Open Source & Self-Hosted

Enterprise-Grade Protection
For Your Web Applications

WafWay is a self-hosted Web Application Firewall that protects against SQL injection, XSS, OWASP Top 10 threats, and L7 DDoS attacks with interactive challenge-response verification. Deploy in minutes, not weeks.

https://yoursite.com Verify you are human This check protects against automated attacks. I am human Click the checkbox to continue PoW Solve Click Verify Pass Grant Redirect PROTECTED BY WAFWAY SHA-256 Proof-of-Work
100% Attack Detection
<1ms Latency Impact
704+ Attack Patterns
L7 DDoS Protection
Verified Performance

100% Attack Detection Rate

Independently tested against 704+ attack payloads including SQLMap, Burp Suite, OWASP ZAP variants, and cutting-edge evasion techniques. Every single attack blocked.

100% Blocked

704 of 704 Attacks Blocked

Comprehensive security testing with real-world attack payloads from popular penetration testing tools and cutting-edge evasion techniques.

SQL Injection
184/184 100%

Union, Boolean, Time-based, Stacked queries, SQLMap payloads

XSS Attacks
128/128 100%

Reflected, Stored, DOM-based, Polyglots, Encoding bypasses

XXE Attacks
53/53 100%

External entities, Parameter entities, Billion laughs, OOB

Command Injection
84/84 100%

Shell commands, Reverse shells, Bypass techniques

Path Traversal
73/73 100%

Directory traversal, Null bytes, Encoding evasions

LFI/RFI
87/87 100%

PHP wrappers, Log poisoning, File inclusion

SSRF
69/69 100%

Cloud metadata, Internal networks, Protocol smuggling

Tested with payloads from:

SQLMap Burp Suite OWASP ZAP Nikto Nmap DirBuster Acunetix Custom Payloads
Next-Gen Protection

Cutting-Edge Attack Detection

26 advanced evasion techniques tested. 100% blocked.

Unicode-Aware Detection

  • Overlong UTF-8 encoding attacks
  • BOM manipulation blocked
  • Zero-width space obfuscation
  • Full-width character variants

Modern Framework Protection

  • ES6 template literal XSS
  • Angular expression injection
  • String.fromCharCode bypasses
  • HTML mutation XSS attacks

Advanced Protocol Handling

  • data: protocol URI attacks
  • GraphQL query introspection
  • IDN/Punycode domain attacks
  • Alternative protocol SSRF

Multi-Layer Encoding Defense

  • Null byte + Unicode injection
  • Recursive URL encoding
  • Operator obfuscation (XOR)
  • HTTP parameter pollution
26 Advanced Attacks
0% Success Rate
100% Detection Coverage
Features

Complete Protection Suite

Everything you need to secure your web applications, from basic threat detection to advanced compliance reporting.

SQL Injection Protection

OWASP CRS-inspired detection with 45+ patterns covering union, boolean, time-based, and stacked query attacks.

XSS Prevention

Comprehensive cross-site scripting detection including reflected, stored, and DOM-based attacks with encoding bypass detection.

Secure Authentication

Industry-standard bcrypt password hashing with cryptographically secure token generation using crypto/rand.

New

Persistent Storage

SQLite-backed storage for rules, attack logs, and traffic analytics with automatic aggregation and data retention.

New

Custom Rules Engine

Create, update, and delete custom WAF rules with database persistence. Define patterns, actions, and priorities.

New

Real-time Analytics

Time-series traffic data, top paths analysis, and attack logging. Export data via REST API for external dashboards.

New

Geo Blocking

Block or allow traffic by country, detect VPNs, Tor exit nodes, and datacenter IPs with MaxMind GeoIP integration.

Bot Detection

Identify and block malicious bots while allowing legitimate crawlers. Includes DNS verification for search engines.

Rate Limiting

Three-tier rate limiting: allow, challenge, or block. Configurable soft threshold triggers human verification before hard blocking.

L7 DDoS Challenge

Interactive "Verify you are human" click-to-verify challenge with SHA-256 proof-of-work. Stops automated attacks while letting real users through in seconds.

New

Distributed State (Redis)

Share rate limits, challenge passes, IP bans, and session state across multiple WAF instances via Redis. ElastiCache compatible.

New

PostgreSQL Support

Enterprise-scale persistent storage with PostgreSQL and connection pooling. RDS compatible. SQLite retained as default for smaller deployments.

New

Security Headers

Automatic HSTS, Content-Security-Policy (CSP), and CORS whitelist configuration. Full compliance with security best practices.

New

HSTS Enforcement

HTTP Strict Transport Security with configurable max-age, includeSubDomains, and preload directives for HTTPS enforcement.

New

Content Security Policy

Comprehensive CSP configuration with 10+ directives including script-src, style-src, frame-ancestors, and report-only mode.

New

Response DLP

Inspects response bodies for credit card numbers (Luhn-validated), SSN, API keys, and stack traces. Masks or blocks data leaks in real-time.

New

Request Smuggling Protection

Detects CL.TE, TE.CL, and TE.TE attack variants. Rejects ambiguous Content-Length and Transfer-Encoding conflicts at the protocol level.

New

Good Bot rDNS Verification

Verifies claimed good bots (Googlebot, Bingbot, Yandex) via reverse DNS + forward DNS confirmation. Blocks spoofed bot user-agents.

New

Virtual Patching

Deploy CVE-specific regex rules via admin UI without code changes. Hot-reloaded within 5 seconds. Block zero-day exploits before vendor patches ship.

