12 Edge PoPs Active (3.2ms)
Monitor-Only Mode

Command Center

Live platform telemetry — traffic, threats, and edge health.

24h Inspected Traffic
38.42M reqs
4,250 RPS peak
Blocked Threats (24h)
241,890 blocked
16% malicious bot traffic
BAP Validation Rate
99.8%
Ed25519 CPS Verified
P99 Edge Latency
3.2 ms
Target: <5.0ms

Real-Time Edge Traffic & Threat Stream

Live RPS breakdown across legitimate users vs. automated bot campaigns

Real Users Blocked Bot Attacks

7-Pillar WAAP Defense

Active mitigations across vectors

Headless Browser Farms Active Block
38.4M
Credential Stuffing K-Anonymity Guard
22,067
BOLA / ID Scraping PoW Soft Challenge
38,670
JA4 Fingerprint Spoofs 99.8% Caught
14,920

Auto-Discovery & Sensitivity Radar

Categorized API attack surface from live traffic

3 Shadow APIs Detected
Public
180 endpoints
Auth
92 endpoints
Admin
85 endpoints
Payment
44 endpoints
PII
8 endpoints

Compliance Posture

Automated regulatory policy coverage

96%
COMPLIANT
OWASP API Top 10 PCI DSS 4.0 GDPR Art. 32 HIPAA Audit

Live Security Incident Feed & Analyst Adjudication

Real-time security events streamed from edge Envoy PoPs with 1-click dispute feedback

Timestamp Client IP ASN / Source Threat Signature Target Endpoint Escalation Action Verdict Adjudicate

Bot & Fraud Intelligence (BAP)

Multi-layered client verification: Device Fingerprinting, JA4 TLS Signals, Proof-of-Work, and Hard Challenges.

BAP Tri-Check Sensor Engine

Verifies client hardware concurrency, screen depth, WebGL renderer, and touch event authenticity.

Headless Chromium DetectionARMED
AudioContext Fingerprint CheckARMED
Touch Event Timing VarianceARMED

Sensor Health

Live BAP ingest verdicts per client (from /sensor/health).

Last ingest
Total ingests0
Blocked0

Challenge Actions

Soft vs hard challenge + block decisions per client (from /sensor/health).

Soft challenge (PoW)0
Hard challenge (JS/CAPTCHA)0
Block (403)0
Geo/ASN verdicts

JA4 / JA4H Fingerprinting

Passive TLS Client Hello & HTTP header hash inspection. Detects Python, Go, and cURL scrapers.

Known Bad JA4 Blocklist38,400 Signatures
Cipher Suite Order AnalysisARMED
TLS Extension Anomaly DetectorARMED
Fingerprint (JA4)StatusReasonAdded

Adaptive Challenges (PoW & CAPTCHA)

Invisible client-side SHA-256 Proof-of-Work soft challenges and Turnstile/hCaptcha fallback clearance tokens.

Soft Challenge (Invisible PoW)Tier 1 Active
Hard Challenge (HMAC Token)Tier 2 Active
GoodBot rDNS ValidatorGoogle/Bing Verified

Interactive Hard Challenge CAPTCHA Sandbox

Test Turnstile/hCaptcha widgets and cryptographic HMAC clearance token generation live

Clearance Token Protocol: wgc_<base64_payload>.<hmac_sha256_signature>

Asset & API Auto-Discovery Matrix

Continuous inventory of subdomains, endpoints, semantic contract diffs, and breaking changes.

Method Path Template Sensitivity Tier Risk Exposure Spec Source Shadow API Version Challenge Actions

WAF, Policy Orchestration & Canary Engine

Configure sensitivity rules, rate limits, canary rollouts, and zero-trust service mesh access control.

