Web Firewall (L7)

Web Firewall (L7)

Managed edge proxy for your sites — TLS, WAF, and DDoS protection in front of everything.

How it works

01

Point your domain

Attach a domain, we terminate TLS on our edge and proxy to your origin over a private path.

02

Filter at the edge

WAF rules, rate limits, and flood absorption happen before your origin sees a packet.

03

Watch everything

Per-site analytics: requests, blocks, challenges, countries, backends — live.

Features

Edge termination

Managed TLS (self-signed, pasted, or origin-CA), HTTP/2, WebSockets.

L7 protection

WAF rules, rate limits, bot filtering and challenge modes per site.

Backend pools

Multiple origins with balancing and health-aware failover.

Geo analytics

Per-country request maps and per-backend breakdowns, live in the console.

Silent features

The parts nobody advertises but everybody relies on.

Origin lockdown snippets

Generated nginx/Apache/Caddy rules so only our edge can reach your origin.

One-click node transfer

Move a site between edge nodes with certs and DNS handled for you.

Certs encrypted at rest

Private keys are AES-GCM in our database, decrypted only at issue time.

Ready when you are.