By Outcome — Protect

WAAP, evolved into modern Web Application & API Protection

OWASP Top 10, custom signatures, block pages — all the classical WAAP protection you expect, on TR7. Alongside it, every layer the modern attack surface demands: API security, bot management, account takeover prevention and client-side defense.

WAAP is the modern umbrella for application-layer defenses. TR7 implements that umbrella without sending your traffic to someone else's cloud — it runs on your hardware. 10,000+ active WAAP signatures update continuously, with every detection natively mapped to CWE, CAPEC and MITRE ATT&CK so it lines up with the taxonomy your security team already uses. Behaviorally-adaptive bot management, OpenAPI-driven API security, account takeover prevention, L7 DDoS protection and client-side script monitoring all run on the same platform, attached to the same vService. Alongside all of it: a content-aware rule engine that can rate-limit or take conditional action on any traffic attribute — including parsed JSON body values — without you writing a single line of script.

10,000+
Active WAAP signatures, continuously updated
10/10
OWASP Web Top 10 + OWASP API Top 10 coverage
On-prem
Traffic and data stay inside your perimeter

WAAP was enough. Then the attack surface moved.

Classical WAAP inspects HTTP request payloads for known attack signatures — SQL injection, XSS, command injection. That work is still essential, and most attacks still hit it. But the attack surface is no longer just signed HTTP payloads.

Public APIs carry traffic that doesn't look like a browser request, and traditional WAAP rules miss them. Automated bots emulate real users, evade signature checks, and exhaust credentials at scale. Account takeover happens through credential stuffing campaigns that hit valid login endpoints with valid-looking traffic. Third-party JavaScript on your pages exfiltrates form data straight to the attacker — and your WAAP never sees it, because the data leaves the browser before it reaches your server.

The industry's answer is WAAP — Web Application and API Protection — a single umbrella that adds API security, bot management, account takeover prevention and client-side defense on top of the WAAP. TR7 implements that umbrella as one platform, on-prem, attached to the same vService that already delivers your application.

Five things that set TR7 WAAP apart

Each of these is valuable alone. Together, they redefine what a web application and API protection platform looks like when it does not depend on someone else's cloud.

On-prem first — your data stays inside your perimeter

Most modern WAAP options route your traffic through an edge cloud you don't operate. TR7 WAAP runs on your hardware, in your data center, under your network controls. No third-party traffic interception, no out-of-perimeter request decryption, no shared multi-tenant edge.

Full modern attack surface in one platform

WAAP (OWASP Top 10 + custom signatures + virtual patching), API security (discovery + OpenAPI schema enforcement), bot management, account takeover prevention, L7 DDoS protection, client-side and Magecart defense. One platform; not a stitched suite of separate appliances.

Deep framework mapping — OWASP, CWE, CAPEC, MITRE ATT&CK

10,000+ active signatures continuously updated. 10/10 OWASP Web Top 10 and 10/10 OWASP API Top 10 coverage. Every detection mapped natively to 100+ CWE codes, 30+ CAPEC patterns and 30+ MITRE ATT&CK techniques — so your SOC and compliance team see WAAP events in the same taxonomy they already use.

AI behavioral rules + content-aware traffic logic

11-factor behavioral scoring engine adapts to your application's normal traffic — TLS fingerprints, IP reputation across 23 categories, request rhythm, and more. On top of that: a content-aware rule engine that can rate-limit or act on any traffic attribute, including parsed JSON body values, header content or cookie contents — without writing a single line of script.

Blocked attacks never count toward your bill

Volumetric DDoS absorbed at the edge of your network, WAAP-blocked requests, bot challenges and rate-limited traffic — none of it counts toward your bandwidth meter. The harder your WAAP works, the bigger the gap between throughput and billable bandwidth.

What TR7 WAAP includes

Every capability below ships as part of the WAAP platform and attaches to your existing vServices.

OWASP Top 10 WAAP — Web and API

10/10 coverage on both the OWASP Web Application Top 10 and the OWASP API Security Top 10. SQL injection, XSS, command injection, CSRF, path traversal, broken object-level authorization and the rest — all covered by managed signatures with continuous updates.

10,000+ active signatures

Continuously updated signature set covering known attack patterns, exploit primitives and emerging CVEs. Virtual patching turns a new CVE into a deployed rule in hours, not weeks.

Native CWE, CAPEC and MITRE ATT&CK mapping

Every detection mapped to its CWE code (100+ codes), CAPEC attack pattern (30+ patterns) and MITRE ATT&CK technique (30+ techniques). SOC investigations, SIEM correlation and compliance reports speak the same taxonomy as the rest of your security stack.

