CyWAF Web application firewall for websites and APIs

Enterprise WAF.
Powered by AI.

CyWAF is a Web Application Firewall that sits between your web application and the internet, combining traffic inspection with AI-powered detection to block malicious requests and let legitimate users through.

No credit card required

Local team, local support Protect apps and domains in minutes Transparent & auditable
Why CyWAF

Six capabilities that make CyWAF different.

Local Data Sovereignty

Keep your data in Egypt with CyCloud SaaS or in your own environment with On-Prem.

AI-Powered Protection

Protection against emerging and unknown attacks.

Stable Pricing

EGP pricing. No USD volatility.

Arabic Support

Egyptian engineers. Your timezone. Your language.

Zero-Touch Deployment

Get protected fast with fully managed SaaS deployment and minimal setup.

Flexible Deployment

Cloud SaaS, CyCloud SaaS, or On-Prem.

BETA
ACME Egypt/app.acme.com.eg/Domain Dashboard

app.acme.com.eg Dashboard ● LIVE

Monitor and analyse web application firewall activity in real time.

TodayToday · Cairo (EET)
Threat postureEvents explorer

Total requests

1,284,502

All WAF-evaluated traffic

Normal requests

1,277,918

Allowed through to origin

Malicious requests

6,584

Matched attack signatures or ML

Enforcement rate

91.7%

6,037 stopped of 6,584 detected

Attacks over time

WAF actions (CRS + ML) across the selected window

All Allowed Blocked
00:0006:0012:0018:0023:00

Live threat feed

Blocked requests, most recent first

LIVE
  1. GET /product?id=1' OR '1'='1app.acme.com.eg RU 203.0.113.42
    Critical
  2. POST /api/v1/loginapp.acme.com.eg CN 198.51.100.7
    High
  3. GET /search?q=<script>alert(1)app.acme.com.eg NL 192.0.2.146
    High
  4. GET /../../etc/passwdapp.acme.com.eg TR 203.0.113.88
    Critical
  5. POST /upload.phpapp.acme.com.eg IR 198.51.100.23
    Medium
View all logs →

Activity heatmap

Time-of-day × outcome

less ■ ■ ■ ■ more
BlockedLoggedPassedAllowed
00:0006:0012:0018:0023:00

Top rules by hits

Matched signatures, current window

Manage →
  1. 942100SQL Injection Attack Detected via libin…1,284
  2. 941110XSS Filter - Category 1: Script Tag Vec…976
  3. 930130Restricted File Access Attempt614
  4. 932160Remote Command Execution: Unix Shell Co…402
  5. 913110Found request header associated with se…287
  6. 920350Host header is a numeric IP address145

Top source IPs

By request volume

  1. 1203.0.113.42 Egypt1,482
  2. 2198.51.100.7 Saudi Arabia1,105
  3. 3192.0.2.146 United Arab Emirates863
  4. 4203.0.113.88 Jordan640
  5. 5198.51.100.23 Qatar512
  6. 6192.0.2.201 Kuwait387
  7. 7203.0.113.157 Bahrain298
  8. 8198.51.100.64 Morocco214

HTTP methods

Top 5 most frequent, current window

  • GET62%
  • POST24%
  • PUT6%
  • DELETE3%
  • HEAD5%

33% target state-changing methods (POST / PUT / PATCH / DELETE)

Attack origins

Geographic distribution of attack sources

1,246 incidents · 5 countries
Map showing attack sources by country
  1. Russia31%
  2. China22%
  3. United States14%
  4. Brazil9%
  5. Germany6%
IP geolocation by DB-IP

Domain Dashboard

Live · app.acme.com
Attacks over time
All traffic, allowed and blocked, across the selected window
All Allowed Blocked
Live threat feed
Blocked requests, most recent first
Live
  1. shop.example.com
    POST/login?id=1' OR 1=1--
    US185.244.12.9
    Crit
  2. shop.example.com
    GET/admin/.env
    RU45.79.11.2
    High
  3. api.example.com
    POST/api/search {"q":"<script>..."}
    CN104.28.9.11
    High
  4. portal.acme.io
    GET/wp-login.php
    NL51.143.22.8
    Med
  5. shop.example.com
    POST/checkout/../../etc/passwd
    BR177.54.148.9
    Crit
View all logs →

