Onboarding
You add a site. We stand up a certificate, a WAF, and a CloudFront edge. You point DNS — or you ask for concierge DNS. Rules start in count.
Add a site
From the dashboard you add a domain and the origin that already hosts it (protocol and host). The product does not move your site. It puts an edge in front of the origin you name.
A new site turns these managed groups on in count: Common attacks (OWASP), Known exploits, SQL injection, Malicious IP blocking. Other groups stay off until you add them. Account takeover and account-creation fraud need a login or registration path before they can run, and they are not in that default set. Application DDoS protection is not on by default.
The WebACL budget is 1,500 WCU. The dashboard shows the running total. Not every group can be on at once.
What “live” means
The site page walks a fixed set of states: Not started, Provisioning, Waiting for DNS, Certificate pending, Live — traffic is flowing, Live — no traffic yet, and Needs attention.
- Not started: the shield has not been requested. DNS comes after it is up.
- Provisioning: the certificate, WAF, and CloudFront edge are being created. There is no DNS change for you yet.
- Waiting for DNS: CloudFront is ready, and the hostname does not point at it yet. Add the record we show, or finish nameserver delegation, then recheck.
- Certificate pending: we see the validation record and the certificate is not issued yet. The page says this is usually a few minutes, sometimes up to 30, and that no further DNS change is needed for that step.
- Live — traffic is flowing: requests are reaching CloudFront. Rules are in count.
- Live — no traffic yet: DNS points at CloudFront, and the published series shows no requests, or CloudWatch has not confirmed them. A missing series is not confirmed. It is not zero.
- Needs attention: setup did not finish. Retry does not change DNS and does not block anything.
The page rechecks on its own. Recheck is there if you want to ask again. If the checker itself cannot be reached, the page says so and does not treat that as a DNS match.
After the edge is up
A first-run card names the single next step (stand up the shield, finish DNS, or review Promote Copilot) and an estimate. You can dismiss it. A new action shows the card again.
Shield-ready mail is one email when the edge is up, with the DNS step or Promote Copilot. It is not repeated, and it does not change WAF mode.
Count mode is the rest of the first day. Copilot will not say Promote until the 24-hour watch window closes, and only when the evidence in the decision table is complete. You still click.
Concierge
You can connect Cloudflare or GoDaddy and publish the records we show, paste the records at any DNS host, or request concierge setup. The dashboard says a specialist will email you within one business day to handle concierge. That note is a request, not a claim that the site is already live.