Security

eWAF

An inline web application firewall and universal website-security platform: a managed, versioned ruleset, real-time malware scanning, runtime PHP blocking, bot management, virtual patching and compliance reporting — for every site from WordPress to Kubernetes.

300+

Edge & agent nodes worldwide

10B+

Requests inspected daily

0.01%

False-positive rate

99.99%

Uptime target

Built to protect. Designed to perform.

What eWAF is

eWAF sits inline as a reverse-proxy firewall with TLS inspection, so it protects an entire fleet from one console rather than a plugin at a time. The managed L7 ruleset is versioned and tunable across paranoia levels one to four, which is what keeps coverage high without drowning a busy site in false positives.

It is one platform rather than a drawer full of point tools: edge firewall, malware scanning and runtime blocking, patch management, bot control, analytics and reporting all share the same console and the same multi-tenant model.

Capabilities

Everything eWAF does

Edge Shield — client-side security

Watch every script running in your visitors' browsers, control AI crawlers, and stay PCI DSS 4.0 compliant — protection a server-side scanner cannot offer.

OWASP Top 10 protection

Managed, versioned coverage against SQL injection, cross-site scripting, LFI/RFI, RCE, SSRF and the rest of the OWASP Top 10.

Bot management

Detect and block malicious bots and scrapers while verified good crawlers such as Googlebot and Bingbot pass through untouched.

Malware & proactive defence

Real-time malware scanning paired with runtime PHP blocking, so an uploaded shell is stopped at execution rather than found at the next scan.

Patch management

Snapshot-first virtual and real patching, so a vulnerable component is shielded immediately and updated safely afterwards.

Real-time analytics

Live dashboards and a persisted, exportable WAF log give actionable insight into every request, threat and trend.

Rate limiting & custom rules

Adaptive per-route rate controls against abuse, credential stuffing and brute force, plus your own rules and policies with per-rule enable/disable and paranoia levels 1–4.

API protection

Schema-aware inspection at the edge secures APIs against abuse, injection and business-logic attacks.

Who it is for

Built for teams like these

Hosting providers

Protect thousands of sites from one multi-tenant console instead of a plugin per customer.

MSPs & agencies

White-label the platform and bill per client, with fleet-wide visibility behind it.

Enterprise

Fleet-scale governance and compliance reporting across every property you run.

eCommerce & WordPress

Stop card skimmers and plugin exploits, with client-side script control for PCI DSS 4.0.

Common questions

eWAF, answered

Still weighing it up? Tell us your stack and we will tell you honestly whether this fits.

Request pricing
Will a WAF break our sites with false positives?

The managed ruleset is versioned and tunable across paranoia levels one to four, with per-rule enable and disable, and the published false-positive rate is 0.01%.

What does eWAF protect that a server-side scanner cannot?

Edge Shield watches the scripts actually running in your visitors' browsers and lets you control AI crawlers — client-side threats such as card skimmers never touch your server, so a server-side scan cannot see them.

Which stacks does it support?

Every major stack, from WordPress through to Kubernetes. It deploys as an inline reverse-proxy firewall with TLS inspection, so the application behind it does not have to change.

More products

The rest of the range

All 10 products

Server Management Suite v2

Server, cloud, security and cost monitoring in one console.

Learn more

SiteHelp

Live visitor intelligence and AI chat you can resell.

Learn more

RemoteBackups

Universal data protection with immutable, verified restores.

Learn more
Let's build something

Ready to hand the technical work to a team that owns it?

Tell us what you are trying to achieve. We will come back with a scope, a timeline and a fixed price — no obligation.

Or call +1 (347) 380-6880 · +91 7350 014 611