Ignite WAF is deployable software for CFML teams and agencies. Run rules, rate limits, and request logs on infrastructure you control—without sending application traffic through a proxy.
Deploy Ignite WAF with your Lucee/CFML application, keep requests and logs on your infrastructure, and manage protection from one operator-focused interface.
Request and log data stays on infrastructure you already control — nothing is proxied through a third-party network to get WAF protection.
Each site gets its own scoped IP, path, signature, and user-agent rules — manage a whole client roster from one lightweight admin panel.
No generic middleware bolted onto an unrelated stack — Ignite WAF is written for the Lucee/CFML runtime and deployment model directly.
The operator interface brings rule changes, request logs, and security audits together so teams can tune protection with context.
| Time | IP | Path | Rule | Decision |
|---|---|---|---|---|
| 14:32:09 | 203.0.113.9 | /wp-login.php | path rule | Deny |
| 14:32:08 | 198.51.100.44 | /checkout | — | Allow |
| 14:32:06 | 185.220.101.7 | /.env | signature | Deny |
| 14:32:04 | 94.102.51.19 | /admin/config.php | signature | Deny |
Beyond request filtering, the admin panel covers the surrounding work of actually operating a firewall day to day.
Fetches your live Content-Security-Policy header and grades it A–F across 40+ directive checks — run on demand or on a schedule, with results emailed to your team.
A broader sweep covering TLS configuration, cookie flags, CORS, clickjacking protection, and exposed paths — separate from the CSP audit, same A–F grading.
Rolling-window rate limiting tracks request bursts per IP and automatically jails offenders — releasable by an operator with the right permission.
Every request is attributed a country via MaxMind GeoIP2, with a bundled MMDB file and REST fallback — no outbound call required for the common case.
Ships with adapters for MSSQL, MySQL, and PostgreSQL behind a shared SQL-dialect layer — MSSQL is the primary target, the others are there when you need them.
Per-user, per-site access control with a fixed permission catalog — logs, config, users, sites, and reports can each be scoped independently per operator.
Get the deployable package and a 14-day evaluation code. No card required.