) Styles: /css/hero.css Behaviour: /js/hero-sim.js All preview content is a labelled simulation with fictional names. ====================================================================== -->

Cortex · Minecraft network operations

The Enterprise Operating System for Minecraft Networks.

Staff management, moderation, player intelligence, Discord ChatOps and telemetry in one command center. Run it as a managed workspace or self-host the whole stack on your own infrastructure.

Public Test Network: Try Cortex Web Portal & iOS App with credentials admin : admin
Open Test Portal →

HMAC-SHA256 ingest SHA-256 audit chain GDPR Art. 15/17

Tenant-isolated query sites
461
Pillars, one platform
6
Server plugins: Paper & Velocity
2
War Room · Simulated preview
War Room threat radar
  1. 18:42:07 Alt cluster · 3 accounts
  2. 18:41:52 VPN exit · AS9009
  3. 18:41:19 Report filed · Survival-1
  4. 18:40:44 Subnet hash match
Player Dossier fingerprint
Voxel_Wraith 7c1e…a94f
82risk
Alt links
3
ASN
AS9009
Last seen
Survival-1
Band
High
  • vpn exit
  • subnet match
  • hw id shared
Staff bridge /sc ↔ #staff-chat
  • [Survival-1] Nyx_Tallow moderator

    /sc Voxel_Wraith is back on the same subnet as the banned alts.

  • [Discord] Quill_Harrow admin

    Confirmed, the ASN is a VPN exit. Hold until the dossier finishes.

  • [Web] Perrin_Slate helper

    Report #4821 from Survival-1 attached to the dossier.

  • [Mobile] Ossian_Ryde owner

    Approved. Ban with an audit note — I'm on the phone.

Built on

  • Paper 1.20–1.21+
  • Velocity 3.3+
  • Discord.js Sentinel
  • MySQL 8
  • Redis
  • Stripe billing

Six pillars

Everything a network needs to run clean

Cortex is the tooling that runs a production Minecraft network, packaged for yours: identity that survives alts, ingest that survives outages, one staff conversation across game, Discord, web and mobile, and a record nobody can quietly rewrite.

Anti-Evasion Fingerprinting

A banned player who comes back on a fresh account, a VPN and a new username is still the same person. Cortex correlates the ASN, a hashed /24 subnet, hardware identifiers and an alt-correlation graph so evasion attempts surface as linked accounts instead of clean slates.

ASN · /24 hash · HWID · alt graph

Zero-Lag High-Throughput Ingest

Every game server signs its events with HMAC-SHA256 under its own hashed ctx_live_ key and streams them to the API off the main thread. An embedded H2 write-through buffer on each server holds the queue when the network drops, so nothing is lost offline and the tick rate never notices.

HMAC-SHA256 · ctx_live_ keys · H2 write-through

Two-Way Discord ChatOps Bridge

Staff talk in one place no matter where they are standing. In-game /sc, Discord #staff-chat, the web TeamChat panel and the mobile app are one conversation, relayed both ways in real time by the Cortex Sentinel bot.

/sc ↔ #staff-chat ↔ TeamChat ↔ mobile

Tamper-Evident Audit Ledger

Every staff action is written to a ledger where each entry carries the SHA-256 of the entry before it. Edit or delete anything in the middle and the chain breaks visibly. A moderator gone bad can be removed; what they did cannot be rewritten.

SHA-256 · prev → hash · verifiable

Native Staff Mobile App

"Cortex Staff" for iOS (via TestFlight) and Android puts the War Room in a pocket: live alerts, one-tap ban, mute and kick, and the same TeamChat thread. Face ID lock and TOTP 2FA guard the session, and it connects to the managed SaaS or to your own self-hosted URL.

iOS TestFlight · Android · Face ID · TOTP

GDPR Article 15 & 17, self-service

Players prove they own an account the only way that cannot be faked: by joining a Mojang-authenticated verification server at verify.cortex.prioxy.io. From there they receive a full export of everything held about them, or an erasure that completes with a signed certificate.

verify.cortex.prioxy.io · export · erasure certificate

How it works

Live in an afternoon, not a sprint

Three steps from an empty workspace to staff signing in on their phones. No database to run, no bot to write, no config to hand-author.

  1. Create your workspace

    Pick a network name and a slug, and Cortex provisions an isolated tenant at <slug>.cortex.prioxy.io with you as owner. Secure the owner account with TOTP before inviting anyone else.

