Security and support

The WAF that tells you what's safe to block — and who runs it, what we log, and how to reach a human. 150/site/month after a 14-day trial. Rules start in count. Counted is not blocked. Nothing moves to block until you click Promote.

Who is behind this

ProtectMyWebsite, a sole proprietorship. Email support@wafcybersecurity.com — that is the contact on the terms, privacy policy, and SLA. Those terms are governed by the laws of North Carolina.

The legal name on the Terms is ProtectMyWebsite, a sole proprietorship. Questions go to support@wafcybersecurity.com.

What sits in front of the site

AWS WAF on Amazon CloudFront. We provision the certificate, the Web ACL, and the distribution. Your origin, hosting, and code stay where they are. You change DNS, or you ask us to coordinate it.

Promote Copilot reads your count window and explains what's safe to promote — you still click once. It never auto-blocks.

What we log

Sensitive headers, including authorization and cookie values, are redacted before any request is logged. We keep request metadata — IP, time, path, method, country, and which rule matched — to show attacks and traffic.

Payments go through Stripe. We do not store your full card number. The privacy policy is the full list, including subprocessors (AWS, Stripe, Amazon SES, and optional Google or Apple sign-in).

Sign-in

Passwords are hashed. You can turn on an authenticator app (a 6-digit code, plus recovery codes) from the account page. A workspace can require that authenticator for owners and admins before they manage sites. It is not on for every new account until you or that workspace enable it.

Support

Email support@wafcybersecurity.com. When you ask us to change DNS for you, concierge is typically about one business day once zone access is clear. That is not a clock-hour support SLA, and there is no public status page for customer edges.

Self-serve billing is a card at Stripe checkout. Cancel before the 14-day trial ends and you won't be charged. Campus teams who need an invoice use Campus Estate — Mac invoices. That is not the $150 checkout.

Uptime

99.9% of in-scope minutes each calendar month for sites that are Live, with a service credit if we miss it. Below 99.9% but at least 99.0%: 10% of that site's monthly fee. Below 99.0% but at least 95.0%: 25%. Below 95.0%: 50% (the cap). Credits go on the next invoice for that site, not cash. Email support@wafcybersecurity.com within 30 days after the month ends (UTC). Late requests may be denied.

The SLA does not cover your origin, DNS or registrar mistakes, or volumetric attacks above the included traffic allowance. It is not a promise that every attack is stopped. There is no public status page for customer edges.

What we do not claim

  • We do not claim SOC 2, ISO 27001, FedRAMP, PCI DSS, or any other compliance certification.
  • No customer logos, testimonials, or usage statistics — there is not a public customer list.
  • Nothing blocks until you click Promote. Count mode is not a silent block.
  • No 100% uptime. The published contact is email; we do not publish a phone number.
  • The scan is a passive look at headers, TLS, and whether a shield is visible. It is not a penetration test.

Report a vulnerability

Email support@wafcybersecurity.com. The machine-readable file is /.well-known/security.txt.