SECURITY · EDGE PROTECTION

HOLD THE EDGE.FILTER AT L7.

Hold The Edge. Filter At L7.

Cloudflare-backed L7 WAF and bot mitigation, bundled with proxied domains and CDN. Application-layer perimeter defense — not dedicated L3/L4 scrubbing.

L7 WAF PROTECTION
Bots MITIGATION
Edge ENFORCEMENT
EU OPERATIONS

Choose your edge policy posture.

Monthly managed tiers. WAF rule depth and bot mitigation scale by plan. Coverage applies to traffic proxied through the edge.

popular
Anti-DDoS

Advanced DDoS + WAF

€35.99 /mo
€0.050 / hour
  • L7 Layer
  • WAF
  • Bot
  • Cloudflare Network
Request a quote

Proxy the domain, then filter at the edge.

A clean path from proxying through the edge to enforcing L7 policies and reading telemetry.

01
Proxy

Route Traffic Through The Edge

Point your domain through the Cloudflare-managed proxy. Edge protection only applies to traffic that traverses the proxy.

# domain.proxy
hostname: api.altovar.net
posture: proxied (orange cloud)
contacts: ops + security
policy: managed WAF on
02
Mitigate

Filter At Application Layer

Managed L7 WAF rules and bot mitigation drop abusive requests at the Cloudflare edge before they reach the origin. This protects application-layer traffic; it is not dedicated L3/L4 scrubbing.

edge.waf api.altovar.net
managed rules engaged...
bot mitigation active...
OK abusive l7 requests blocked
OK clean traffic forwarded
03
Review

Read The Edge Telemetry

Cloudflare event logs and analytics surface blocked traffic, bot activity, and WAF triggers for post-event review and tuning.

edge.events api.altovar.net
blocked requests12.4k
bot challenges3.1k
service impactminimal
reportexport ready
What It Covers
Scope HTTP/HTTPS traffic on proxied hostnames
WAF Managed and custom L7 rules
Bots Bot category recognition and challenges
Rate-limiting Per-hostname rate-limit rules
What It Does Not Cover
L3/L4 scrubbing Not a dedicated scrubbing center service
Non-proxied origin Traffic bypassing the proxy is unprotected
Tbps claims No bespoke volumetric mitigation guarantees
Per-customer console No dedicated scrubbing-console UI
Telemetry
Events Edge analytics for blocked requests
Metrics Bot challenges, WAF triggers, rate-limits
Alerts Operational notifications at edge policy events
Exports Cloudflare analytics for downstream review
Operations
Policy review WAF rule tuning support on higher plans
Residency EU-managed control surface
Review Post-incident reporting via edge analytics
Assurance Honest about scope — L7 defense, not L3/L4 scrubbing
CLOUD

HOLD THE EDGE.FILTER AT L7.

Cloudflare-backed L7 WAF and bot mitigation for proxied domains.

PROXY A DOMAIN →