Managed WAF Ruleset

A web application firewall in front of one domain, with the ruleset tuned to your application instead of left on a vendor default — a default either blocks your own customers or waves everything through. We keep the rules current, and when one starts blocking legitimate traffic we are the ones who work out which rule and why.

What you get

  • A managed ruleset for one domain, tuned against your real traffic rather than left at its defaults
  • False-positive triage: you forward the request that was blocked, we find the rule and decide whether to narrow it or drop it
  • A monthly rule pass, including new rules published in response to newly disclosed vulnerabilities
  • Rate limits on the endpoints that need them — login, search, password reset, anything expensive to serve
  • A monthly summary of what was blocked, so the ruleset is something you can look at rather than something you trust

What this does not cover

  • The vulnerability itself — a rule that blocks an injection attempt stands in front of code that is still wrong, and the rule is the stopgap, not the fix
  • Traffic that reaches your origin directly by IP address, bypassing the edge; closing that path off is part of Server Security Hardening Baseline
  • Volumetric floods, which are absorbed at the network edge rather than by rules — that is DDoS Mitigation Standby
  • Abuse that looks exactly like a real user: a correct password used by the wrong person is a successful login, and a ruleset cannot see the difference
  • Domains other than the one in scope, and any hostname that is not proxied through the edge

Who it fits

A public application with a login or a form on it, where the ruleset today is either switched off or quietly blocking real customers. If you are already on Growth Managed Hosting, WAF management is part of that plan — do not buy it twice.