Honest documentation for FLY Enterprise WAF
Technical blog, release notes, architecture, and security docs — written for security teams, auditors, and enterprise buyers. We describe only what exists in the shipped product code.
Honest technical articles
No inflated marketing — explanations of how the WAF actually behaves in code.
All 5 articlesRoute learning vs OpenAPI validation — what the WAF actually does
Reporting mode learns Method + URL only. OpenAPI parameter and JSON enforcement is a separate, opt-in layer when API Security is enabled.
Read articleStatic-asset SQL alerts — false positive labeling, not disabled protection
How scoped CRS skip on GET/HEAD .js/.css works, why API paths stay fully inspected, and how the UI labels likely false positives.
Read articleReporting → detection-only → Protection — a safe rollout playbook
Phased application modes before enforcement — with honest limits on what route learning covers.
Read articleOpenAPI validation — setup, pipeline position, and honest limits
API Security step 7 before CRS; manual upload; no $ref; no auto-discovery.
Read articleSOC Queue vs Decision Engine — who decides what
Queue prioritizes — only the Decision Engine enforces Allow / Block / Challenge.
Read articleWhere is this hosted?
All Trust Center pages live on the NestServer website under /trust.html and /trust/. Deploy by uploading the entire website/ folder to your web host (same as the main marketing site). Internal engineering docs stay in the product repository under docs/waf/ — not all are published publicly.
Security contact
Report vulnerabilities responsibly to it@softecinternational.com. Do not test against customer environments without written authorization.