Early Access · Self-Hosted WAF

Self-Hosted Web Application Firewall, Deployed & Tuned by MYC Engineers

Stop SQL injection, XSS, bots and exploit scanners inside your own environment — your traffic and logs never pass through a third-party network. Our engineers deploy the WAF, tune out false positives without opening security holes, and keep it running with alerts straight to your team.

  • 100% Self-hosted, data stays with you
  • OWASP Top 10 protection by default
  • L7 Web & API attack defense

Why a self-hosted WAF instead of a cloud WAF or DIY ModSecurity.

Cloud WAFs route your traffic through someone else's network. Open-source WAFs are free but hard to run safely. We built the middle path.

The usual options

  • Cloud WAF — traffic, cookies and logs pass through a third-party network, a problem under data-residency rules.
  • DIY ModSecurity — no dashboard, raw SecRule files, and nobody sure why a request was blocked.
  • False positives are “fixed” by disabling whole rules, silently opening holes.
  • No audit trail of who changed which policy, and when.
  • Alerts land in a mailbox nobody reads at 2 a.m.

With MYC

  • Runs in your environment — VM, private cloud or Kubernetes; data never leaves.
  • Pick a policy, click apply — protection levels instead of hand-written rules.
  • Scoped exceptions — tune one rule for one host and field, never the whole engine.
  • Tamper-evident audit log — hash-chained and verifiable.
  • Alerts where your team is — WhatsApp group, Slack, Teams, Telegram, email, webhook.

Web application firewall features for web apps and APIs.

Proven open-source detection at the core, with the control plane, tuning and operations that make it usable in production.

OWASP Top 10 Protection

OWASP Core Rule Set against SQLi, XSS, RCE, LFI/RFI, path traversal and protocol attacks, with Basic, Standard and Strict levels.

Semantic Detection

A semantic layer detects injection by structure, not just regex, covering SQLi, XSS, NoSQL, SSTI and LDAP, with multi-pass decoding against obfuscation.

Safe False-Positive Tuning

Monitor mode, scoped exceptions, policy versioning and rollback. Fix false positives without weakening protection.

Bot Defense

Proof-of-work browser challenge, client-side anti-automation, and bad bot and scanner blocking, with no third-party CAPTCHA.

Rate Limiting & Auto-Ban

Per-site rate limits, slow-request (Slowloris/CC) protection and automatic banning of abusive clients.

IP, Geo & Threat Intel

IP allow/block lists, per-country geo policy, VPN/proxy/Tor blocking and IP reputation feeds.

Auto HTTPS & mTLS

Let's Encrypt certificates with auto-renew, bring-your-own certificates, TLS 1.2/1.3 and per-site client-certificate (mTLS).

API Security

Positive security for APIs: method and path allowlists and OpenAPI schema validation, deny-by-default.

Data Leak Prevention

Detect credit card numbers, national ID (NIK), phone numbers and emails in responses, and block or mask them.

Real-Time Attack Analytics

Live dashboard of requests, blocks and attacks per site, with the exact rule, field and reason behind every block, plus real latency (p95).

Multi-Channel Alerting

Alerts to WhatsApp groups, Slack, Microsoft Teams, Telegram, Discord, email and webhooks.

Enterprise Access Control

SSO (OIDC, LDAP/Active Directory), role-based access, MFA/TOTP, scoped API tokens and a hash-chained audit log.

Our WAF onboarding process: from monitor mode to full protection.

A WAF that blocks your own customers is worse than none. We switch to blocking only after real traffic proves it is safe.

  1. 01

    Assessment

    We map your applications, APIs, authentication flows, traffic volume and compliance needs, and pick the deployment model.

  2. 02

    Deploy in your environment

    We install the WAF on your VMs, private cloud or Kubernetes, set up HTTPS and put it in front of your apps, in monitor mode.

  3. 03

    Tune on real traffic

    Our engineers review what would be blocked and create scoped exceptions for legitimate traffic, such as session cookies and rich-text fields.

  4. 04

    Switch to blocking

    Once false positives are cleared, we enable blocking per site, with versioned policies and instant rollback ready.

  5. 05

    Operate & alert

    Attack analytics, health checks and alerts go to your team's channels, with MYC engineers on escalation.

  6. 06

    Keep rules current

    Rule updates and virtual patches for new CVEs, rolled out carefully so updates never break your apps.