Custom signatures and rules — per vService

Add organization-specific signatures, exception rules and virtual patches. Per-vService rule scoping so a policy on one service does not affect another.

API security with OpenAPI schema enforcement

API discovery surfaces endpoints actually in use. OpenAPI schema enforcement validates request method, path, parameters and body against the contract. Per-endpoint rate limits and method restrictions.

AI behavioral rules + 11-factor bot scoring

11-factor weighted scoring engine analyzes TLS fingerprints, IP reputation across 23 categories, request rhythm and request shape. Behavioral baseline adapts to your application's normal traffic over time, with an exponential scoring curve tuned for low false positives.

Content-aware traffic rules — no scripting

Rate limit, challenge or block on any traffic attribute — header values, cookie contents, URL parameters, and even values inside parsed JSON request bodies. All configured visually in the same rule builder used elsewhere on the platform. No proprietary scripting language.

Account takeover (ATO) prevention

Detects credential stuffing patterns on login endpoints. Recognises distributed low-and-slow attempts, impossible travel and abnormal session-creation rates that single-IP rate limiting misses.

L7 DDoS protection

HTTP-flood, slow-loris and application-layer volumetric attacks absorbed at the WAAP layer. Pair with TR7's L4 DDoS protection for the full vector range.

Client-side / Magecart / JS skimming defense

Monitors third-party scripts loaded by your pages. Detects unauthorized script changes, suspicious form-data exfiltration patterns and supply-chain skimming attacks that the server-side WAAP cannot see.

Managed signature updates

Signature databases for WAAP, bot fingerprints and IP reputation feeds update continuously — no manual download cycle, no version skew between sites.

Post-quantum cryptography ready

TLS termination supports post-quantum cipher suites alongside classical ones — ready for the migration without re-architecting when it becomes mandatory.

Host groups and multi-tenant policy scoping

Group services by tenant or business unit; apply policy at the group level. One ruleset for the corporate tenant, another for the customer tenant, both on one platform.

Custom block pages

Branded block pages per policy. Show the right message to the right blocked request; serve a maintenance page when an attack triggers an automated lockdown.

Pair with browser-layer isolation

When payload inspection is not enough — the request looks clean but the attacker is targeting browser-rendered DOM — the ZeroLeak isolation layer renders the application off-device, so there is nothing on the user's machine for the attacker to exfiltrate.

Full visibility and audit

Every WAAP decision — blocked, challenged, allowed — emits structured telemetry. Investigate any request end-to-end through the same console used to manage the vService.

Architecture — how a request is protected

Six well-defined stages. Every stage configurable per vService. Every stage visible as a diagram in the Dynamic Flow Panel.

01

vService listener and TLS termination

The request reaches the vService listener. TLS terminates here so the WAAP layers can inspect cleartext. Modern ciphers, hardware-accelerated handshakes.

02

Volumetric and reputation filtering

L7 DDoS protection, IP reputation feeds and geo policy run before deep inspection. Obvious flood traffic and known-bad sources are dropped without consuming inspection budget.

03

WAAP signature and rule evaluation

OWASP signature checks, custom rules, structural attack detection, parameter and argument validation. Request scored and decided: allow, block, virtual patch, or pass to behavior analysis.

04

Bot evaluation

Signature and behavior signals score the request as human, known bot or unknown automation. Mitigation per policy: allow, challenge, throttle, or drop.

05

API schema enforcement

For requests targeting an API endpoint, the OpenAPI schema check validates method, path, parameters and body against the contract. Mismatches trigger configured action.

06

Action and audit

The decision is applied — pass through to backend, return a block page, issue a challenge, or rate-limit. The full decision chain is logged for investigation and compliance.

Where this outcome shows up

E-commerce — flash sales and carding attacks

Bot management blocks credential stuffing and carding bots during high-traffic events. WAAP rules stop OWASP Top 10 attacks; client-side defense prevents skimmers from harvesting card data at checkout.

Banking and financial services

OWASP-mandated controls, account takeover prevention on login endpoints, API protection for open-banking flows, and audit-ready logging for regulatory review.

Healthcare portals

Patient data protection at the application layer, on-prem deployment keeps PHI inside the hospital perimeter, schema validation on portal APIs to prevent injection-style data leakage.

Government and public-sector services

On-prem WAAP for citizen-facing services where data residency is non-negotiable. OWASP coverage for compliance frameworks, audit logging for the security operations team.

Public-facing APIs

Schema validation against the OpenAPI contract, per-endpoint rate limiting, method restrictions, parameter validation. Combined with bot management to stop API scraping and credential stuffing.

Account takeover defense at scale

Login endpoints under continuous credential-stuffing pressure. ATO detection recognises distributed attempts, impossible travel and abnormal session-creation rates that single-IP rate limiting misses.

