WAF (Web Application Firewall)

We protect your projects from OWASP Top 10 and targeted attacks without compromising speed or availability.

By signing up you agree to the Terms of Service.

ico

Quick
start

ico

Easy
to rent

ico

GDPR
compliance

What is WAF?

WAF is a web application firewall. It sits between the user and your site, inspecting every request and allowing only safe traffic through.

Suspicious attempts - such as SQL injections or malicious scripts - are blocked. This keeps your data secure and your website running smoothly.

ssl-1-1-2-1-1
Security
Attack blocking

The system analyzes incoming traffic and blocks malicious requests before they ever reach your application.

icon_40x40_isolated-nw
Only with CDN

WAF can be enabled in just a few clicks in the control panel, with no complex setup, and is available together with CDN.

Admin access
Flexible billing

Charges apply for every 10,000 requests, avoiding overpayment for unused ones.

How to enable WAF in Serverspace?

No complex setup - just a couple of clicks and the CDN-based WAF protects your product from web threats.

icon_100x100_join (4) 1
Register

Signing up in the Serverspace control panel takes just 20 seconds. All you need is an email address.

icon_100x100_start111
Upload your link

In the left sidebar, go to the CDN section, select WAF, and attach the link to your website or web application.

icon_100x100_redundantreliable111
Use it

Congratulations! Your website is now protected from 99.9% of web threats. You can continue working safely.

Advantages of WAF in the Serverspace control panel

icon_40x40_cloud1
One-click management

Enable or disable attack protection directly in the interface with no complex setup.

icon_40x40_specific_features
Flexible operation modes

You can choose between detection only (logging) or full blocking of suspicious requests.

icon_40x40_docs11
Transparent auditing

Log storage and a detailed incident journal for analysis and compliance with security requirements.

growth
Automatic rule updates

New signatures and policies are applied without service downtime, ensuring up-to-date protection at all times.

WAF is right for you if:

monitoring_02-1-2-2-1

E-commerce

WAF protects payment forms and customer accounts from hacking and data theft.

It monitors requests to shopping carts, payment forms, and personal accounts. By blocking attempts to inject malicious code or intercept card data, it reduces the risk of fraud and leaks.

ssl-1-1-2-1

Fintech and banking

Helps meet PCI DSS requirements and blocks attacks on online services.

WAF inspects all traffic for vulnerabilities, protecting online banking and APIs from SQL injections and XSS. This supports PCI DSS audits and maintains customer trust.

cli-1-1-2-1

Education and public services

Prevents leaks of personal data of students and citizens.

Services with personal accounts and databases of students or citizens are protected from unauthorized access. WAF stops large-scale data leaks and attacks on portals.

cli-2-1-1-2-1 1

SaaS platforms

Ensures service stability, API protection, and SLA compliance for clients.

WAF filters requests to APIs, authorization modules, and control panels. It reduces the load from bots and hacker scanners, helping maintain SLAs and stable service performance.

User-friendly control panel

To enable WAF, your website must be connected to CDN. In the site settings, activating WAF takes just a couple of clicks.

Screenshot 2025-09-22 175150
Screenshot 2025-09-22 175220

Pay only for what you actually protect

Serverspace WAF offers transparent billing: charges apply for every 10,000 requests, preventing overpayment and scaling alongside your traffic growth.

FAQ:

Why is WAF only available with CDN?

In Serverspace, WAF operates at the content delivery network (CDN) level. This approach filters traffic before it reaches your server, reducing infrastructure load. Combined with CDN, protection against SQL injections, XSS, and other OWASP threats becomes highly effective: malicious requests are blocked at the perimeter, while users enjoy fast and secure access to applications.

How is WAF billed in Serverspace?

Serverspace WAF uses fully transparent billing: charges apply for every 10,000 requests passing through the filtering system.

This model gives you precise cost control without overpaying for unused packages. As your project traffic grows, payments scale automatically, keeping the balance between security and budget.

What makes WAF different from DDoS protection?

DDoS protection blocks large-scale network attacks that overload servers, while WAF analyzes each HTTP/HTTPS request to safeguard applications from OWASP Top 10 threats such as SQL injections, XSS, API attacks, and data leaks. The best results come from using both services together. For comprehensive protection, you can enable WAF in Serverspace along with DDoS filtering.

Where can I activate the service?

WAF is available directly in the Serverspace control panel under the CDN section. Activation takes just a few seconds and doesn’t require any additional software. Simply open the interface and click “Enable WAF”, and protection will start working automatically.