Scanning your connection...
Back to Glossary
Cloud

What is Web Application Firewall?

A security tool that monitors and filters HTTP traffic between a web application and the internet, protecting against common web attacks.

Also known as: WAF

WAFs protect web applications from attacks that network firewalls can't detect.

What It Blocks

  • SQL injection
  • Cross-site scripting (XSS)
  • Cross-site request forgery (CSRF)
  • File inclusion attacks
  • Automated scanners and bots

Providers

  • Cloudflare WAF: Widely used, free tier available
  • AWS WAF: For AWS-hosted applications
  • ModSecurity: Open-source WAF

Privacy Consideration

WAFs terminate TLS connections to inspect traffic content. This means the WAF provider can see all traffic, including sensitive data. For privacy-critical applications, self-hosted WAFs (ModSecurity) avoid this third-party exposure.

Related Terms

Have more questions?

Use our guided flow to get the right next privacy step for Web Application Firewall.

Open Guided Flow