NestServer Product

FLY Enterprise WAF

Self-hosted Web Application Firewall with reverse proxy, OWASP-grade detection, optional OpenAPI parameter and JSON validation, route learning in Reporting mode, and SOC-ready operations — on your infrastructure with full control. This page describes only what is implemented in the product code.

Reverse Proxy + SSL Decision Engine SOC Queue Explainable Blocking On-Premise False Positive Intelligence OpenAPI (optional)
This page lists only capabilities that exist in the shipped product code. Optional features (OpenAPI upload, API Security, CSP toggle, etc.) must be enabled per application in the admin portal. Full Trust Center: release notes, architecture, security & SOC docs Customer community — hub, office hours, newsletter
Latest Enhancements

Recent WAF Enhancements

Operational improvements that reduce analyst noise and sharpen multi-app visibility — without changing the decision engine architecture.

    Protect Every Application

    Reverse proxy, static sites, or redirect modes with per-app enforcement, detection-only, or reporting.

    Intelligent Detection Stack

    OWASP modules, behavioral signals, threat intel feeds, risk scoring, and virtual patches — unified in one pipeline.

    Built for SOC Teams

    Incidents, prioritized SOC queue, attack campaigns, threat hunting, and tamper-evident audit trails.

    Route Learning — Not Full App Profiling

    Nest WAF builds a baseline of legitimate application routes during Reporting mode, then uses OWASP rules and policies for payload decisions. It does not auto-learn parameters, headers, or JSON structure from traffic.

    What Reporting mode learns
      What stays rule-based (not auto-learned from traffic)
        A known route can still be blocked if a parameter value matches an attack rule (e.g. SQLi). Reporting reduces false positives on new URLs — not a guarantee of zero tuning after Protection.
        API Security

        OpenAPI Level 3 — Parameter & JSON Schema Enforcement

        Upload your OpenAPI schema manually — the WAF validates query/path parameters and JSON request bodies before the OWASP rule engine runs. Route learning still covers Method + URL only; schema enforcement is opt-in per application.

        In product when API Security + OpenAPI are enabled
          Not in product yet
            Pipeline: OpenAPI validation (step 7) → virtual patches → detection modules → OWASP rule engine (step 11).

            Clean Architecture — Each Layer Has One Job

            Fly WAF separates records, correlation, prioritization, and enforcement so your SOC workflow stays predictable.

            Component Role Decides? Changes State?
            IncidentRecord — what happened
            CampaignCorrelation — grouped attack narrative
            SOC QueuePrioritization — where to start
            Security CaseInvestigation workflow (roadmap)
            Decision EngineAllow / Block / Challenge
            Explanation LayerWhy this decision was taken
            SOC Queue does not decide, does not change state, and does not own resolved/unresolved — it only tells analysts where to start.
            Protection

            Application Protection & Edge

            Protected Applications

              SSL/TLS & Certificates

                Application Authentication

                  Reverse Proxy & Routes

                    Detection

                    Detection & Rules Engine

                    OWASP Detection Modules

                      Custom Rules & Policies

                        Behavioral Detection

                          Virtual Patches

                            Bot, Flood & App Security

                              Positive Security & API

                                Intelligence

                                Threat Intelligence & Correlation

                                Threat Intel Feeds

                                  Geo, IP Lists & Rate Limits

                                    Attack Campaigns

                                      Risk Score Engine

                                        Decision

                                        Security Decision Engine & Explanation

                                        Policy-Driven Decisions

                                          Decision Explanation Layer

                                            SOC Operations

                                            Incidents, Queue & Hunting

                                            Security Incidents

                                              SOC Queue (Advisory)

                                                Threat Hunting

                                                  Knowledge Base & SOC Engine

                                                    Operations

                                                    Dashboards, Logs & Compliance

                                                    Dashboard & Analytics

                                                      Protection & Traffic Logs

                                                        Compliance & Reports

                                                          SIEM Export & Audit

                                                            Administration

                                                            Platform Admin & Deployment

                                                            RBAC & Multi-Tenant

                                                              Deployment & Tenant Reset

                                                                Ready to protect your applications?

                                                                Request a demo to see FLY Enterprise WAF live — reverse proxy, explainable blocking, and SOC queue in action.

                                                                Request WAF Demo