Now accepting new tenants

A managed Web Application Firewall for teams who'd rather not run their own HAProxy cluster

WAF, rate limiting, bot challenge, automatic SSL, and load balancing for your domains โ€” configured from one dashboard, enforced at the edge, no infrastructure to babysit.

Platform

Everything your ingress layer should already do

Point your domain's DNS at ShieldIngress and every request gets inspected, filtered, and routed before it ever reaches your origin.

๐Ÿงฑ

Web Application Firewall

A Coraza/ModSecurity-compatible rule engine blocks SQL injection, XSS, remote code execution, and other OWASP Top 10 attacks automatically, on every request.

๐ŸŒ

IP & Geo Rules

Allow or block traffic by IP address, CIDR range, or country โ€” stop known-bad sources before they ever hit your backend.

โฑ๏ธ

Rate Limiting

Per-path request throttling stops brute-force attempts, scraping, and abusive clients without touching your application code.

๐Ÿค–

Bot Challenge

A lightweight JavaScript challenge filters out scripted bot traffic while real visitors pass through without ever noticing.

๐Ÿ”’

Automatic SSL

Free, auto-renewing Let's Encrypt certificates for every domain you add โ€” issued and renewed with zero manual steps.

โš–๏ธ

Load BalancingPRO

Distribute traffic across multiple backend servers with health checks, so a single unhealthy origin never means downtime.

๐Ÿงช

Staging DeploysPRO

Test a configuration change against a real staging environment before it ever reaches production traffic.

โ†ฉ๏ธ

Revision History

Every change is versioned. See exactly what changed and when, and roll back to a previous revision instantly if something breaks.

๐Ÿ“Š

Real-Time Dashboard

Live WAF events, traffic stats, and domain health, all in one place โ€” no digging through raw log files.

How it works

Live in minutes, not a migration project

1

Add your domain

Point ShieldIngress at your existing origin server โ€” no code changes required.

2

Configure your rules

Set up WAF, rate-limit, geo, and bot-challenge rules from the dashboard.

3

Update your DNS

Repoint your domain to ShieldIngress's edge โ€” SSL is issued automatically.

4

You're protected

Every request is inspected and filtered before it reaches your origin.

Pricing

Simple, per-domain pricing

Two plans. No setup fees, no bandwidth surprises. Cancel any time.

Basic
$19.99/month

For a single site that needs real protection without the overhead.

  • โœ“ 1 domain
  • โœ“ Up to 10 rules per rule type
  • โœ“ Web Application Firewall
  • โœ“ IP & geo blocking
  • โœ“ Rate limiting & bot challenge
  • โœ“ Automatic SSL
  • โœ“ Revision history
Get Started
FAQ

Questions, answered

Do I need to change my application code?

No. ShieldIngress sits in front of your existing origin server as a reverse proxy โ€” you point DNS at it and configure rules from the dashboard.

What happens if I go over my domain limit?

You won't be cut off. Upgrade to Pro any time from your dashboard, and the new limits apply immediately.

Can I test changes before they go live?

Yes โ€” Pro plans include a staging environment. Deploy a configuration change there first, verify it behaves the way you expect, then push it to production.

What if a rule breaks something?

Every configuration change is saved as a revision. Roll back to any previous revision from the dashboard in seconds.

How do SSL certificates work?

ShieldIngress automatically issues and renews a free Let's Encrypt certificate for every domain you add โ€” no manual renewal, ever.

Ready to put a real WAF in front of your site?

Set up your first domain in minutes.

Get Started