Live Canary Deployment & SLO Auto-Rollback

Staged traffic shifting (25%) with automatic 0ms rollback on SLO breach

Target Version:
v2.5.0-waf-rules
Current Traffic Split:
25% Canary / 75% Base
Canary Error Rate:
0.04% (SLO limit 2.0%)
Avg Canary Latency:
24.5 ms

Zero-Trust Service Mesh & SPIFFE Identity Guard

East-west microservice authorization matrix and internal mTLS policy enforcement

Target Microservice SPIFFE Trust Domain Pattern Authorized Callers Permitted Methods Restricted Paths
payment_processor ^spiffe://cluster\.local/ns/prod/sa/.*$ order_service checkout_ui POST, GET /metrics /internal/admin
user_auth_service ^spiffe://cluster\.local/ns/auth/sa/.*$ api_gateway POST /actuator/env

Compliance & Regulatory Vault

One-click regulatory rule packs and tamper-evident audit evidence generator.

Onboarding & Cryptographic Key Management

Manage DNS delegation verification, ACME certificates, and BAP CPS sensor key rotation.

Automated Domain Pilot Onboarding Wizard

Provision new customer domain with DNS TXT challenge verification and 7-day learning baseline

Add Domain to Client

Register additional domain for existing client. Optionally enable automatic TLS setup.

Seeds one plan-clamped monitor rule per discovered endpoint (KYC approved required)

Low-KYC & Approval (Country-Wise)

Submit identity packet with country jurisdiction; admins/managers review & approve pending tasks with live sync.

Current Plan & Limits

Loading…

Pending Approvals & Sync

Country:
Loading…

BAP CPS Sensor Key Pair

Ed25519 asymmetric key pair used by client-side SensorDataBuilder to sign telemetry payloads.

Public Key Fingerprint (CPS Registry): loading…

ACME TLS Certificates

Automated Let's Encrypt TLS certificate provisioning for Path A DNS proxying.

Loading…

Enterprise Settings Dashboard

Professional grade controls for organization management, RBAC, advanced SSO, unified billing, and document synchronization.

Enterprise Settings
Loading…

Pricing

Setup

Loading…

Role‑Based Access Control

Define and assign roles to users, view permissions matrix.

UsernameNameRoleCreatedModeKYC

Advanced SSO Integrations

Configure SAML, OIDC providers, and manage federation settings.

Unified Billing

View subscription usage, invoices, and edit payment methods.

Document Sync

Create, edit, and synchronize policy documents across the organization.

Manager Console

Team, roles, and approvals for managers.

Team Members

Loading…

Pending Approvals

Loading…

My Access

Your role and what you can do.

My Role

Loading…

My Permissions

Loading…

My Client Status

Loading…

Client Protection & Endpoint Rules Setup

Configure endpoint rate limits, challenge tiers, and inspection modes according to your client plan limits.

Client Plan & Enforcement Policy
Client Default · Free Plan
Max Endpoints: 25
Rate Limit Cap: 60 req/min
Challenges: PoW / Soft

Client Endpoint Policies

Fine-tune per-route rate limits and challenge tiers. Write operations are clamped to your plan tier.

Method Path Template Rate Limit (req/min) Challenge Tier Enforcement Mode Actions
Loading client rules…

Client Policy Tester & Simulation

Verify how incoming client traffic is evaluated against your rate limits and challenges in real-time.

Admin Setup & System Settings

Global control plane configuration, dynamic feature flags, edge subsystem telemetry, and incident runbooks.

Dynamic Feature Flags

Hot-toggle real-time WAAP capabilities across edge proxies without restarts.

Loading flags…

Edge PoP Subsystems

Real-time edge cluster status and latency.

Edge Proxy Gateway 3.2ms · 12 PoPs
JA4 TLS Heuristics Engine Active (0.8ms)
Anomaly Detector & Redis Stream 0.00% Error
SPIFFE Mesh Attestation mTLS Valid

Automated Runbooks

Trigger automated incident playbooks and mitigation workflows.

Developer Docs

Endpoint reference for integrating with the WaapGuard control plane. Authenticated users only.

API Endpoint Reference

Snippets:
MethodEndpointDescriptionAuth

Quick Start

Your OpenAPI Spec
Loading…