Guides
Plain-English WAF explainers for campus and agency teams. Start with count mode, then operate without breaking forms.
Solutions · Free security scan · Pricing · Blog
Getting started
What is WAF count mode? (and why you start there)
Count mode lets campus and agency teams put a WAF in front of production without blocking real users on day one — observe ~24 hours, then promote what's safe to block.
What's safe to block on a WAF?
Learn what's safe to block on a managed WAF. Rules start in count; Promote Copilot explains Promote, Hold, or Needs allowlist — you still click once.
Operations & false positives
WAF false positives on forms: stop blocking legitimate POSTs
Why WAFs block registration, admissions, and government forms — multipart uploads, CSRF tokens, odd field names, payment callbacks — and how count-first stopping of false positives works.
Virtual patching websites with a managed WAF
Virtual patching at the edge buys time before CMS updates land. Managed WAF rules start in count; promote what's safe to block — Copilot explains, you click.
What a WAF 403 page means (and why you start in count)
A branded 403 is what visitors see after you promote a rule to block. Count mode comes first. Promote Copilot explains what's safe — you still click once.
Platforms
Product pages: WordPress · Shopify · Magento · Drupal · Higher education · Government
Security basics
What is a WAF (Web Application Firewall)?
A plain-English explanation of what a web application firewall (WAF) is, what it protects against, and how a managed WAF works.
The OWASP Top 10, explained simply
A simple explanation of the OWASP Top 10 web application risks and how a web application firewall mitigates them.
HTTP security headers, explained
What the important HTTP security headers do — HSTS, Content-Security-Policy, X-Frame-Options, and more — and why they matter.