Layer 7 · WAF & CDN

One proxy in front of everything.

Firewall and cache in the same hop.

Your traffic passes through a reverse proxy we wrote ourselves. It inspects every request against managed rulesets and your own rules, serves what can be cached from the edge, and forwards only what actually needs your origin — in a single hop, with no extra latency for the privilege.

Scroll for more
In-houseEngine
Managed + customRulesets
1.3, automaticTLS
Tiered edgeCache

What you get

Everything in one proxy

Firewall, cache, DNS and TLS handled in the same hop your traffic already takes.

Managed rulesets

SQL injection, cross-site scripting and the rest of the OWASP Top 10, maintained by us and updated without you deploying anything.

Custom rules

Match on path, method, header, query, country, ASN, fingerprint or rate — then allow, challenge, rate limit or block. Built in the panel, live immediately.

Edge cache

Static assets served close to your users, with tiered caching so repeat misses collapse into one origin request instead of a stampede.

Image optimization

Images converted and resized on the fly at the edge, so you ship one original and every device gets an appropriate version.

TLS everywhere

Free certificates that renew themselves, TLS 1.3, HSTS and encrypted connections all the way to your origin by default.

DNS included

Authoritative DNS with instant propagation. Manage records in the panel or by API, and proxy any record with one toggle.

Rules you can actually reason about.

A rule is only useful if you can tell what it will do before you save it. Every event in the live log carries the reason it was scored, and any event can be turned into a rule in one click — so you build from what actually happened on your site rather than from guesswork.

  • 01Every event shows why it scored
  • 02Turn any event into a rule in one click
  • 03Test a rule in observe mode before enforcing
  • 04Per-domain rules, analytics and retention

Built so automation keeps working.

APIs, webhooks and integrations are traffic your business depends on, and a firewall that breaks them is worse than no firewall. There are no default per-IP rate limits: you set the limits that suit your application, and machine traffic is never challenged just for being machine traffic.

  • 01No default rate limits imposed on your traffic
  • 02API routes excluded from browser-style checks
  • 03Verified crawlers pass without a challenge
  • 04Cache rules per path, not one global setting

Questions

Before you ask

Put it in front of your site today.

Free plan, no credit card, no code changes.