Managed Web Application Firewall

A WAF that nobody tunes is either a rubber stamp or an outage generator. Deflecto’s WAF is managed: our analysts maintain the signature set, review false positives weekly and ship rule updates continuously — usually within hours of a new CVE being published.

Coverage

  • OWASP Top 10 and the OWASP Core Rule Set, tuned per application profile (WordPress, Magento, Laravel, Django, Spring, custom APIs)
  • Virtual patching for disclosed CVEs in popular frameworks and CMS plugins
  • JSON and GraphQL body inspection with schema-aware limits
  • File-upload scanning and content-type enforcement
  • Positive security models for APIs from your OpenAPI specification

Modes

Start every new rule in log mode, promote to challenge, and only then to block. You can see exactly what a rule would have done against the last seven days of your traffic before you enable it.

Scroll to Top