    • Name, slug, owner account
    • 14-day trial, no card, while billing is disabled
  2. Drop in the plugins & invite Sentinel

    Download cortex-paper.jar (Paper 1.20–1.21+) and cortex-velocity.jar (Velocity 3.3+). The wizard hands you a config.yml already filled with a per-server key; in Discord, /cortex link <code> then /cortex setup builds the channels and webhooks.

    # plugins/CortexCore/config.yml
    api-url: "https://<slug>.cortex.prioxy.io"
    server-key: "ctx_live_9f3c…a71e"
    server-name: "lobby-1"
    • /cortex setup creates #staff-alerts, #appeals, #audit-log, #staff-chat
  3. Open the portal & mobile app

    Staff accept their invite at /portal, enrol TOTP and land in the live War Room. Install Cortex Staff on iOS or Android, point it at your workspace, and the same alerts and chat follow them off the desk.

    • Roles: helper, moderator, developer, admin, owner
    • Live War Room, TeamChat, one-tap actions

Security

Built fail-closed

Multi-tenant software is only as private as its weakest query. Cortex was designed so the safe path is the only path.

Tenant isolation is enforced at a single query chokepoint that every one of the 461 database call sites passes through. A request that arrives without a resolved tenant does not fall back to "all tenants"; it fails.

Each game server authenticates with its own ctx_live_ key, stored only as a hash and revocable on its own without touching the rest of the network. Staff sessions are JWTs backed by Redis-side revocation and rotated signing keys, so a sign-out or a role change takes effect immediately, not at token expiry. TOTP 2FA with recovery codes protects every staff account, and billing is owner-only.

  • Per-server revocable keys
  • SHA-256 chained audit ledger
  • Redis-backed session revocation
  • GDPR Art. 15/17 self-service
audit_ledger tenant: emerald-sky
chain verified
  1. #0412 mute mod.Aria → Blockington_42 14:02:11
    preva6d0…19b3 hash3f9a…c21d
  2. #0413 ban mod.Aria → CreeperDaisy 14:05:47
    prev3f9a…c21d hash8b07…e4f2
  3. #0414 note helper.Kai → Sir_Diggalot 14:09:02
    prev8b07…e4f2 hashd1c4…77a9
  4. #0415 unban admin.Noor → Pixel_Pete 14:12:38
    prevd1c4…77a9 hash5e2b…0c8f
4 entries · sha256 · verified against head 5e2b…0c8f
Simulated preview · fictional player names

Pricing

Priced per staff seat, not per player

Your player count is your success, not our invoice. Pay for the people who moderate, and scale the network underneath them as far as it goes.

Size your team

1 to 250 seats. Starter caps at 25 · Network Pro caps at 250 · Enterprise / BYO is unlimited. Helpers, moderators, developers, admins and owners each take one seat.

Billing

Lifetime applies to Enterprise / BYO only. Starter and Network Pro are always monthly.

Starter

One server or proxy, a small team, the full moderation toolkit.

$15/mo

Includes 3 seats · $3.00 per extra seat

  • 3 staff seats included, $3.00 per extra seat, 25 seats maximum
  • 1 proxy or server
  • 30-day log retention
  • Two-way Discord ChatOps bridge
  • Anti-evasion fingerprinting and alt correlation
  • Tamper-evident audit ledger
  • GDPR Article 15 & 17 self-service for players
Start free

14-day trial

Enterprise / BYO

The whole stack on your own metal, under your own name.

$49/mo

Unlimited seats · or $299 lifetime

  • Unlimited staff seats
  • Self-hosted Docker stack
  • Bring your own database
  • White-label Discord bot
  • Custom domain
  • Everything in Network Pro
Start free

14-day trial

5 seats on Starter = $9 + 2 × $3 = $15/mo

5 seats on Network Pro = $24/mo (10 seats included)

5 seats on Enterprise / BYO = $49/mo · unlimited seats

Every plan starts with a 14-day trial. While billing is not yet enabled on the platform, the onboarding wizard creates your trial workspace without a card; once billing is enabled, a card is added through Stripe. Prices in USD.

Distribution

Managed SaaS or your own metal

Same plugins, same staff app, same audit chain. Choose who runs the box. Start on SaaS and move to a self-hosted stack later with a full workspace export.