New

WebSocket Support

Transparent WebSocket passthrough with per-IP connection rate limiting and configurable max connection duration. No impact on real-time apps.

New

IP Management Portal

Admin UI to manage IP whitelist and blacklist at runtime. Add, remove, and monitor IPs with instant enforcement — no restarts needed.

New

Path-based Access Rules

Configurable path whitelist and blacklist with glob pattern matching. Block access to sensitive paths like /.env, /.git, /wp-admin, and more.

New
L7 DDoS Protection

Interactive Human Verification

When suspicious traffic is detected, WafWay presents an interactive challenge page. A SHA-256 proof-of-work runs silently in the browser, then the user clicks a checkbox to confirm they're human. Real users pass in seconds. Bots and automated scripts cannot.

<3s
Human solve time
100%
Bot block rate
30min
Pass validity
https://yoursite.com Verify you are human This check is required to protect against automated attacks. Verification complete Redirecting... PoW Solve Click Verify Pass Granted Redirect PROTECTED BY WAFWAY SHA-256 Proof-of-Work
Enterprise

Advanced Security Features

L7 DDoS Challenge
Redis Distributed State
PostgreSQL & SIEM
API Protection
Compliance Reports
Multi-Region DC/DR
HSTS & CSP Headers
24/7 Premium Support
CORS & Clustering
How It Works

Deploy in 5 Minutes

WafWay sits between the internet and your application, inspecting every request before it reaches your servers.

Internet Traffic
WafWay Inspect, Challenge & Filter
Your Application
1

Download

Single binary, no dependencies. Works on any Linux server.

2

Configure

Point to your backend application and customize protection levels.

3

Deploy

Run as a systemd service and start blocking threats instantly.

Deploy Anywhere

Cloud-Native, Self-Hosted

Single binary. Zero dependencies. Deploy on any cloud, any VM, any container — your infrastructure, your data.

AWS

EC2, ECS, EKS

  • Deploy on EC2 or Fargate container
  • ALB/NLB for SSL termination
  • VPC peering to app subnets
  • ElastiCache (Redis) for HA
  • RDS PostgreSQL for multi-instance
  • Graviton (ARM64) support
Deploy on AWS

Docker & Kubernetes

Containers, Helm, K8s Ingress

  • Lightweight Alpine-based Docker image
  • Docker Compose for quick setup
  • Kubernetes DaemonSet or Deployment
  • Config via mounted volume or ConfigMap
  • Horizontal scaling with Redis state
  • Health endpoint for readiness probes
Deploy on K8s

Integration Patterns

Reverse Proxy Mode

Most common. WafWay sits between your load balancer and application servers.

Internet → Load Balancer (SSL)
  → WafWay :8081 (inspect)
    → App Server :3000

Sidecar Mode

WafWay runs on the same VM as your app. Simplest setup for single-server deployments.

Internet → Nginx (SSL :443)
  → WafWay :8081 (inspect)
    → localhost:3000 (app)

High Availability

Multiple WafWay instances sharing state via Redis + PostgreSQL for zero-downtime.

LB → WafWay-1 ↔ Redis
LB → WafWay-2 ↔ Redis
    → App Pool (N servers)
📦

Single Binary

~30MB compiled Go binary. No Java, no Node.js, no runtime. Just copy and run.

🔒

Your Data, Your Servers

Zero data sent to third-party clouds. Complete data sovereignty for compliance.

🌐

Multi-Domain Routing

One WafWay instance protects 50+ domains with host-based backend routing.

5-Second Hot Reload

Config changes, virtual patches, and route updates applied without restart.

The WafWay Advantage

Why Choose WafWay?

Built for modern security challenges with uncompromising protection

<1ms

Zero Latency Impact

Lightning-fast request processing that your users won't even notice. Built with Go for maximum performance.

100%

Your Data, Your Servers

Complete data sovereignty. No third-party access. Your traffic never leaves your infrastructure.

1

Single Binary Deploy

No dependencies, no containers required. Just download and run. Deploy in under 5 minutes.

7

Comprehensive Coverage

Full OWASP Top 10 protection across 7 attack categories including cutting-edge evasion techniques.

Zero

No Vendor Lock-in

Self-hosted on your infrastructure. No per-request fees, no bandwidth charges, no data sent to third parties.

L7 DDoS Protection with Interactive Human Verification
Modern Unicode & Encoding Attack Detection
Redis Distributed State for Multi-Instance Deployments
Real-time Dashboard, Analytics & SIEM Integration
HSTS, CSP, CORS Security Headers & Compliance Reporting
About Us

We Are ConceptGood Consultants

ConceptGood Consultants is an AI Product Development and Consulting firm based in Pune, India. We specialize in building intelligent solutions that transform how businesses operate.

Our portfolio includes ConceptGood (AI innovation platform), RaysHR (AI-powered HRMS), ArchitectGood (AI architecture platform), Crew4J (Java AI agent framework), and WafWay (Enterprise WAF). Each product represents our commitment to practical AI innovation.

Beyond products, we offer AI consulting services to help enterprises navigate their AI transformation journey — from strategy to implementation.

2025 Founded
5 Products
AI First Approach
Global Reach

Innovation First

We leverage cutting-edge AI to solve complex business challenges.

Client Success

Your success is our success. We go above and beyond for our clients.

Excellence

We strive for excellence in every product and service we deliver.

Quality

Enterprise-grade quality in everything we build.

Start Protecting Your Applications Today

Join thousands of teams using WafWay to block web attacks.