Pricing
You pay for volume, not features.
Every plan includes unlimited rules, full metrics and support. Pick by hits/month you expect.
Every plan includes:
- Unlimited rules
- Priority whitelist
- Under Attack mode
- Real-time metrics
- No lock-in — cancel anytime
The model
Behind, not in front.
What changes when the WAF stops being a proxy and runs inside your own application.
Traditional proxy WAF
Intercepts traffic before it reaches your server
Other WAF and CDN providers
- Requires delegating DNS and TLS termination
- WAF outage means full service outage
- Generic rules with a high false-positive rate
- Logs reflect the CDN, not real traffic
- SSL certificate management under third-party control
- Incompatible or problematic when combined with other CDNs
CoreWAF inline
Runs inside your application, no intermediaries
Your server remains the sole entry point
- No DNS changes, no infrastructure dependencies
- Fail-open by design: if it fails, traffic passes through
- Your own rules, no imposed global policies
- Metrics based on actual traffic received by your application
- Compatible with any CDN: Cloudflare, Fastly, BunnyCDN…