Your WAF, managed and sovereign

A Web Application Firewall managed, deployed, and operated by our experts, built on the open source CrowdSec technology. Protection based on attacker behavior rather than signatures.

What sets us apart from traditional WAFs

Typical application protection solutions force two trade-offs: routing all your traffic through a third-party service, and endlessly maintaining static rules. Our approach avoids both.
Icon representing data and traffic sovereignty

A sovereign WAF: your traffic never leaves your perimeter

Proxy-mode WAFs (CDNs and front-facing protection services) require that all of your traffic pass through a third party, which terminates your TLS sessions and therefore sees the plaintext content of every request. Our control plane is deployed on your own infrastructure or ours, hosted in France: no one but you and us ever sees your requests.
Icon representing performance and the absence of added latency

A high-performance WAF: zero added latency

In the Advanced plan, traffic is duplicated to the control plane for Layer 7 analysis: analysis happens “out-of-band”, meaning outside the request path. Your users never pass through any additional component, not a single millisecond is added, and an analyzer outage can never take down your service.
Shield icon representing behavioral attack detection

Behavioral, not signature-based

A rules-based WAF (like OWASP CRS) requires constant tuning, and its false positives end up blocking your legitimate users. CrowdSec reasons in behavioral scenarios: it’s the attacker’s way of operating that gets detected. The result: unknown attackers contained without a prior signature and far fewer false positives.
Icon representing open source and the open ecosystem

Open source and shared threat intelligence

CrowdSec is open source: no black box, no vendor lock-in, full reversibility. Community blocklists pool reports from the entire community and are continuously updated. And your cost depends on neither your request volume nor your bandwidth.

Two service tiers: Classic and Advanced

The Classic plan protects your platforms at the network level and blocks known, detected malicious sources. The Advanced plan adds Layer 7 application analysis of your traffic and custom protection scenarios tailored to your applications.

WAF
Classic
WAF
Advanced
ENIX WAF SYSTEM
Dedicated control plane
Real-time analysis typeBehavioral scenarios
based on logs
Behavioral and application
scenarios, custom-built:
headers, URL parameters,
and request bodies
Attack monitoring interface
Integration with one of your existing systems (load balancers / reverse proxy, firewall, CDN)
FILTERING
Preventive filtering of known malicious IPs (CrowdSec CTI)
Layer 4 protection: network filtering, TLS overload protection
Layer 7 protection: traffic analysisHTTP logsLogs +
Headers + HTTP payload
Self-protection scenarios against unknown attackers
Custom protection scenarios
MANAGED SERVICES
Monitoring and alerting
Security watch and component updates
Support during attack eventsBasic,
based on logs
Advanced,
based on
duplicated traffic
Protection scenario tuningStandard
scenarios
Custom
scenarios

Both plans are available with 24/7 managed support, business hours including weekends, or standard business hours. The exact scope of your protection is defined together with you before deployment.

We plug into your existing setup

You don’t need to redesign your architecture or insert a new component into your request path. Blocking decisions are enforced by the equipment you already operate.
Icon representing WAF integration with your load balancers and reverse proxies

Load balancers / Reverse proxy

Blocking is enforced as close to your applications as possible, on your existing load balancers or reverse proxies, with the necessary application-level granularity.
Icon representing WAF integration with your firewall

Firewall

Decisions are pushed to your firewall to cut off malicious traffic at the network level, before it even reaches your servers.
Icon representing WAF integration with your CDN

CDN

If you use a CDN, decisions are also propagated there to filter at the edge, as far from your infrastructure as possible.

What our managed WAF service covers

Setup

Deployment of the CrowdSec WAF control plane and integration with one of your existing systems: load balancers, reverse proxy, firewall, or CDN.

Filtering

Layer 4 protection (network filtering, TLS overload protection), preventive filtering of known malicious IPs with automated updates, and self-protection scenarios against unknown attackers.

Analysis and detection

Real-time log analysis, or of the traffic itself in the Advanced plan thanks to duplication to the control plane for Layer 7 inspection.

Monitoring and alerting

Continuous monitoring of the protection service, alerting on significant events, and an attack monitoring interface at your disposal.

Support during attacks

In the Classic plan, our engineers adjust scenarios based on signals observed in your logs. In the Advanced plan, AppSec lets us analyze the application context of requests and create custom protections tailored to your application’s behaviors and endpoints.

Watch and updates

We track new attack techniques to evolve your protection scenarios. And we track CVEs of the components deployed for your WAF, keeping it up to date by applying patches as soon as a vulnerability could affect you.

The CrowdSec technology

A control plane that centralizes analysis: it ingests your HTTP logs and, in the Advanced plan, duplicated traffic, then decides which remediations to apply
Behavioral scenarios that describe ways of attacking — brute-force, enumeration, vulnerability scanning, scraping, API abuse — rather than request signatures
An AppSec component for application-level analysis: headers, URL parameters, and request bodies inspected in context, with rules tailored to your endpoints
Premium CTI: reports from the entire community feed continuously updated malicious IP blocklists
Icon representing open source, the CrowdSec technology behind our WAF
Enix is a CrowdSec partner

Our CrowdSec WAF is operated daily, on our own platforms as well as our clients’. CrowdSec is a French vendor, which extends our sovereignty requirements all the way down to the choice of the security building block.

Background dot icons
A fully operated service, not simply a product

You don't inherit a tool to run yourself: our senior engineers operate the solution for you, reachable directly on your dedicated messaging channel, with no escalation matrix
A poorly tuned WAF is a WAF that blocks your customers: tuning protection scenarios is part of the service, up to writing custom scenarios for your applications in the Advanced plan
We operate this solution daily, on our own platforms as well as our clients', including in critical production
Enix is ISO 27001 certified by SGS and has a dedicated security team — discover our security expertise

FAQ - Frequently Asked Questions
A sovereign WAF is a Web Application Firewall whose control plane is hosted in French data centers or directly on your own infrastructure, without ever routing your traffic through a foreign third party. Unlike CDN-mode WAFs, which terminate your TLS sessions and therefore see the plaintext content of every request, our solution guarantees that no one but you and Enix ever sees your data. We are also members of Libralis, which offers additional security and business-continuity guarantees, along with legal protection against extra-European law.
A traditional network firewall filters traffic at the network level (Layer 3/4): IP addresses, ports, and protocols, allowed or not. It doesn’t see the content of requests. A WAF operates at the application level (Layer 7): it analyzes the content of HTTP requests (headers, parameters, body) to detect attacks like SQL injection or XSS, which are invisible to a network firewall since they pass through allowed ports (80/443). The two are complementary: one protects the infrastructure, the other protects your applications.
A proxy-mode WAF (CDN or front-facing protection service) requires that all of your traffic pass through a third party before reaching your servers, which adds latency and an extra point of failure. An out-of-band WAF, like the one we offer in the Advanced plan, analyzes a duplicated copy of the traffic outside the request path: your users never pass through any additional component, no latency is added, and an analyzer outage can never take down your service.
Want to learn more about our managed WAF service?
Contact us