IGNITE WAF · self-hosted request firewallLucee / CFML · MSSQL / MySQL / Postgres

Protect your Lucee apps before requests reach them.

Ignite WAF is deployable software for CFML teams and agencies. Run rules, rate limits, and request logs on infrastructure you control—without sending application traffic through a proxy.

SELF-HOSTED · NO THIRD-PARTY EGRESS MULTI-TENANT · PER-SITE RULES CFML-NATIVE
live at the edgesite: shop.example.com
requests/min blocked today
01
IP rules
Allow/deny by address or CIDR range.
02
Signature
Regex match against known attack patterns.
03
User-agent
Block scrapers and known bad clients.
04
Path
Deny requests to sensitive or nonexistent routes.
05
Rate limit
Rolling-window jail for request floods.

Protection that fits the stack you already operate.

Deploy Ignite WAF with your Lucee/CFML application, keep requests and logs on your infrastructure, and manage protection from one operator-focused interface.

01 / SELF-HOSTED CONTROL

Data never leaves your host

Request and log data stays on infrastructure you already control — nothing is proxied through a third-party network to get WAF protection.

02 / MULTI-TENANT SIMPLICITY

Built for agencies managing many sites

Each site gets its own scoped IP, path, signature, and user-agent rules — manage a whole client roster from one lightweight admin panel.

03 / CFML-NATIVE FIT

Built for how Lucee actually runs

No generic middleware bolted onto an unrelated stack — Ignite WAF is written for the Lucee/CFML runtime and deployment model directly.

See what was allowed, blocked, and rate-limited.

The operator interface brings rule changes, request logs, and security audits together so teams can tune protection with context.

Request Logs — shop.example.com BS v2.4.1
Requests today48,206
Blocked1,204
Rate-limited318
Active rules146
TimeIPPathRuleDecision
14:32:09203.0.113.9/wp-login.phppath ruleDeny
14:32:08198.51.100.44/checkoutAllow
14:32:06185.220.101.7/.envsignatureDeny
14:32:0494.102.51.19/admin/config.phpsignatureDeny
Illustrative request data showing the information available to operators during evaluation.

Everything an operator needs, nothing an agency can't run.

Beyond request filtering, the admin panel covers the surrounding work of actually operating a firewall day to day.

01

CSP Security Audit

Fetches your live Content-Security-Policy header and grades it A–F across 40+ directive checks — run on demand or on a schedule, with results emailed to your team.

02

Quick Scan

A broader sweep covering TLS configuration, cookie flags, CORS, clickjacking protection, and exposed paths — separate from the CSP audit, same A–F grading.

03

Velocity jail

Rolling-window rate limiting tracks request bursts per IP and automatically jails offenders — releasable by an operator with the right permission.

04

Geo resolution

Every request is attributed a country via MaxMind GeoIP2, with a bundled MMDB file and REST fallback — no outbound call required for the common case.

05

Portable across engines

Ships with adapters for MSSQL, MySQL, and PostgreSQL behind a shared SQL-dialect layer — MSSQL is the primary target, the others are there when you need them.

06

Granular permissions

Per-user, per-site access control with a fixed permission catalog — logs, config, users, sites, and reports can each be scoped independently per operator.

Evaluate Ignite WAF in your own environment.

Get the deployable package and a 14-day evaluation code. No card required.