Fleet Overview

6 protected domains · Last 24h
Protected domains
6
All healthy
Total requests
486K
+8.4% vs prior day
Blocked attacks
2,083
0.43% of traffic
Avg. latency
18ms
Within target
Attacks over time
Blocked requests across your domains
Live
00:0006:0012:0018:00Now
Protected domains Health
  • app.acme.comHealthy
  • shop.acme.comHealthy
  • api.acme.comHealthy
  • portal.acme.comHealthy
  • pay.acme.comHealthy
+1 more protected domain
Global attack surface

Attacks come from everywhere.
Blocked before they reach you.

Scanners, bots, credential-stuffers, exploit probes — hitting your sites from every corner of the internet. CyWAF inspects each one and drops the bad ones at the edge. Nothing reaches your origin unless you'd want it to.

  • Attack origin detected
  • Request inspected
  • Origin protected
625+
OWASP Core Rule Set + CyRules managed rules - live the day they're published
Tunable
Per-site balance - speed vs coverage, detect vs prevent
Seconds
Rule changes apply without redeploys
< 10 min
From DNS change to first blocked attack

Everything your team asks for, in one console

Every request logged Complete audit trail Role-based access Secure sign-in 24/7 monitoring
The platform

Built to detect, block, and respond.

Explore the controls that help your team protect applications, manage traffic, and respond to threats with confidence.

Multi-Domain Protection

Protect multiple websites and applications from one CyWAF console, with separate policies and health visibility for each domain.

Core WAF Protection

Use OWASP CRS and CyRules to block common web attacks, including SQL injection, XSS, RCE, scanners, and more.

AI Threat Detection

Use WAMM to analyze requests for attack probability and identify disguised, emerging, and previously unseen attack patterns.

Rule & Policy Management

Create, group, organize, and manage domain-specific protection rules from one console.

Access & Traffic Controls

Control IP access, file uploads, rate limits, and other request policies for each protected domain.

Monitoring & Investigation

Review domain logs, audit activity, attack details, and packet captures when you need to investigate an incident.

The AI layer

Beyond signatures.
Learn what your attackers look like.

CyWAF uses WAMM, its machine-learning model trained on real-world web attack patterns. WAMM evaluates every request across multiple attack classes and shows how strongly the request matches each one. A built-in AI assistant turns technical alerts into plain-English explanations your whole team can read.

Read the WAMM research paper
  • WAMM looks beyond signatures It helps identify disguised, emerging, and previously unseen attack patterns.
  • Clear attack-class confidence The percentage shows how strongly WAMM associates a request with an attack class; each class is scored separately.
  • Human-readable explanations An AI assistant translates the model result into why it matters and what to do.

Live detection in action

POST /api/search Host: shop.example.com
Content-Type: application/json { "q": "1' UNION SELECT password FROM users--" }
0.94
SQL injection attempt detected
94% SQL injection · each attack class scored separately
LLM Explanation
This request attempted a SQL injection through the q parameter — a classic attempt to pull password data from the users table. Both our signature rules and the AI engine flagged it — blocked with high confidence.
Per-class distribution

Not just a verdict.
A shape.

Every request is scored against each attack class WAMM recognizes, not just block or allow. The radar shows the main match and secondary signals, so your team can tune thresholds per class instead of relying on one global dial.

Class distribution

POST /api/search · 2 ms ago

AI · 0.94
SQL Injection · 0.94XSSCMD InjectionPath TraversalRCELDAPXXESSRF · 0.76
Top classesSQL Injection+SSRF·Request probing for both data exfiltration and internal-service access
Coming soon

More AI for your protection workflow.

New AI capabilities planned to help your team detect, tune, and respond to threats.

Behavioral Anomaly Detection

Learn normal application behavior and flag unusual requests beyond known attack signatures.

