A firewall that lives inside your deployment, not in front of it.

Ignite WAF installs as software beside your Lucee/CFML application. Every request is evaluated on your host, against rules you control, before it ever reaches your app code.

Everything an operator needs, nothing an agency can't run.

Beyond request filtering, the admin panel covers the surrounding work of actually operating a firewall day to day.

CSP security audit

Fetches your live Content-Security-Policy header and grades it A–F across 40+ directive checks — on demand or on a schedule, results emailed to your team.

Quick scan

A broader sweep covering TLS configuration, cookie flags, CORS, clickjacking protection, and exposed paths — same A–F grading.

Velocity jail

Rolling-window rate limiting tracks request bursts per IP and automatically jails offenders — releasable by an operator with the right permission.

Geo resolution

Every request is attributed a country via MaxMind GeoIP2, with a bundled MMDB file and REST fallback — no outbound call required for the common case.

Portable across engines

Ships with adapters for MSSQL, MySQL, and PostgreSQL behind a shared SQL-dialect layer — MSSQL is the primary target, the others are there when you need them.

Granular permissions

Per-user, per-site access control with a fixed permission catalog — logs, config, users, sites, and reports can each be scoped independently per operator.

What happens between the socket and your app.

Every inbound request runs through the same ordered pipeline. The first rule that matches decides the outcome — everything else is skipped.

01

Request arrives

TCP connection hits your host directly — no upstream hop.

02

IP rule check

Address or CIDR range matched against allow/deny lists.

03

Path & UA check

Route and client string matched against configured patterns.

04

Signature match

Body and query matched against known attack regexes.

05

Rate check

Rolling window checked; repeat offenders enter velocity jail.

06a

Deny

Request dropped, decision and rule logged.

Beside your app, not between it and the internet.

A proxy WAF puts a third party's network between your users and your server. Ignite WAF runs as a process on the same host as your application, registered as a request filter in front of your Lucee handler — not a separate network hop, port, or DNS change.

Client
Browser / API caller
→
Your server
Lucee application
Ignite WAF evaluates request
Decision + rule logged locally
Allowed requests reach your app

Five rule types, one evaluation order.

Rules are stored per site and evaluated in the order shown in the pipeline above. Each type has its own matcher and its own log entry.

  • IP rules
    Allow or deny a single address or CIDR range. Evaluated first, cheapest check in the pipeline.
  • Path rules
    Deny requests to routes that shouldn't exist on a CFML host — WordPress paths, dotfiles, admin probes.
  • User-agent rules
    Match against known scraper and bad-client strings, independent of IP reputation.
  • Signature rules
    Regex match against query string and body for known injection and traversal patterns.
  • Rate limit
    Rolling-window counter per IP. Exceeding the threshold moves the address into velocity jail.
rules/shop.example.com.json
// evaluated top to bottom, first match wins
{
  "type": "path",
  "pattern": "^/wp-login\.php$",
  "action": "deny",
  "log": true
},
{
  "type": "signature",
  "pattern": "(?i)(\bor\b\s+1=1|union\s+select)",
  "action": "deny"
},
{
  "type": "rate_limit",
  "window_seconds": 60,
  "max_requests": 600,
  "jail_minutes": 15
}

Every rule is editable from the same interface that logs it.

Changes take effect on the next request — no redeploy, no restart.

Rule Editor — shop.example.com 5 rule types
allow198.51.100.0/24 — office VPN rangeactive
deny185.220.101.0/24 — known Tor exit rangeactive
deny45.33.12.201 — repeat signature matchactive
allow203.0.113.0/24 — payment webhook sourceactive

Run the pipeline above against your own traffic.

Create an account and get a 14-day trial — no card required.