27 features

Features that implement this solution

Capabilities referenced by this solution — the technical pieces that compose the controls described above.

Cookie Security Flags

TR7 ADCTR7 WAAP
Application Delivery & AccelerationWeb Application & API Protection

Complete missing HttpOnly, Secure and SameSite flags at the response layer — no application changes required.

Financial Services· Healthcare

Inline TLS Backend Inspection

TR7 WAAPTR7 ADC
Web Application & API ProtectionAPI SecurityPCI DSS ComplianceHIPAA Compliance

WAAP inspection, mTLS identity and data masking keep working even as traffic flows to backends over TLS.

Financial Services· Healthcare· Government

JSON Path Operations

TR7 ADCTR7 WAAP
Application Delivery & AccelerationAPI SecurityWeb Application & API Protection

Turn JSON body fields and JWT content into first-class signals for every traffic decision.

Response Body Modification

TR7 ADCTR7 WAAP
Application Delivery & AccelerationWeb Application & API ProtectionData Leakage Prevention

Mask, replace or inject HTML into response content — without changing a line of backend code.

Healthcare· Financial Services

Traffic Quarantine

TR7 ADCTR7 WAAP
Web Application & API ProtectionDDoS MitigationBot Management

Observe behavior instead of blocking instantly — isolate sources that exceed a threshold and release them automatically.

Retail & E-commerce· Financial Services

FX Expression and Variable Engine

TR7 ADCTR7 WAAPTR7 GTM
Application Delivery & AccelerationWeb Application & API ProtectionAPI Security

One expression language — traffic, health, logging, GTM, security and access decisions in the same model.

Live Traffic Tracking

TR7 ADCTR7 WAAPTR7 L7 Reporting
Application Delivery & AccelerationWeb Application & API Protection

See production traffic request by request — turn observation directly into rule actions.

L7 Traffic Analytics & Reporting

TR7 ADCTR7 WAAPTR7 L7 Reporting
Application Delivery & AccelerationWeb Application & API Protection

30+ breakdown dimensions, three formats (PDF / XLSX / HTML), up to 10 years of on-device history — no separate management server.

WAAP Attack Reporting

TR7 WAAPTR7 L7 Reporting
Web Application & API ProtectionAPI SecurityBot Management

3000+ rules, OWASP / API Top 10 / CWE taxonomy, 14 correlation axes, per-host-group + cross-group rollups.

Financial Services· Government

Cookie Encryption Rule

TR7 ADCTR7 WAAP
Application Delivery & AccelerationWeb Application & API ProtectionData Leakage Prevention

Hide cookie values from the client — protect session integrity without touching backend code.

Financial Services· Healthcare

Content-Aware Rules

TR7 ADCTR7 WAAP
Application Delivery & AccelerationModernize Legacy AppsWeb Application & API ProtectionAPI Security

Move beyond headers — make body content part of the traffic and security decision.

SSL/TLS Acceleration

TR7 ADC
Application Delivery & AccelerationWeb Application & API ProtectionPCI DSS ComplianceHIPAA Compliance

Move TLS beyond file-based configuration — turn it into a per-service security profile, certificate lifecycle and post-quantum readiness layer.

Deployment Topology Modes

TR7 ADCTR7 WAAPTR7 AAM
Application Delivery & AccelerationModernize Legacy AppsWeb Application & API Protection

Insert TR7 ADC into the traffic path without touching backend IP addresses, gateways or routes.

FTP Security Proxy

TR7 WAAP
Web Application & API ProtectionData Leakage PreventionModernize Legacy Apps

Manage FTP not as an open port, but as a command-by-command controlled secure file transfer session.

Financial Services· Government· Healthcare

Built-In Firewall

TR7 ADC
Application Delivery & AccelerationWeb Application & API Protection

ADC, routing and L3/L4 security from a single console.

WAAP Signature & Scoring

TR7 WAAP
Web Application & API ProtectionAPI SecurityPCI DSS Compliance

Combine signature, score and context in a single engine — manage known attacks with confidence.

Financial Services· Government· Retail & E-commerce· Healthcare

Self-Hosted CAPTCHA

TR7 WAAP
Bot ManagementWeb Application & API Protection

Generation, delivery and verification — all inside the ADC. Zero calls to any third-party cloud service.

Financial Services· Government· Retail & E-commerce

Custom WAAP Rules

TR7 WAAP
Web Application & API Protection

Add your own WAAP logic alongside the built-in signature set — same scoring engine, same logs, same policy pipeline.

Geo/ASN Access Control

TR7 WAAPTR7 ADC
Web Application & API ProtectionDDoS Mitigation

Turn country and ASN context into access decisions — without dependency on external services.

