Web Application Firewall, end to end
We have run WAFs in production in front of Umbraco for years, our own GreenStack platform included. So we have met the rule that breaks the backoffice whenever an editor pastes an image, the geo block that quietly shut a German manufacturer's regional sales team out of their own CMS, and the bot rule that turned a legitimate uptime monitor into a stream of 03:00 false positives. Turning a WAF on is trivial; stopping it blocking the people you want to serve is the job.
Platforms we work with routinely: Cloudflare WAF and Bot Management, Azure Front Door WAF, Azure Application Gateway WAF, and on-premise appliances where they are required. The work spans custom rule authoring, OWASP Core Rule Set tuning, rate limiting on authentication and form endpoints, geo and ASN policy, bot management, and structured review of WAF events so signal stays clear of noise. On the Umbraco side we cover backoffice path protection, surface controller exceptions, media URL allow-lists, and the login and password-reset endpoints that attract most of the automated traffic.
A security review that has just made a WAF mandatory, one that has gone two years without tuning, or a need for someone accountable for the rules and alerts so your developers are not: we will scope it, configure it and run it.
The reviews are about the same things, over and over:
speed of response, depth of expertise, and named engineers who know the platform.
What Our Customers Say:
Let's Talk
Tell us what you are running and what is in front of it today, and we will come back with a scoping conversation. No obligation and no automated funnel.