Solutions

Web Application Firewall (WAF)

A managed WAF in front of your application: injections, XSS, scans and bot floods blocked before they reach your code, tuned so legitimate traffic passes.

Your application is scanned every day by bots looking for an injection, a forgotten admin page, a login to brute force. Patching every flaw in your code takes months; an attacker needs one night.

Our Web Application Firewall sits in front of your application and inspects every request. Attacks are blocked at the edge, before they ever reach your code: injection, cross-site scripting, scans, brute force and bot floods.

What You Get

  • Common exploits blocked at the perimeter, protecting code you cannot always patch fast enough
  • Scanners and abusive clients banned automatically, rate limits on the URLs that attract them
  • Rules tuned to your application: your customers, partners, APIs and monitoring pass, attackers do not
  • Hosted on your own infrastructure: your traffic does not transit through a third-party cloud
  • In your ISVTEC console: banned addresses, every refused request and why, and a button to lift a ban yourself
  • Open-source rules, no proprietary appliance, no lock-in
  • Fully managed by us: deployment, tuning, monitoring, rule updates

How We Switch It On Without Breaking Anything

  1. Detection: the WAF goes in front of your application and only logs what it would block. Nothing is refused.
  2. Tuning: we read those logs against your real traffic and adjust the rules until every legitimate request passes.
  3. Blocking: we switch on protection at the time you choose, then check the first night and the first peak of traffic.
  4. Follow-up: we report what was refused, and the flaws the logs reveal in your application, so each fix on your side removes an exception on ours.

Part of Our Cybersecurity Offer

The WAF is one layer of our cybersecurity offer, alongside the bastion, the VPN with MFA, hardening and audits.