Lock it
Filtering at the layer the attack is actually on.
A managed rule set in front of your public services, with rate limiting and the ability to run a rule in detect-only mode first — so you find out what it would have blocked before it blocks a customer.
WAF
- Managed rule sets
- Detect-only mode
- Per-path rate limiting
- Custom rules
How it helps
What you get with WAF
Detect before enforce
Run a rule in monitoring mode, look at what it matched, then turn it on. Nobody should learn a WAF rule was too broad from a support ticket.
Rate limiting
Per-path and per-IP limits for the endpoints that get abused — login, signup, password reset.
Managed and updated
Common rule sets kept current, with your own rules on top rather than instead.
Security & access
The rest of Security & access
Zero-trust access, VPN, an SSH bastion, a web application firewall and managed SSH keys.
VPN
Encrypted access to private networks, scoped per user.
Learn moreSSH Bastion
Brokered SSH with a session record you can hand an auditor.
Learn moreZero-trust access (ZTA)
Per-user, per-resource policy instead of a flat network perimeter.
Learn moreSSH Keys
Managed keys with an inventory of who holds what.
Learn moreInfrastructure you can point at.
Start in minutes on dedicated capacity, or talk to us about private capacity and named datacentres. Every tier is the whole platform.
Every service, every tier Predictable egress No charge to open a ticket