invented a model. Because we sit on the traffic.

> **Informational, not SLA proof**
>
> MYO data is informational. It is not a contractual measurement of the CDN. It cannot prove an SLA breach. It is there to operate, not to litigate.

## What it does not decide

Seeing a challenge is not writing the policy. Seeing a US crawler is not an allowlist. Seeing a login burst is not absorbing a fraud specialist.

Enforcement still lives on the orchestrated edge — Cloudflare, Fastly, Akamai, depending on the account. MYO reads the feed. It does not yet issue allow / challenge / block as a product we own. Teams who live in three vendor consoles know this: a pane without a policy owner is a prettier export.

It is the same gap as [the layer nobody owns](/en/news/humans-bots-agents-who-owns-this-layer), seen from the logs instead of the tickets.

## The gap we are building toward

We are building native detection into MYO. Future tense. No GA date to invent. Not “DataDome is dead.” For mainstream bot management, the intent is to absorb. For high-stakes fraud, the specialist stays a complement until we can hold that depth for ten years.

Until then, the useful move is not waiting for the engine. It is reading *your* logs during a POV: what is already visible, what has no owner, what the policy should say before the native product exists.

See, now. Decide, with someone. Detect ourselves, next.

[Request a read](/en/contact): A read on your logs, during POV — MYO on your non-human traffic — challenges, crawlers, login, stock. Informational, precise, with no native-detection promise before it exists.
