The firewall that stands in front of your application
Stop OWASP Top 10 attacks, bot traffic and application-layer DDoS before they reach your application. Live within minutes with a DNS change.
Until you fix the code, the vulnerability stays exposed
When a vulnerability is reported, the patching process can take weeks, and during that time the application is defenseless. With virtual patching, NetWaf closes the gap without touching the code side, so your team can plan the fix at ease.
Block attacks such as SQL injection, XSS, RCE and path traversal with a ready-made rule set.
Close a known vulnerability at the WAF layer without changing the application code.
Let good bots (search engines) through and stop scraper and credential-stuffing bots.
Define request limits per IP, session or endpoint.
It watches traffic for the first week and suggests rules; you decide what to block.
Blocked requests flow into the SIEM; incident analysis is done on one screen.
Integrations
It runs as a reverse proxy; it does not matter where your application is hosted. It can be on the Tres cloud, in your own data center or with another provider.
Compliance
Pricing
Pricing is based on the number of domains you protect, your traffic and the management level (you manage it or we manage it). We prepare a quote to fit your needs.
Pricing tailored to your needs
We prepare a custom quote based on your usage volume and requirements, and get back to you within a few minutes.
Get a quoteNetWaf — frequently asked questions
No. NetWaf runs as a reverse proxy; you only need to point your domain's DNS record to NetWaf. No code, server or architecture change is required, and deployment takes minutes.
OWASP Top 10 attacks such as SQL injection, XSS, remote code execution and path traversal are blocked before reaching the application with a continuously updated ready-made rule set. You can also write rules specific to your own application.
Yes. Virtual patching lets you close a known vulnerability by blocking it with a rule at the WAF layer, without touching the application code. While your development team plans the permanent fix, the vulnerability is not left exposed.
For the first week NetWaf only watches your traffic in learning mode and suggests rules; you turn on blocking. This keeps the false positive rate at the 0.01% level and does not interrupt the real user flow.
No. NetWaf verifies and lets through good bots (search engines such as Google and Bing); it stops malicious bots that scrape, do credential stuffing and scan inventory.
Yes. NetWaf is independent of where your application is hosted; it can be on the Tres cloud, in your own data center or with another provider. It receives traffic at the front, scrubs it and forwards it to your backend server.
It meets PCI DSS's web application firewall requirement (Requirement 6.6). Blocked requests are logged and can be reported for audit; with the Logchase integration you perform incident analysis on one screen.
NetWaf counters seemingly legitimate HTTP requests sent to exhaust the application (L7 DDoS) with rate limiting and behavioral analysis. Volumetric network-layer attacks, meanwhile, are absorbed by the scrubbing infrastructure in front of it.
What teams using NetWaf say
Let us monitor your application free for a week
In learning mode we analyze your traffic and report which attacks are coming. Without turning on blocking — just see them.