Vorpcel // Web Application Firewall

Application protection.
Enforced at the edge.

Inspect application and API traffic before it reaches your origin. Vorpcel WAF combines managed rules, bot controls and rate limits with policies tailored to your applications, giving your team control over how requests are handled.

inbound Blocked passed

Defense in depth.

Combine request inspection, traffic controls and application policy.

Managed rules

Apply managed signatures for common web attack patterns, including injection, cross-site scripting and path traversal. Select rule sensitivity to suit your application.

Managed signaturesConfigurable sensitivity

ML request scoring

Complement signature-based inspection with machine-learning request scores where enabled. Model scores contribute additional context to the configured risk decision.

Request analysisRisk signals

Bot protection

Use client, network and traffic signals to assess automated requests. Configure bot policies to allow, challenge or block traffic according to your application requirements.

JS challengeRequest rates

Network reputation

Use IP reputation, geographic origin and ASN information to add network context to request evaluation and access policies.

IP reputationASN & geography

Rate limiting

Set request limits for sensitive routes and clients. Tune thresholds to control excessive traffic and account for expected application usage.

By routeBy IP

Access control

Manage access using IP, geographic and ASN policies alongside application-specific rules. Apply controls at the edge without changing application code.

Geo-blockingIP allowlist

API protection

Apply HTTP request inspection, bot controls and rate limits to APIs routed through the WAF. Tailor policies for the endpoints and request patterns your services expose.

01 / 07
capabilities
ML request scoring

Add context beyond signatures.

Managed rules identify recognizable attack patterns. Optional machine-learning scoring adds a separate assessment of request characteristics, complementing rule matches and network signals in the WAF risk engine. Review scores alongside decision evidence when tuning protection.

Payload anomaly
Assess request characteristics to add a model-based risk signal alongside managed-rule matches.
Traffic context
Consider client and request-rate signals alongside content inspection when evaluating suspicious traffic.
Complementary detection
Combine different risk signals to extend analysis beyond a single matching signature.
Scores in context
Review risk scores with rule matches and decision details to understand how the configured policy handled a request.

Machine-learning scoring is optional and depends on the enabled configuration.

Adaptation

Policies shaped around your application.

Different endpoints serve different purposes. Combine managed protection with custom rules, route controls and exceptions to account for administrative access, public APIs and customer-facing workflows.

/api/admin/*WAF · IP allowlistSTRICT
/api/*WAF · scoring · rate limitsSTANDARD
/checkout/*WAF · bots · scoringSTRICT
/auth/*WAF · rate limitsSTANDARD
/static/*Managed rulesRELAXED
Custom rules
Create rules for routes, IPs, headers, and parameters specific to your product.
Route-specific controls
Tailor rules and limits for administrative routes, public APIs and checkout flows.
Shadow evaluation
Observe score-based decisions in shadow mode before enforcing them. Explicit access rules and other direct controls retain their configured behavior.
Policy refinement
Review affected requests and refine rules or exceptions to accommodate legitimate application behavior.
Event logexample.com
Block
POST /api/auth/login
Risk score · 0.94
14:22:07
Block
GET /?id=1' OR '1'='1
Managed rule · SQLi
14:22:05
Allow
GET /products/42
No rule match
14:22:05
Block
GET /admin
Access control · geography
14:22:03
Allow
POST /checkout
Within rate limit
14:22:02
Observability

Understand how your policies act.

Explore request events with the route, client context, action and available rule or score details. Use the dashboard to investigate activity, review policy impact and guide configuration changes.

Request context

Inspect route, source, action and available detection details in request events.

Decision reasoning in the dashboard

Decision reasoning visible directly in the dashboard.

History by domain and time

Event history by domain and time interval.

Tune with confidence

Use event evidence to identify unintended blocks and guide policy adjustments.

Start now

Place the WAF
in front of your application.

Evaluate the WAF with a scoped deployment, application-specific policies and request visibility in the dashboard.