Your WAF, managed and sovereign
A Web Application Firewall managed, deployed, and operated by our experts, built on the open source CrowdSec technology. Protection based on attacker behavior rather than signatures.
What sets us apart from traditional WAFs
Typical application protection solutions force two trade-offs: routing all your traffic through a third-party service, and endlessly maintaining static rules. Our approach avoids both.A sovereign WAF: your traffic never leaves your perimeter
Proxy-mode WAFs (CDNs and front-facing protection services) require that all of your traffic pass through a third party, which terminates your TLS sessions and therefore sees the plaintext content of every request. Our control plane is deployed on your own infrastructure or ours, hosted in France: no one but you and us ever sees your requests.A high-performance WAF: zero added latency
In the Advanced plan, traffic is duplicated to the control plane for Layer 7 analysis: analysis happens “out-of-band”, meaning outside the request path. Your users never pass through any additional component, not a single millisecond is added, and an analyzer outage can never take down your service.Behavioral, not signature-based
A rules-based WAF (like OWASP CRS) requires constant tuning, and its false positives end up blocking your legitimate users. CrowdSec reasons in behavioral scenarios: it’s the attacker’s way of operating that gets detected. The result: unknown attackers contained without a prior signature and far fewer false positives.Open source and shared threat intelligence
CrowdSec is open source: no black box, no vendor lock-in, full reversibility. Community blocklists pool reports from the entire community and are continuously updated. And your cost depends on neither your request volume nor your bandwidth.Two service tiers: Classic and Advanced
The Classic plan protects your platforms at the network level and blocks known, detected malicious sources. The Advanced plan adds Layer 7 application analysis of your traffic and custom protection scenarios tailored to your applications.
| WAF Classic | WAF Advanced | |
|---|---|---|
| ENIX WAF SYSTEM | ||
| Dedicated control plane | ||
| Real-time analysis type | Behavioral scenarios based on logs | Behavioral and application scenarios, custom-built: headers, URL parameters, and request bodies |
| Attack monitoring interface | ||
| Integration with one of your existing systems (load balancers / reverse proxy, firewall, CDN) | ||
| FILTERING | ||
| Preventive filtering of known malicious IPs (CrowdSec CTI) | ||
| Layer 4 protection: network filtering, TLS overload protection | ||
| Layer 7 protection: traffic analysis | HTTP logs | Logs + Headers + HTTP payload |
| Self-protection scenarios against unknown attackers | ||
| Custom protection scenarios | — | |
| MANAGED SERVICES | ||
| Monitoring and alerting | ||
| Security watch and component updates | ||
| Support during attack events | Basic, based on logs | Advanced, based on duplicated traffic |
| Protection scenario tuning | Standard scenarios | Custom scenarios |
Both plans are available with 24/7 managed support, business hours including weekends, or standard business hours. The exact scope of your protection is defined together with you before deployment.
We plug into your existing setup
You don’t need to redesign your architecture or insert a new component into your request path. Blocking decisions are enforced by the equipment you already operate.Load balancers / Reverse proxy
Blocking is enforced as close to your applications as possible, on your existing load balancers or reverse proxies, with the necessary application-level granularity.Firewall
Decisions are pushed to your firewall to cut off malicious traffic at the network level, before it even reaches your servers.CDN
If you use a CDN, decisions are also propagated there to filter at the edge, as far from your infrastructure as possible.What our managed WAF service covers
Deployment of the CrowdSec WAF control plane and integration with one of your existing systems: load balancers, reverse proxy, firewall, or CDN.
Layer 4 protection (network filtering, TLS overload protection), preventive filtering of known malicious IPs with automated updates, and self-protection scenarios against unknown attackers.
Real-time log analysis, or of the traffic itself in the Advanced plan thanks to duplication to the control plane for Layer 7 inspection.
Continuous monitoring of the protection service, alerting on significant events, and an attack monitoring interface at your disposal.
In the Classic plan, our engineers adjust scenarios based on signals observed in your logs. In the Advanced plan, AppSec lets us analyze the application context of requests and create custom protections tailored to your application’s behaviors and endpoints.
We track new attack techniques to evolve your protection scenarios. And we track CVEs of the components deployed for your WAF, keeping it up to date by applying patches as soon as a vulnerability could affect you.
The CrowdSec technology
Our CrowdSec WAF is operated daily, on our own platforms as well as our clients’. CrowdSec is a French vendor, which extends our sovereignty requirements all the way down to the choice of the security building block.