AI-Assisted WAF Rule Tuning

Analyze false positives and recommend rule corrections, exceptions, and threshold adjustments.

AI Rule Enhancement Suggestions

Suggest improvements to existing WAF rules based on observed traffic and attack patterns.

Multi-WAMM Training & Management

Manage WAMM training and detection pipelines to continuously improve threat detection.

AI-Powered Whitelisting

Learn legitimate traffic patterns and suggest policy rules for your protected applications.

Per-class distribution

Not just a verdict.
A shape.

Every request is scored against every attack class our AI recognizes — not a binary block/allow. The radar shows the engine's certainty and its second-guesses, so you can tune thresholds per class instead of one global dial.

Class distribution

POST /api/search · 2 ms ago

AI · 0.94
Top classes SQL Injection + SSRF · Request probing for both data exfiltration and internal-service access
Time-to-protected: minutes

From DNS change to blocked attacks, fast.

Three steps. No kernel modules, no sidecars, no weeks of tuning.

1

Point your DNS

Add your site. Update your DNS to route through CyWAF. TLS terminates at the edge; your origin sees only clean traffic.

2

Enable protection

Turn on attack protection with one click. Enable AI detection. Add IP reputation feeds. Set rate limits that make sense for your app.

3

Watch threats get blocked

The dashboard lights up. Review every blocked attack with full context, tune rules on the fly, and ship custom rules in seconds.

Custom rules

Custom rules for every application.

Protect the endpoints, business logic, and traffic patterns that make your application unique. Start with a guided rule builder, add conditions as your needs grow, or write raw SecRule syntax in Expert Mode. Every option is enforced by the same WAF engine.

  • Rule organizationGroup rules, reorder priority, and enable or disable them without deleting.
  • Rate limitingBy IP, path, method, header, or any combination.
  • File protectionPath-scoped file extension blocks. Block .php only in /uploads/
  • IP accessReusable allowlists and blocklists with built-in threat intelligence feeds.

Single rule, common operators

Group
Match targetsSelect where the pattern should be applied.

Chain conditions as chips, AND only

All conditions must match (AND).

WhenREQUEST_URImatches^/admin/
ANDMETHODisPOST
Thenblockseverity: WARNING
Live previewSecRule REQUEST_URI "@rx ^/admin/" ...

Chain conditions with AND

Variables to inspect
REQUEST_HEADERSmatchesadmin-token

Raw SecRule syntax

# Block unauthorized writes to admin
SecRule REQUEST_URI "@rx ^/admin/" "id:1001,phase:2,deny,log,msg:'Unauthorized admin write'"
SecRule helperRequired: variable, operator, unique id, phase, and a disruptive action such as deny.
Multi-site protection

One dashboard.
Every site.
Zero cross-contamination.

Each site you protect runs in its own isolated protection zone. Settings, rules, and logs stay completely separate — so a rule change or false positive on one site never touches any of the others.

  • Isolated rule sets, isolated configs, isolated logs
  • Per-domain snapshots — revert a bad config in one click
  • Clone a known-good config to a new domain instantly
  • Role-based access — different domains, different permissions
shop.example.com
Base onAI on
api.example.com
Base onCustom rules: 14
portal.acme.io
Base onRate 8
www.example.com
Base onAI on
admin.acme.io
Base onIP gate
static.cdn.co
Base onExt block
6 domains protected All healthy · 0 incidents
Built for teams

Governance your auditor will love.

Every setting change, every rule edit, every login — logged and replayable. The compliance answers are waiting in the dashboard.

Immutable Audit Log

Every change in the console — who, what, when, before/after — recorded for SOC 2, ISO 27001, internal governance.

Settings History

Browse or revert any configuration change with before/after snapshots. "What changed last Tuesday?" answered in seconds.

Team Permissions

Invite teammates and scope permissions per site. Security team sees logs, dev team edits rules, execs see the dashboard.

Secure Sign-In

Modern sign-in with optional multi-factor and single sign-on (SSO). No default admin accounts, no insecure defaults.