Financial Services· Government

IP Reputation Feeds

TR7 WAAPTR7 ADC
Web Application & API ProtectionDDoS Mitigation

TR7's central feed, external URL lists and your own exceptions converge in a single IP reputation engine.

Syslog Forwarding Proxy

TR7 ADCTR7 WAAP
Web Application & API ProtectionMulti-Protocol PlatformModernize Legacy Apps

Collect, classify, replicate and forward UDP and TCP syslog traffic in front of your SIEM.

Financial Services· Government· Healthcare

DNS Firewall & Load Balancer

TR7 ADCTR7 WAAP
Web Application & API ProtectionDDoS MitigationMulti-Protocol Platform

Accelerate enterprise DNS traffic and block malicious queries — in a single layer.

Financial Services· Government· Healthcare

Smart ACL Conditions

TR7 ADCTR7 WAAP
Application Delivery & AccelerationWeb Application & API Protection

Not just an IP list — real traffic intelligence across 60+ criteria, AND/OR/NOT groups and Smart Function chains.

Virtual Patching

TR7 WAAP
Web Application & API ProtectionModernize Legacy Apps

Close a vulnerability at the traffic layer in minutes — no code change required.

Financial Services· Government· Healthcare

GraphQL Deep Inspection

TR7 WAAP
API SecurityWeb Application & API Protection

Do not treat GraphQL traffic as a plain POST body — catch introspection, nested DoS and query batching patterns inside your WAAP.

Client-Side Script Protection

TR7 WAAP
PCI DSS ComplianceWeb Application & API Protection

Apply 8 security headers at the ADC layer without touching application code.

Financial Services· Retail & E-commerce

Block Page Customization

TR7 WAAP
Web Application & API Protection

Replace the generic 'access denied' screen with a controlled, branded experience that carries your message, language and reason code.

Common questions

What's the difference between WAAP and WAAP?
WAAP (Web App & API Protection) inspects HTTP requests for known attack signatures — OWASP Top 10, SQL injection, XSS. WAAP (Web Application and API Protection) keeps the WAAP and adds the rest of what modern attacks need: API security, bot management, account takeover prevention and client-side defense. TR7 WAAP is the WAAP you expect plus the WAAP umbrella, in one platform.
Is TR7 WAAP a cloud service or on-prem?
On-prem first. TR7 WAAP runs on your hardware, in your data center, under your network controls. Your traffic is never decrypted in someone else's cloud, and your data never leaves your perimeter. Virtual deployment on your own virtualization platform is supported too.
Does API security require a separate license or product?
API security ships as part of the WAAP platform — discovery, OpenAPI schema enforcement, per-endpoint rate limiting and method restrictions are included. No separate API security gateway to license.
How are signatures and protection rules updated?
Managed signature updates run continuously — WAAP rule databases, bot fingerprint sets and IP reputation feeds. No manual download cycle, no per-site version skew.
What does ZeroLeak add that WAAP alone does not cover?
WAAP inspects request and response payloads. ZeroLeak renders the application off-device in a remote browser, so even when a payload is clean to inspection, an attacker cannot reach the DOM, scrape source, or persist anything on the user's machine. ZeroLeak is the browser-layer companion to WAAP for high-sensitivity portals and admin consoles.
Does the bandwidth model apply to attacks blocked by WAAP?
Yes. Volumetric DDoS the WAAP layer absorbs, WAAP-blocked requests, bot challenges and rate-limited traffic are excluded from the bandwidth meter. You pay for what your application actually serves to legitimate users, not for the attacks the platform stopped.
Can WAAP and load balancing run on the same appliance?
Yes. WAAP policy attaches to the same vService that delivers the application — same configuration model, same platform, same operations team. No separate WAAP appliance to deploy, route around or maintain.
Does TR7 map WAAP detections to CWE, CAPEC and MITRE ATT&CK?
Yes. Every detection is natively mapped to 100+ CWE codes, 30+ CAPEC attack patterns and 30+ MITRE ATT&CK techniques. SIEM correlation, incident response and compliance reporting all see WAAP events in the same taxonomy your security team already uses.
Can rules act on values inside a JSON request body?
Yes. The content-aware rule engine can rate-limit, challenge or block on any traffic attribute — headers, cookies, URL parameters and values parsed out of JSON request bodies. All configured in the visual rule builder; no proprietary scripting language to learn. Example: rate-limit an API endpoint differently based on the value of a 'tier' field inside the request body.

WAAP, evolved — without sending your traffic away

Request a live demo of TR7 WAAP. We will configure WAAP, API security, bot management and client-side defense on your environment in one session.