THE WAFIO PLATFORM
Every layer.
A clear purpose.
Explore the security controls, understand how they work, and choose the right policies for your applications and infrastructure.
01APPLICATION SECURITY
Semantic WAF
Inspect HTTP requests with semantic analysis and OWASP CRS.
- 17 semantic engines covering SQL, XSS, commands, SSRF, injection families, and other attack patterns.
- OWASP CRS through Coraza, with sensitivity filtering and configurable clean-result suppression.
02FILE SECURITY
Malicious Uploads Detection
Verify complete uploaded files against known SHA-256 signatures.
- Multipart file inspection and optional whole-body scanning for raw upload endpoints.
- Exact verification after Bloom screening, plus custom SHA-256 allowlists and blocklists.
03NETWORK SECURITY
eBPF Firewall
Apply Linux network policies using XDP and TC.
- XDP filtering at the network interface and supported TC attachment points.
- Address, protocol, and port policies for the services on a host.
04HOST SECURITY
Runtime Security
Investigate process, file, and connection activity on hosts.
- Supported execution, file, and connection events such as execve, openat, and connect.
- Process and parent context, user attributes, and available event details.
05REQUEST POLICY
Traffic Controls
Combine flood controls, bot checks, geographic and path policies.
- L7 flood controls and configured block policies.
- Geographic filtering backed by the configured GeoIP data.
06OPERATIONS
Central Management
Manage projects, agents, access, and policies from one control plane.
- Project membership with viewer, member, and owner roles.
- Certificate-based agent enrollment and gRPC mutual TLS.
07INVESTIGATION
Security Visibility
Review WAF decisions, host events, and audit history together.
- WAF decision streams with action, category, and available match details.
- Host and network enforcement event views.
08SECURITY DATA
Threat Intelligence
Manage the databases and rule data used by your protection layers.
- MalwareBazaar hash-feed configuration with an encrypted provider credential.
- GeoIP data and OWASP CRS rule sources.
SEE THE CONNECTIONS
One platform. Connected protection.
See how network, application, and runtime controls work together.