Local Data Sovereignty
Keep your data in Egypt with CyCloud SaaS or in your own environment with On-Prem.
CyWAF is a Web Application Firewall that sits between your web application and the internet, combining traffic inspection with AI-powered detection to block malicious requests and let legitimate users through.
No credit card required
Keep your data in Egypt with CyCloud SaaS or in your own environment with On-Prem.
Protection against emerging and unknown attacks.
EGP pricing. No USD volatility.
Egyptian engineers. Your timezone. Your language.
Get protected fast with fully managed SaaS deployment and minimal setup.
Cloud SaaS, CyCloud SaaS, or On-Prem.
Monitor and analyse web application firewall activity in real time.
All WAF-evaluated traffic
Allowed through to origin
Matched attack signatures or ML
6,037 stopped of 6,584 detected
WAF actions (CRS + ML) across the selected window
Blocked requests, most recent first
Time-of-day × outcome
Matched signatures, current window
By request volume
Top 5 most frequent, current window
33% target state-changing methods (POST / PUT / PATCH / DELETE)
Geographic distribution of attack sources
Scanners, bots, credential-stuffers, exploit probes — hitting your sites from every corner of the internet. CyWAF inspects each one and drops the bad ones at the edge. Nothing reaches your origin unless you'd want it to.
Everything your team asks for, in one console
Explore the controls that help your team protect applications, manage traffic, and respond to threats with confidence.
Protect multiple websites and applications from one CyWAF console, with separate policies and health visibility for each domain.
Use OWASP CRS and CyRules to block common web attacks, including SQL injection, XSS, RCE, scanners, and more.
Use WAMM to analyze requests for attack probability and identify disguised, emerging, and previously unseen attack patterns.
Create, group, organize, and manage domain-specific protection rules from one console.
Control IP access, file uploads, rate limits, and other request policies for each protected domain.
Review domain logs, audit activity, attack details, and packet captures when you need to investigate an incident.
CyWAF uses WAMM, its machine-learning model trained on real-world web attack patterns. WAMM evaluates every request across multiple attack classes and shows how strongly the request matches each one. A built-in AI assistant turns technical alerts into plain-English explanations your whole team can read.
Read the WAMM research paperq
parameter — a classic attempt to pull password data from the
users
table. Both our signature rules and the AI engine flagged it —
blocked with high confidence.
Every request is scored against each attack class WAMM recognizes, not just block or allow. The radar shows the main match and secondary signals, so your team can tune thresholds per class instead of relying on one global dial.
POST /api/search · 2 ms ago
New AI capabilities planned to help your team detect, tune, and respond to threats.
Learn normal application behavior and flag unusual requests beyond known attack signatures.
Analyze false positives and recommend rule corrections, exceptions, and threshold adjustments.
Suggest improvements to existing WAF rules based on observed traffic and attack patterns.
Manage WAMM training and detection pipelines to continuously improve threat detection.
Learn legitimate traffic patterns and suggest policy rules for your protected applications.
Every request is scored against every attack class our AI recognizes — not a binary block/allow. The radar shows the engine's certainty and its second-guesses, so you can tune thresholds per class instead of one global dial.
POST /api/search · 2 ms ago
Three steps. No kernel modules, no sidecars, no weeks of tuning.
Add your site. Update your DNS to route through CyWAF. TLS terminates at the edge; your origin sees only clean traffic.
Turn on attack protection with one click. Enable AI detection. Add IP reputation feeds. Set rate limits that make sense for your app.
The dashboard lights up. Review every blocked attack with full context, tune rules on the fly, and ship custom rules in seconds.
Protect the endpoints, business logic, and traffic patterns that make your application unique. Start with a guided rule builder, add conditions as your needs grow, or write raw SecRule syntax in Expert Mode. Every option is enforced by the same WAF engine.
.php
only in
/uploads/
Single rule, common operators
Chain conditions as chips, AND only
All conditions must match (AND).
SecRule REQUEST_URI "@rx ^/admin/" ...Chain conditions with AND
Raw SecRule syntax
# Block unauthorized writes to admin SecRule REQUEST_URI "@rx ^/admin/" "id:1001,phase:2,deny,log,msg:'Unauthorized admin write'"
Each site you protect runs in its own isolated protection zone. Settings, rules, and logs stay completely separate — so a rule change or false positive on one site never touches any of the others.
Every setting change, every rule edit, every login — logged and replayable. The compliance answers are waiting in the dashboard.
Every change in the console — who, what, when, before/after — recorded for SOC 2, ISO 27001, internal governance.
Browse or revert any configuration change with before/after snapshots. "What changed last Tuesday?" answered in seconds.
Invite teammates and scope permissions per site. Security team sees logs, dev team edits rules, execs see the dashboard.
Modern sign-in with optional multi-factor and single sign-on (SSO). No default admin accounts, no insecure defaults.
Point-in-time snapshots of each site's full protection setup. Roll back a bad change, or clone a known-good setup to a new site.
In-app alerts for security events and config changes. Stay informed without living in the dashboard.
Tokens, passwords, and personal data are automatically redacted in logs. Privacy-safe by default.
Built-in account lockout on failed sign-in attempts. We protect your apps from attackers — and we protect the console from them too.
Every console capability has a REST endpoint. Every service ships as a container. Every deployment has Kubernetes manifests. Your protection setup belongs in version control, and CyWAF makes that easy.
/api/v1/, versioned and stable.
docker compose up
from zero to protected.
Reviewable foundations, continuous security scanning, and clear visibility into every request we protect.
The capabilities you expect from a major WAF — paired with local engineering support, flexible deployment, and pricing that actually fits MENA budgets.
Same engine, same console, same rules. You decide where it runs. Start in minutes on our cloud, keep your data in-country, or host it entirely yourself.