FLY Enterprise WAF
Self-hosted Web Application Firewall with reverse proxy, OWASP-grade detection, optional OpenAPI parameter and JSON validation, route learning in Reporting mode, and SOC-ready operations — on your infrastructure with full control. This page describes only what is implemented in the product code.
Recent WAF Enhancements
Operational improvements that reduce analyst noise and sharpen multi-app visibility — without changing the decision engine architecture.
Protect Every Application
Reverse proxy, static sites, or redirect modes with per-app enforcement, detection-only, or reporting.
Intelligent Detection Stack
OWASP modules, behavioral signals, threat intel feeds, risk scoring, and virtual patches — unified in one pipeline.
Built for SOC Teams
Incidents, prioritized SOC queue, attack campaigns, threat hunting, and tamper-evident audit trails.
Route Learning — Not Full App Profiling
Nest WAF builds a baseline of legitimate application routes during Reporting mode, then uses OWASP rules and policies for payload decisions. It does not auto-learn parameters, headers, or JSON structure from traffic.
What Reporting mode learns
What stays rule-based (not auto-learned from traffic)
OpenAPI Level 3 — Parameter & JSON Schema Enforcement
Upload your OpenAPI schema manually — the WAF validates query/path parameters and JSON request bodies before the OWASP rule engine runs. Route learning still covers Method + URL only; schema enforcement is opt-in per application.
In product when API Security + OpenAPI are enabled
Not in product yet
Clean Architecture — Each Layer Has One Job
Fly WAF separates records, correlation, prioritization, and enforcement so your SOC workflow stays predictable.
| Component | Role | Decides? | Changes State? |
|---|---|---|---|
| Incident | Record — what happened | ❌ | ✅ |
| Campaign | Correlation — grouped attack narrative | ❌ | ✅ |
| SOC Queue | Prioritization — where to start | ❌ | ❌ |
| Security Case | Investigation workflow (roadmap) | ❌ | ✅ |
| Decision Engine | Allow / Block / Challenge | ✅ | ❌ |
| Explanation Layer | Why this decision was taken | ❌ | ❌ |
Application Protection & Edge
Protected Applications
SSL/TLS & Certificates
Application Authentication
Reverse Proxy & Routes
Detection & Rules Engine
OWASP Detection Modules
Custom Rules & Policies
Behavioral Detection
Virtual Patches
Bot, Flood & App Security
Positive Security & API
Threat Intelligence & Correlation
Threat Intel Feeds
Geo, IP Lists & Rate Limits
Attack Campaigns
Risk Score Engine
Security Decision Engine & Explanation
Policy-Driven Decisions
Decision Explanation Layer
Incidents, Queue & Hunting
Security Incidents
SOC Queue (Advisory)
Threat Hunting
Knowledge Base & SOC Engine
Dashboards, Logs & Compliance
Dashboard & Analytics
Protection & Traffic Logs
Compliance & Reports
SIEM Export & Audit
Platform Admin & Deployment
RBAC & Multi-Tenant
Deployment & Tenant Reset
Ready to protect your applications?
Request a demo to see FLY Enterprise WAF live — reverse proxy, explainable blocking, and SOC queue in action.
Request WAF Demo