Comparison of the managed SaaS and self-hosted (BYO) distributions of Cortex
  Managed SaaS <slug>.cortex.prioxy.io Self-hosted (BYO) docker compose
Hosting Operated by Prioxy. Your workspace is provisioned in minutes at your own subdomain. Your servers, your region. One Docker Compose stack, one .env file.
Database Managed for you. Tenant isolation is enforced at the single query chokepoint and fails closed. Bring your own MySQL 8.4+ or MariaDB 11.4+. Cortex never needs your game servers' database.
Updates Rolled out continuously. Nothing to patch. Pull new images on your own schedule. You decide when to move.
Discord bot The shared Cortex Sentinel bot: /cortex link, /cortex setup, /sc. White-label. Run Sentinel under your own bot application, name and avatar.
Custom domain Your <slug>.cortex.prioxy.io workspace. Any domain you own, with your own TLS.
Data residency Prioxy-operated infrastructure. GDPR Article 15 exports and Article 17 erasure built in. Wherever you run it. Data never leaves your network unless you send it.
Mobile app Cortex Staff for iOS and Android signs in to your workspace (Network Pro and up). The same app. Staff enter your self-hosted URL on first launch.
Price Starter from $9/mo, Network Pro from $24/mo, billed per staff seat. $49/mo or $299 lifetime, unlimited seats.
$ cp .env.example .env        # database, JWT secret, Discord bot, domain
$ docker compose up -d
$ docker compose logs -f cortex-api

One .env file, then you are live

Everything the stack needs lives in a single .env file: database URL, JWT secret, Discord bot token and your domain. Point api-url in each plugin at your API and every game server starts signing its ingest with its own ctx_live_ key.

Running it yourself does not mean running it blind: the same fail-closed tenant isolation, JWT revocation and hash-chained audit ledger ship in the image.

Docker Compose MySQL 8.4+ / MariaDB 11.4+ Redis

FAQ

Questions network owners ask first

Straight answers. If yours is not here, [email protected] reaches the people who built it.

Do you need my database credentials?

No. Cortex never touches your game servers' database. Each Paper or Velocity plugin holds exactly one per-server key (ctx_live_…), stored hashed on our side, and signs every request to the API with HMAC-SHA256. Revoke one server's key and only that server goes dark. Self-hosting? Then the database is yours anyway, and you hand its URL to your own stack through the .env file.

What happens if the API is unreachable?

Nothing is lost. Every game server runs an embedded H2 write-through buffer: punishments, chat, joins and fingerprints are written locally first and shipped to the API asynchronously. If the connection drops, the buffer keeps filling and replays in order as soon as the API answers again. Your staff keep moderating; the ledger catches up.

Can I move from SaaS to self-hosted later?

Yes. Request a full workspace export, stand up the Docker stack on your own hardware, import, and change api-url in each plugin's config.yml. Plugins, roles, audit history and the staff app all carry over. The same path works in reverse if you would rather stop running servers.

How does the trial work?

Every plan starts with 14 days. The onboarding wizard adapts to the platform: while billing is not yet enabled, it creates your trial workspace with no card at all. Once billing is enabled, you add a card through Stripe during onboarding and the 14-day trial still applies. Either way your workspace lives at <slug>.cortex.prioxy.io/portal from the first minute.

Which Minecraft versions are supported?

cortex-paper.jar runs on Paper 1.20 through 1.21 and newer; cortex-velocity.jar runs on Velocity 3.3+. Configuration is three keys: api-url, server-key and server-name. Running a different proxy or a heavily modified fork? Ask us before you buy.

How is my staff's access secured?

Five roles (helper, moderator, developer, admin, owner) with owner-only billing. TOTP two-factor authentication with recovery codes. JWT sessions backed by Redis-side revocation and key rotation, so a stolen token can be killed instantly. Per-server credentials revocable one at a time. The mobile app adds a Face ID lock. And every staff action lands in the audit ledger SHA-256 chained to the entry before it, so a rogue moderator cannot rewrite what they did.

How do you handle GDPR requests from players?

Self-service, with real proof of ownership. A player joins verify.cortex.prioxy.io, a Mojang-authenticated verification server, which proves they control the account. They then receive either a full Article 15 data export or an Article 17 erasure, closed with a signed certificate. Your staff never have to judge a request by a Discord DM.

Can I white-label the Discord bot?

On Enterprise / BYO, yes: run Sentinel under your own Discord application with your name and avatar. Starter and Network Pro use the shared Cortex Sentinel bot. Either way, /cortex setup creates the Cortex category with #staff-alerts, #appeals, #audit-log and #staff-chat, idempotently, and needs only Manage Channels, Manage Webhooks, View Channels and Send Messages.

Ready when you are

Give your staff a command center

Fourteen days, your own workspace, plugins that drop into the servers you already run.