Web Firewall (L7)
Web Firewall (L7)
Managed edge proxy for your sites — TLS, WAF, and DDoS protection in front of everything.
How it works
01
Point your domain
Attach a domain, we terminate TLS on our edge and proxy to your origin over a private path.
02
Filter at the edge
WAF rules, rate limits, and flood absorption happen before your origin sees a packet.
03
Watch everything
Per-site analytics: requests, blocks, challenges, countries, backends — live.
Features
Edge termination
Managed TLS (self-signed, pasted, or origin-CA), HTTP/2, WebSockets.
L7 protection
WAF rules, rate limits, bot filtering and challenge modes per site.
Backend pools
Multiple origins with balancing and health-aware failover.
Geo analytics
Per-country request maps and per-backend breakdowns, live in the console.
Silent features
The parts nobody advertises but everybody relies on.
Origin lockdown snippets
Generated nginx/Apache/Caddy rules so only our edge can reach your origin.
One-click node transfer
Move a site between edge nodes with certs and DNS handled for you.
Certs encrypted at rest
Private keys are AES-GCM in our database, decrypted only at issue time.