İçeriğe geç
Tres Teknoloji
Services / Network / Web Application Firewall WAF, bot management and virtual patching

Protect your application against OWASP attacks

Put a managed firewall (WAF) in front of your web application; stop OWASP Top 10 attacks, malicious bots and zero-day exploits without touching the application.

Managed rule set
Highlights
OWASP Top 10 Managed rule set
Bot management Good/bad bot distinction
Virtual patching Protection without code changes
Domain/month Predictable pricing
Ideal for Blocking SQL injection and XSS Authentication and API abuse Content scraping and inventory bots Zero-day protection before patching
Pricing

A quote for your needs

The exact price is set by your needs and scale. Get a quote or schedule a meeting with your account manager.

Get a quote for a custom configuration
Plan Requests/month Rule set Bot management Virtual patching Price
waf.starter 2 million Managed Basic Included On quote
waf.pro 20 million Managed + custom Advanced Included On quote
waf.business 100 million Managed + custom Advanced + ML Priority On quote
waf.enterprise Custom Custom Dedicated Dedicated On quote
Prices exclude VAT and are quoted based on your needs.
Features

Protection that works without touching a line of code

Managed OWASP rules

A continuously updated rule set against Top 10 attacks such as SQL injection, XSS and command injection.

Virtual patching

When you cannot yet patch a known vulnerability, block the attack instantly at the WAF layer.

Bot management

Let good bots (search engines) through and remove scraper and abuse bots with fingerprinting and behavior.

Rate limiting

Stop brute force and abuse with request rate limits per IP, session or endpoint.

Custom rules

Define match and block rules specific to your own application from the panel.

Audit and reporting

Blocked requests and triggered rules flow to Logchase; compliance auditing gets easier.

S.S.S.

Frequently asked questions about Web Application Firewall

No. Traffic is routed to the WAF layer through your domain; no code or server change is needed. You can start rules in monitor (log) mode and switch them to blocking once you are confident.

When a vulnerability is found in a library, testing and releasing a permanent patch takes time. Virtual patching blocks requests targeting that vulnerability at the WAF layer instantly, protecting you until you apply the real patch.

You first run new rules in monitor mode, which only logs, to see whether they mistakenly block legitimate traffic; then you switch to blocking mode with confidence. Engineer support helps with fine-tuning.

Protection against application-layer (L7) abuse is within the WAF scope. For volumetric (L3/L4) attacks we recommend running it together with the DDoS Protection service on the same edge network.

You just route your domain's traffic to the WAF layer; no code change is needed. You can run rules in monitor mode first and switch to blocking once you are confident.

With virtual patching we block requests targeting a known vulnerability at the WAF layer instantly, until you apply the permanent patch; this way you are not left unprotected during the patch window.

Yes. The WAF, DDoS protection and CDN can be combined on the same edge network; you manage both speed and multi-layer security from one place.

Customer reviews

What do teams using Web Application Firewall say?

“After starting the WAF in monitor mode and clearing the false positives, we switched to blocking; SQL injection attempts no longer reach the application at all.”
Barış Çelik Security Engineer · Aksu Fintek
“When a critical vulnerability appeared in a library we closed it instantly with virtual patching; we applied the permanent patch later at our leisure. We changed nothing on the code side.”
DY Deniz Yıldız Software Architect · Pusula Ödeme
“We eliminated content-scraping bots with bot management; our server load and fake traffic dropped noticeably. The fixed per-domain price made budgeting easy.”
SK Selin Kara Technical Director · Vadi Medya
“After switching to Web Application Firewall (WAF) we measured the performance difference clearly in our application response times.”
ZA Zeynep Acar Operations Manager · Filo Takip
“We can reach the support team even in the middle of the night; response times are genuinely as fast as promised.”
EA Emir Aslan Senior Systems Specialist · Verimli Bulut
“They gave us free consulting before the migration; together we worked out how much of each resource we needed.”
SA Selin Aydın Systems Administrator · Anadolu Lojistik
“The contract and SLA terms are clear; we built a transparent relationship from the start, not a negotiation.”
İY İpek Yıldırım Product Manager · Sigorta Bahçesi
“The price/performance balance came out better than overseas providers, and we are invoiced in TRY.”
ZA Zeynep Acar Operations Manager · Filo Takip
Related services
Cloud Server Live in seconds $0.0123/hr
Bare Metal Unshared physical hardware On quote
Kubernetes Managed Kubernetes $9.00/mo
Serverless Scales to zero On quote