Config Snapshots

Point-in-time snapshots of each site's full protection setup. Roll back a bad change, or clone a known-good setup to a new site.

Notification Center

In-app alerts for security events and config changes. Stay informed without living in the dashboard.

Sensitive Data Redaction

Tokens, passwords, and personal data are automatically redacted in logs. Privacy-safe by default.

Account Protection

Built-in account lockout on failed sign-in attempts. We protect your apps from attackers — and we protect the console from them too.

Developer experience

Infrastructure-as-code,
not infrastructure-as-clickops.

Every console capability has a REST endpoint. Every service ships as a container. Every deployment has Kubernetes manifests. Your protection setup belongs in version control, and CyWAF makes that easy.

  • Full REST API — every resource under /api/v1/, versioned and stable.
  • Docker-nativedocker compose up from zero to protected.
  • Kubernetes manifests shipped in the repo — scale horizontally on any cloud or on-prem.
  • No vendor lock-in — built on open, proven technologies. Your data and rules are yours, in standard formats.
Terminal — CyWAF REST API
# Create a custom rate-limit rule via the API $ curl -X POST https://cywaf.example.com/api/v1/rate-limit-rules \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/json" \ -d '{ "domain": "api.example.com", "match": { "path": "/login", "method": "POST" }, "limit": 10, "window_seconds": 60, "action": "block" }' # Response — rule is live on all edges in < 1s { "id": "rl_2x9K", "status": "active", "applied_to": ["edge-1", "edge-2", "edge-3"], "update_time_ms": 187 }
Why trust CyWAF

No obscure magic. No vendor lock-in.

Reviewable foundations, continuous security scanning, and clear visibility into every request we protect.

Open foundations
  • Built on reviewable technologies
  • Industry-standard attack signatures
  • No secret sauce
  • Continuously updated
Continuous security
  • Automated vulnerability scans
  • Dependency auditing
  • Secret-leak detection
  • Fast update cadence
Privacy & compliance
  • Complete audit trail
  • Role-based access
  • Per-site data isolation
No lock-in
  • Clean REST API
  • Standard log formats
  • Open integration points
  • Your data, your control
Automated vulnerability scans · Dependency auditing · Secret-leak detection · Responsible disclosure
CyWAF vs other vendors

Global-grade protection, without the global-vendor friction.

The capabilities you expect from a major WAF — paired with local engineering support, flexible deployment, and pricing that actually fits MENA budgets.

Capability
CyWAF
Other vendors
Local support teamPeople who know your stack
Engineers in your timezone · response in hours
Global queue · tiered escalation
Data residencyWhere your traffic logs live
Stays in your region · MENA-hosted option
Ships across borders by default
DeploymentHow it runs in your environment
Self-host or fully managed cloud
Vendor cloud only · one shape fits all
OWASP Core Rule SetIndustry-standard signatures
Same day as OWASP publishes · plus CyRules managed set
On vendor cadence · weeks behind
AI attack explanationsUnderstand every blocked request
Built-in · automatic plain-language reasoning per request
No per-request explanations · generic AI assistant at best
Custom rule authoringWrite rules that fit your app
Visual builder on every plan · expert mode on higher tiers
Enterprise-tier only · limited expressiveness
PricingWhat you'll actually pay
Flat · region-priced · predictable bill
USD-pegged · per-request fees · surprise overages
Vendor lock-inCan you leave if you need to
Standard SecRule syntax · logs in open formats
Proprietary formats · data tied to their cloud
OnboardingFrom signup to protecting traffic
Minutes · direct help from the team that builds it
Weeks of procurement · docs-first rollout
Generalized comparison based on publicly available pricing, documentation, and customer feedback from major global WAF vendors. Your mileage may vary — we're happy to walk through a side-by-side for your specific stack.
Choose your deployment

One WAF. Three ways to run it.

Same engine, same console, same rules. You decide where it runs. Start in minutes on our cloud, keep your data in-country, or host it entirely yourself.