Vorpcel // Web Application Firewall

Intelligence and coverage
in front of every request.

Your application is under attack all the time. The WAF analyzes every request before it reaches your server, blocks malicious ones, and lets legitimate traffic through with no impact for the user.

inbound blocked passed
§ 01

Defense in depth.

Seven layers evaluate every request together.

01

Managed rules

Broad coverage maintained and updated automatically. New threats are incorporated without your team's intervention, from day one.

Automatic updatesNo manual configuration
02

Behavioral AI

Machine-learning analysis of payload, session, and access-pattern anomalies in real time, catching signatureless and zero-day threats that static rules miss. Available on higher plans.

Session anomalyZero-day
03

Bot protection

Malicious automation identified by session fingerprint, access rate, and behavior pattern. Bots are challenged or blocked before reaching any endpoint.

JS challengeRate analysis
04

Network reputation

Real-time IP reputation, geolocation, abuse history, and ASN classification. Network context enriches every decision even before content analysis.

IP reputationASN & geo
05

Rate limiting

Rate control by route, method, and origin. Automatic reaction to anomalous request patterns without impacting legitimate traffic.

By routeBy IP
06

Access control

Restriction by geographic origin, ASN, and IP allowlist per route. Define who can access each part of your application without changing the code.

Geo-blockingIP allowlist
07

API protection

Your APIs are inspected like any other request - the same managed rules, behavioral AI, bot and rate-limit layers apply to every API endpoint. No schema import or extra setup required.

01 / 07
layers
§ 02 · Behavioral AI

Attacks that no signature has seen yet.

Managed rules catch known attacks. The threats that hurt the most are the ones written for you, that no rule describes yet. On higher plans the WAF adds a machine-learning layer that scores each request on its own behavior, so a novel or obfuscated attack is caught on how it acts, not on a signature it will never match.

Payload anomaly
Structure and content of the request scored against learned-normal traffic, flagging obfuscation static rules miss.
Session and pattern analysis
Access rate, sequence, and behavior over a session reveal brute force, enumeration, and abuse before damage is done.
Zero-day and signatureless coverage
Threats with no published rule are caught on behavior, closing the window between a new attack and its signature.
A score, not a black box
Every request gets a risk score that combines with rules and reputation, so you see why a decision was made.

Behavioral AI is available on higher plans.

§ 03 · Adaptation

Broad protection, adapted to your context.

The WAF comes with broad coverage from day one, but your business has unique routes, flows, and patterns. Create custom rules, calibrate sensitivity per route, and adapt the policy without compromising the default coverage.

/api/admin/*WAF · IP allowlistSTRICT
/api/*WAF · AI · rate-limitSTANDARD
/checkout/*WAF · bots · AISTRICT
/auth/*WAF · rate-limitSTANDARD
/static/*basic WAFRELAXED
Custom rules
Create rules for routes, IPs, headers, and parameters specific to your product.
Sensitivity per route
Distinct policies for the admin panel, public API, and checkout, without global configurations.
Monitor mode
Start in monitor mode to understand traffic before enabling active blocking.
False positive management
Mark exceptions and adjust rules directly in the dashboard when needed.
Event logexample.com
block
POST /api/auth/login
behavioral · score 0.94
14:22:07
block
GET /?id=1' OR '1'='1
managed rule · SQLi
14:22:05
allow
GET /products/42
clean · no match
14:22:05
block
GET /admin
access control · geo
14:22:03
allow
POST /checkout
clean · rate ok
14:22:02
§ 04 · Observability

Every decision logged with full context.

Knowing an attack was blocked is just the beginning. The WAF logs the route, origin, category, and rule that acted on every request, so your team has full context without digging through raw logs.

01

Full event context

Route, origin, category, and rule triggered in every event.

02

Decision reasoning in the dashboard

Decision reasoning visible directly in the dashboard.

03

History by domain and time

Event history by domain and time interval.

04

Tune with confidence

False positive identification and quick adjustment.

Start now

Place the WAF
in front of your application.

Free trial, no credit card required. Configure your first domain and monitor events in the dashboard.