An application firewall with analysts behind it.

Managed WAF delivered with our partners Cloudflare and Fortinet — rules tuned to your apps and updated by the SOC when threats change, not when you remember.

Cloudflare & FortinetSOC-tunedBot & rate controls
Capabilities

Protection that keeps current

Always-on security that adapts to new threats so you stay ahead, not behind.

Tuned rule setsOWASP core rules adjusted to your traffic — protection without false-positive storms.Exceptions worked out
Bot managementScrapers and credential stuffers filtered before they reach the app.Good bots in, bad out
Rate controlsPer-route limits calm abusive clients automatically.
Abuse throttled
SOC updatesEmerging-threat rules pushed by analysts, with change notes.
Rules follow threats
OWASP coverageTop-10 categories enforced in blocking mode.
The checkbox, actually met
API protectionSchema validation and method controls for APIs.
APIs get armour too
Virtual patchingRules shield known CVEs while you schedule fixes.
Protected before patched
TLS inspectionEncrypted traffic inspected at the edge.
No blind spots
Incident reportingBlocked events and tuning history reported monthly.
Evidence for audits
False-positive disciplineTuned tiers rehearse exceptions per app before enforcement.
Users never wrongly blocked
Delivered with partners

Partnered with Cloudflare and Fortinet

The WAF service is built on platforms from our security partners — enforced at Cloudflare's global edge or on Fortinet FortiWeb inside your sovereign tenancy — and run, tuned and watched by our SOC.

CloudflareTechnology partner
Edge WAF · Bot management · DDoS
Enforced at the global edge

Attacks are absorbed at Cloudflare's anycast network before they ever reach your tenancy — managed rule sets, bot filtering and DDoS protection switched on by pointing DNS at the edge.

Cloudflare managed + OWASP rule sets in blocking mode
Bot management, rate limiting and API Shield
DDoS absorption across 300+ global locations
Best for public web apps, APIs and global audiences
FortinetTechnology partner
FortiWeb · In-region appliance
Sovereign, inside your tenancy

FortiWeb virtual appliances run inside your YallaCloud regions — ML-based anomaly detection and virtual patching while inspected traffic never leaves the jurisdiction.

ML anomaly detection beyond signature matching
Virtual patching shields known CVEs at the edge of the app
In-region HA pairs — traffic stays sovereign
Best for regulated and data-resident workloads
CloudSouqThe YallaCloud marketplace
Explore the plans in CloudSouq
Edge and in-region WAF plans for both platforms are listed in CloudSouq — compare inclusions, sizes and bundles, all inside your one flat fee.
Two ways to run it

Per application, or estate-wide

Both use SOC-maintained rule sets. The difference is scope.

Per ApplicationNamed appsPolicies attached to specific applications, each tuned to its own traffic and release cadence.
Tuning that follows the app
Clear ownership per service
Straightforward compliance mapping
Best for:A handful of critical apps
Explore Per Application plans
OR
Estate-wideEverything publishedEvery published endpoint inspected under a common baseline, with per-app exceptions where needed.
Nothing published without inspection
Common baseline, local exceptions
One posture report for the estate
Best when:New endpoints appear often
Explore Estate-wide plans
Who decides, who runs it

What each group gets from WAF

Four groups shape a cloud decision. Pick the one you belong to — the platform reads differently from each seat.

Someone is watching the front door

Application attacks are met by a monitored service rather than a device somebody configured two years ago.

GovernedSovereignPredictable

FAQs

Who maintains the rules?
Our SOC maintains the managed rule sets on both Cloudflare and FortiWeb; tuning depth depends on the policy tier you choose.
Cloudflare or Fortinet — which do we pick?
Cloudflare Edge when reach, DDoS absorption and time-to-enable matter most; FortiWeb In-Region when inspected traffic must stay inside the jurisdiction. Many estates run both — edge for public apps, in-region for regulated ones.
Will it block legitimate traffic?
That is what tuning is for — the Tuned tiers work exceptions out per application before full enforcement.
Can it protect APIs?
Yes, including schema validation and rate limiting on Tuned Plus.
How does it attach to our apps?
At the Layer 7 load balancer or CDN — or by pointing DNS at the Cloudflare edge — so there is nothing to install in the application itself.
Do we get reporting for audits?
Yes — blocked-event summaries, tuning history and incident reports on a monthly cycle.
How is the flat fee different from public cloud pricing?
Everything inside the plan you opt for is included — no additional charge for the components that make it up. Public clouds meter each component on consumption, so the bill moves with usage. Here the plan is reserved for you and the figure you agreed is the figure you pay.
Can we drive it from Terraform and CI?
Yes. Every operation is exposed through the REST API, CLI and a maintained Terraform provider, with scoped API keys per team. If the console can do it, your pipeline can do it.
How do limits and quotas work?
Quotas are yours to shape — carve capacity per team or project and delegate inside it. Hard ceilings are a conversation, not a wall; the estate re-baselines at thresholds you approve.
Better together

Build more around every protected application.

Connect Managed WAF to the platform services that keep every application available, trusted and observable.

At the core
Managed WAF

Application filtering becomes a complete defence when delivery, network protection, endpoint security and operations work around it.

InspectFilterProtectObserve
One application defence layer
ApplicationTrafficProtectionVisibilityEvidence
Noura
Noura — AI Cloud Experience Guide

Two ways Noura gets you moving

Choose the way that fits you best — Noura makes every step simple.

Not sure where to start?
Start the conversation

Describe the workload in plain language — Noura works out the tiers, sizes and protection with you.

Plain language input
Smart sizing & protection
No commitment. Just clarity.
Talk to Noura
Want to see it working?
Experience it in the marketplace

Explore CloudSouq experiences built on these services — see WAF working inside real solutions before you commit to anything.

Try real solutions
See it work in action
Commit with confidence
Explore CloudSouq
Noura is your guide at every stepfrom first question to final success.Intelligent
Guidance
Secure &
Trusted
Human
Simplicity