Managed WAF · Nothing to install

Block malicious traffic before it reaches your app.

Point your domain at SelfSec and every request is inspected inline before it reaches your origin — managed rules, signed virtual patches and bot mitigation, with every block naming the rule that made it, no software on your servers and no change to your application.

  • Pre-release
  • Nothing to install
  • Runs in front of any stack

Synthetic live WAF preview showing requests inspected and blocked in front of an origin.

12Attack categories inspected inline
0Third-party code in the detection engine
DetectionThe mode you start in
2 recordsProve the name, then point it
SelfSec WAF outcomes

What changes when SelfSec WAF is in the loop

Start with the result your team needs, then inspect the technical depth behind it.

Enforce in front, not inside

Every request is evaluated against 12 attack categories before it is forwarded, stopping injection, protocol abuse, bots and abusive rates while they are still in front of your application.

Patch exposure the same day

Shield a known-vulnerable route with a virtual patch while the application team ships the permanent fix. Rule bundles are signed and verified against a pinned key before they reach your traffic.

Explain every decision

A block names the rule that made it and leaves an evidence trail you can inspect — not a vendor decision you have to defend to a customer without knowing what it was.

How it works

Four steps, one continuous workflow

A clear path from first contact with the application to evidence your team can act on.

01

Point

You prove the hostname is yours — a TXT record we give you, or a file we ask you to serve — and then point the name at SelfSec instead of your origin. Nothing is installed and your application code stays exactly as it is.

02

Observe

Protection starts in detection mode. Every decision the firewall would have made is recorded and nothing is refused, so you see what enforcement would do to real traffic before it does it.

03

Enforce

When you say so, a site moves to blocking — a runtime change in the engine, not a redeploy. Clean traffic reaches your origin; blocked traffic gets an enforcement response with the matched rule recorded against it.

04

Tune

If a rule is wrong for your application, tell us and we correct it for you without giving up the rest of the set. Making that correction yourself is not in the console yet — it is on the roadmap.

Rule anatomy

What a rule is actually made of

Ask your current provider for the rule that blocked your customer's checkout. Here a rule is a record rather than a black box: what it is called, what it looks at and how serious it considers a match. Your console names the rules that fired on every event today; showing you the record behind them is on the roadmap.

One rule, as the engine records itenabled
{
"id""sqli-union-select",
"name""SQL UNION SELECT",
"category""SqlInjection",
"severity""Critical",
"targets"["Path", "Query", "Header", "Cookie", "Body"],
"pattern""…"not published here
}
  • Readable

    Every event names the rule identifiers that matched. Reading the record behind them in your console is on the roadmap.

  • Tunable

    A correction is surgical rather than all-or-nothing — one rule, one path, one parameter. Today you ask us for it; the control is on the roadmap.

  • Portable

    The same engine is one you could run yourself. Nothing about the rule set locks you to our hosting.

Pattern bodies will stay inside your account, not on a public page — the set has to keep working against the people it is for.

Control by architecture

Know where every security-sensitive flow goes

Requests to a protected site are inspected on SelfSec infrastructure on the way to your origin. What is kept is the metadata behind each enforcement decision — full request and response bodies are never stored.

Read the Privacy Policy

Documented flows

MANAGED EDGE · NAMED FIELDS

Requests are inspected on SelfSec infrastructure

Account activation is narrowly scoped

Optional telemetry stays off unless you turn it on

Be first to run SelfSec WAF

Join the launch list for availability, deployment guidance and the first production-ready release.