All products
Application protection

Hexa WAF

Hexa WAF evaluates inbound HTTP requests before they reach the origin. It combines the managed rule catalog with customer-defined allow, log, and block rules.

Signature capability
Managed + custom WAF policies

This capability is backed by the Hexa Shield control plane and reverse-proxy architecture described in the project documentation.

Managed rule catalog for common application-layer attack indicators

Custom allow, log, and block rules

Per-domain WAF enable/disable controls

Security-event visibility for matched requests

Immediate configuration invalidation across proxy nodes through Redis

How it works

Protection in a clear request flow.

Each product is managed from the same Hexa Shield account and domain model instead of requiring separate control panels.

  1. 1

    Traffic reaches the Hexa Shield proxy

  2. 2

    Managed WAF rules inspect the request

  3. 3

    Customer custom rules are evaluated

  4. 4

    Matched actions are logged or enforced

  5. 5

    Allowed traffic continues to the customer origin