Inspect application and API traffic before it reaches your origin. Vorpcel WAF combines managed rules, bot controls and rate limits with policies tailored to your applications, giving your team control over how requests are handled.
Combine request inspection, traffic controls and application policy.
Apply managed signatures for common web attack patterns, including injection, cross-site scripting and path traversal. Select rule sensitivity to suit your application.
Complement signature-based inspection with machine-learning request scores where enabled. Model scores contribute additional context to the configured risk decision.
Use client, network and traffic signals to assess automated requests. Configure bot policies to allow, challenge or block traffic according to your application requirements.
Use IP reputation, geographic origin and ASN information to add network context to request evaluation and access policies.
Set request limits for sensitive routes and clients. Tune thresholds to control excessive traffic and account for expected application usage.
Manage access using IP, geographic and ASN policies alongside application-specific rules. Apply controls at the edge without changing application code.
Apply HTTP request inspection, bot controls and rate limits to APIs routed through the WAF. Tailor policies for the endpoints and request patterns your services expose.
Managed rules identify recognizable attack patterns. Optional machine-learning scoring adds a separate assessment of request characteristics, complementing rule matches and network signals in the WAF risk engine. Review scores alongside decision evidence when tuning protection.
Machine-learning scoring is optional and depends on the enabled configuration.
Different endpoints serve different purposes. Combine managed protection with custom rules, route controls and exceptions to account for administrative access, public APIs and customer-facing workflows.
/api/admin/*WAF · IP allowlistSTRICT/api/*WAF · scoring · rate limitsSTANDARD/checkout/*WAF · bots · scoringSTRICT/auth/*WAF · rate limitsSTANDARD/static/*Managed rulesRELAXEDExplore request events with the route, client context, action and available rule or score details. Use the dashboard to investigate activity, review policy impact and guide configuration changes.
Inspect route, source, action and available detection details in request events.
Decision reasoning visible directly in the dashboard.
Event history by domain and time interval.
Use event evidence to identify unintended blocks and guide policy adjustments.
Evaluate the WAF with a scoped deployment, application-specific policies and request visibility in the dashboard.