Trust Center

Honest documentation for FLY Enterprise WAF

Technical blog, release notes, architecture, and security docs — written for security teams, auditors, and enterprise buyers. We describe only what exists in the shipped product code.

FLY Enterprise WAF is not open source. This Trust Center is for transparency and evaluation — not a developer community or public code repository.
Technical Blog

Honest technical articles

No inflated marketing — explanations of how the WAF actually behaves in code.

All 5 articles
2026-06-10

Route learning vs OpenAPI validation — what the WAF actually does

Reporting mode learns Method + URL only. OpenAPI parameter and JSON enforcement is a separate, opt-in layer when API Security is enabled.

Read article
2026-06-10

Static-asset SQL alerts — false positive labeling, not disabled protection

How scoped CRS skip on GET/HEAD .js/.css works, why API paths stay fully inspected, and how the UI labels likely false positives.

Read article
2026-06-12

Reporting → detection-only → Protection — a safe rollout playbook

Phased application modes before enforcement — with honest limits on what route learning covers.

Read article
2026-06-12

OpenAPI validation — setup, pipeline position, and honest limits

API Security step 7 before CRS; manual upload; no $ref; no auto-discovery.

Read article
2026-06-12

SOC Queue vs Decision Engine — who decides what

Queue prioritizes — only the Decision Engine enforces Allow / Block / Challenge.

Read article

Where is this hosted?

All Trust Center pages live on the NestServer website under /trust.html and /trust/. Deploy by uploading the entire website/ folder to your web host (same as the main marketing site). Internal engineering docs stay in the product repository under docs/waf/ — not all are published publicly.

Security contact

Report vulnerabilities responsibly to it@softecinternational.com. Do not test against customer environments without written authorization.