WAF deployment models: on-premise, hybrid or cloud.

Same engine and same dashboard. The difference is only where it runs and who operates it.

Self-Hosted

  • Runs on your VMs, private cloud or Kubernetes available
  • Traffic, logs and keys stay with you
  • Suited to banks, government and regulated industries
  • Your team operates, MYC supports

Hybrid / Managed

  • WAF runs in your environment available
  • MYC engineers tune and operate it
  • Data residency without the operational load
  • Multi-node behind Huawei Cloud ELB

Cloud-Hosted (SaaS)

  • Point your DNS, get protected roadmap
  • No infrastructure on your side
  • For SMEs and digital agencies
  • Planned after early access

WAF controls for PCI-DSS, ISO 27001, POJK and UU PDP audits.

When your auditor asks “is there a WAF in blocking mode, MFA for admins and an audit trail?”, the answer and the evidence are ready.

PCI-DSS 6.4 WAF in blocking mode in front of public-facing web applications
MFA + RBAC strong authentication and role-based access for every administrator
Audit trail hash-chained, verifiable log of who changed what, and when
Data residency traffic and logs stay in your own environment and region

What this WAF does, and what it doesn't.

Security products fail when they overpromise. Here is where it fits in your stack.

Built for

  • Application-layer (L7) attacks on websites and APIs: injection, XSS, RCE, traversal.
  • Bots, scanners and abuse: challenges, rate limits, auto-ban.
  • Data residency and on-premise requirements.
  • Governance: tuning, versioning, audit, access control.

Not built for

  • Volumetric L3/L4 DDoS: keep an anti-DDoS service or CDN in front.
  • Global CDN / edge caching: the WAF sits behind your CDN.
  • Global ML threat intelligence at hyperscaler scale.
  • Hosted SaaS today: planned after early access.
Early Access Program

Become a design partner

The WAF is already running on real traffic, where the full tuning cycle has been proven: detect, find the false positive, apply a scoped fix, and keep blocking real attacks. We are now onboarding a limited number of organizations as design partners.

  • Hands-on deployment and tuning by MYC engineers
  • Direct influence on the roadmap and priorities
  • A direct line to the engineers building the product
Live running on real traffic today
2 engines ModSecurity and Coraza, no single-engine lock-in
Multi-node scales out behind Huawei Cloud ELB
CI/CD policy deployed as desired state

Web application firewall questions, answered.

What is a self-hosted web application firewall?

A self-hosted WAF is a reverse proxy that runs in your own environment — on-premise, in your private cloud or on your cloud VMs — and inspects HTTP traffic before it reaches your application, blocking attacks such as SQL injection, XSS and remote code execution. Unlike a cloud WAF, your traffic and logs never pass through a third-party network.

Does our traffic or data leave our environment?

No. The WAF data plane, logs and analytics run inside your environment, which suits banks, government and other organizations with data-residency requirements. MYC engineers can operate it for you under a hybrid model without moving your traffic.

How are false positives handled?

Every site starts in monitor mode. MYC engineers review which rules would block legitimate traffic and create scoped exceptions — for one rule, one host and one parameter — instead of disabling protection globally. Every change is versioned, can be rolled back and is recorded in a tamper-evident audit log.

Does it replace Cloudflare or DDoS protection?

No. It focuses on application-layer (L7) protection and does not provide volumetric L3/L4 DDoS mitigation or a global CDN. If you need those, keep a CDN or anti-DDoS service in front; the WAF is designed to sit behind it.

Does it help with PCI-DSS and other compliance requirements?

It provides controls auditors ask for — a WAF in blocking mode in front of public web applications, MFA for administrators, role-based access and a tamper-evident audit trail — with a control mapping for PCI-DSS v4.0, ISO/IEC 27001, POJK, SPBE/BSSN and UU PDP. It speeds up an audit but does not replace certification of your organization.

What does early access mean?

The WAF is already running on real traffic, and we are onboarding a limited number of design partners. Early-access customers get hands-on deployment and tuning by MYC engineers and direct influence on the roadmap. The hosted SaaS model is planned for a later phase.

Protect your web apps with a self-hosted WAF.

Tell us which applications you need to protect, where they run and your compliance requirements. A senior MYC engineer will reply with a deployment proposal.