OWASP Top 10 Protection
OWASP Core Rule Set against SQLi, XSS, RCE, LFI/RFI, path traversal and protocol attacks, with Basic, Standard and Strict levels.
Stop SQL injection, XSS, bots and exploit scanners inside your own environment — your traffic and logs never pass through a third-party network. Our engineers deploy the WAF, tune out false positives without opening security holes, and keep it running with alerts straight to your team.
Cloud WAFs route your traffic through someone else's network. Open-source WAFs are free but hard to run safely. We built the middle path.
SecRule files, and nobody sure why a request was blocked.Proven open-source detection at the core, with the control plane, tuning and operations that make it usable in production.
OWASP Core Rule Set against SQLi, XSS, RCE, LFI/RFI, path traversal and protocol attacks, with Basic, Standard and Strict levels.
A semantic layer detects injection by structure, not just regex, covering SQLi, XSS, NoSQL, SSTI and LDAP, with multi-pass decoding against obfuscation.
Monitor mode, scoped exceptions, policy versioning and rollback. Fix false positives without weakening protection.
Proof-of-work browser challenge, client-side anti-automation, and bad bot and scanner blocking, with no third-party CAPTCHA.
Per-site rate limits, slow-request (Slowloris/CC) protection and automatic banning of abusive clients.
IP allow/block lists, per-country geo policy, VPN/proxy/Tor blocking and IP reputation feeds.
Let's Encrypt certificates with auto-renew, bring-your-own certificates, TLS 1.2/1.3 and per-site client-certificate (mTLS).
Positive security for APIs: method and path allowlists and OpenAPI schema validation, deny-by-default.
Detect credit card numbers, national ID (NIK), phone numbers and emails in responses, and block or mask them.
Live dashboard of requests, blocks and attacks per site, with the exact rule, field and reason behind every block, plus real latency (p95).
Alerts to WhatsApp groups, Slack, Microsoft Teams, Telegram, Discord, email and webhooks.
SSO (OIDC, LDAP/Active Directory), role-based access, MFA/TOTP, scoped API tokens and a hash-chained audit log.
A WAF that blocks your own customers is worse than none. We switch to blocking only after real traffic proves it is safe.
We map your applications, APIs, authentication flows, traffic volume and compliance needs, and pick the deployment model.
We install the WAF on your VMs, private cloud or Kubernetes, set up HTTPS and put it in front of your apps, in monitor mode.
Our engineers review what would be blocked and create scoped exceptions for legitimate traffic, such as session cookies and rich-text fields.
Once false positives are cleared, we enable blocking per site, with versioned policies and instant rollback ready.
Attack analytics, health checks and alerts go to your team's channels, with MYC engineers on escalation.
Rule updates and virtual patches for new CVEs, rolled out carefully so updates never break your apps.
Same engine and same dashboard. The difference is only where it runs and who operates it.
When your auditor asks “is there a WAF in blocking mode, MFA for admins and an audit trail?”, the answer and the evidence are ready.
Security products fail when they overpromise. Here is where it fits in your stack.
A self-hosted WAF is a reverse proxy that runs in your own environment — on-premise, in your private cloud or on your cloud VMs — and inspects HTTP traffic before it reaches your application, blocking attacks such as SQL injection, XSS and remote code execution. Unlike a cloud WAF, your traffic and logs never pass through a third-party network.
No. The WAF data plane, logs and analytics run inside your environment, which suits banks, government and other organizations with data-residency requirements. MYC engineers can operate it for you under a hybrid model without moving your traffic.
Every site starts in monitor mode. MYC engineers review which rules would block legitimate traffic and create scoped exceptions — for one rule, one host and one parameter — instead of disabling protection globally. Every change is versioned, can be rolled back and is recorded in a tamper-evident audit log.
No. It focuses on application-layer (L7) protection and does not provide volumetric L3/L4 DDoS mitigation or a global CDN. If you need those, keep a CDN or anti-DDoS service in front; the WAF is designed to sit behind it.
It provides controls auditors ask for — a WAF in blocking mode in front of public web applications, MFA for administrators, role-based access and a tamper-evident audit trail — with a control mapping for PCI-DSS v4.0, ISO/IEC 27001, POJK, SPBE/BSSN and UU PDP. It speeds up an audit but does not replace certification of your organization.
The WAF is already running on real traffic, and we are onboarding a limited number of design partners. Early-access customers get hands-on deployment and tuning by MYC engineers and direct influence on the roadmap. The hosted SaaS model is planned for a later phase.
Tell us which applications you need to protect, where they run and your compliance requirements. A senior MYC engineer will reply with a deployment proposal.