Skip to content
← All projects
EUDORIA
Proposal · WAF — Web Application Firewall

Web Application Firewall · web applications

Your website is a door open to the world.

Every exposed web application is under automated attack, every day — bots looking for known flaws and credentials. The WAF protects it on the fly, without touching a line of your code.

For websites, portals, e-commerce and APIs exposed on the InternetProject from € 3,500 · then maintenance from € 290/month, optional
01

What the WAF sees

A real attack, stopped — with a unique incident code and decoded payload.

Every blocked attack has a name and a code.

Not “something was blocked”: the exact request, the OWASP rule that fired, the anomaly score and an incident code linking logs and alerts. You know what was thrown at you — and that you dodged it.

Blocked 403Eudoria WAF#b4e1c07a
RCE / PHP injection on your site
POST your-site.com/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
Rule
OWASP CRS 949110 — anomaly threshold
Category
RCE / PHP injection
Anomaly
score 33 (threshold: 5)
Source
185.220.101.x · Tor exit
Outcome
blocked · tracked · alert sent
Decoded payload and geolocated source included in the alert. Example from real, anonymised traffic.
02

What it blocks

OWASP Top 10 rules, plus bots and abuse — tuned to your application.

  • SQL injectionAttempts to tamper with your database through forms and URLs.
  • Cross-site scripting (XSS)Malicious scripts injected to hit your users.
  • RCE & injectionRemote code execution, path traversal, command injection.
  • Bots & credential stuffingRapid-fire automated logins with stolen credentials: slowed down and blocked.
  • Scraping & abuseAutomated data harvesting and API abuse, with smart rate-limiting.
  • Application flood (L7)Waves of requests aimed at taking the site down: mitigated on the fly.
Virtual patching

A critical flaw comes out in software you use — a CMS, a plugin, a library — and you can't update right away? We block the exploit at the WAF within hours, while you patch calmly. The window in which you are vulnerable closes sooner.

03

The project

Fixed price per protected application. Light-touch maintenance, optional.

WAF

Project from € 3,500+VAT

then maintenance from € 290/month

OWASP Top 10 protection on your application, with tracked alerts.

  • Tuned OWASP Top 10 rules
  • Bot & credential stuffing protection
  • Alerts with incident code
  • Continuous false-positive reduction (with maintenance)
Recommended

WAF + Virtual Patching

Project from € 5,500+VAT

then maintenance from € 490/month

Everything in WAF, plus proactive defence against new vulnerabilities.

  • Everything in WAF
  • Rapid CVE virtual patching
  • Application flood (L7) mitigation
  • Monthly report of what was blocked
  • Dedicated human contact

Per protected application/domain. Multiple applications or high traffic: tailored quote, same fixed-price logic.

On your code

Zero changes

Every block

Incident code

New CVEs

Virtual patch

04

Why Eudoria

Our WAF doesn't spit out unreadable logs: every attack comes out with an incident code, the decoded payload and geolocation. We wired the engine ourselves — and we use it to protect our own services.

Alerts you understand

Incident code shared between WAF and logs, payload already decoded, geolocated source. Not a wall of text.

Tuned, not generic

Rules adapt to your application: high protection, low false positives. Hand-curated over time.

Sovereign

None of your users' traffic passes through a third-party cloud. The WAF runs where you decide.

Let's see what really comes in

Let's put the WAF in front of your site and look together.

We start with an assessment that includes analysis of your exposed applications. Then the WAF closes what needs closing, and shows you every day what it stopped.

Let's talk →

No changes to your code · Fast activation

Eudoria · sovereign security & IT · ItalyIndicative amounts, VAT excluded · quote on the real perimeter