A managed Web Application Firewall for teams who'd rather not run their own ingress infrastructure

WAF, rate limiting, bot challenge, automatic SSL, and load balancing for your domains — configured from one dashboard, enforced at the edge, no infrastructure to babysit. 100% web-based — no downloads, installs, or agents on your servers.

Platform

Everything your ingress layer should already do

Point your domain's DNS at ShieldIngress and every request gets inspected, filtered, and routed before it ever reaches your origin.

Web Application Firewall

A battle-tested rule engine blocks SQL injection, XSS, remote code execution, and other OWASP Top 10 attacks automatically, on every request.

IP & Geo Rules

Allow or block traffic by IP address, CIDR range, or country — stop known-bad sources before they ever hit your backend. Save your own country groups, or start from ones we maintain for you (EU, sanctioned countries, and more).

Rate Limiting

Throttle requests by path, HTTP method, and country, all in one rule. Not sure a limit is safe to turn on? Run it in log-only mode first and see what it would have blocked before it ever denies a real request.

Bot Challenge

Pick the challenge strength that fits the threat — an invisible JavaScript check, a real proof-of-work puzzle, or a drag-to-verify slider — scoped to exactly the path getting hit, so real visitors never notice.

Automatic SSL

Free, auto-renewing Let's Encrypt certificates for every domain you add — issued and renewed with zero manual steps.

Security Headers

Check your live site against the security headers that actually matter, then fix what's missing with one click — no code changes, no redeploying your app.

Edge CachingPRO

Serve repeat requests straight from the edge instead of hitting your origin every time. Static assets are cached automatically; add your own rules for exactly what to cache and what to always skip.

Load BalancingPRO

Distribute traffic across multiple backend servers with health checks, so a single unhealthy origin never means downtime.

Staging DeploysPRO

Test a configuration change against a real staging environment before it ever reaches production traffic.

Revision History

Every change is versioned. See exactly what changed and when, and roll back to a previous revision instantly if something breaks.

Real-Time Dashboard

Live WAF events, traffic stats, and domain health, all in one place — no digging through raw log files.

Two-Factor Authentication

Optional TOTP-based 2FA for every team member, with one-time backup codes if you lose your device — protect the account that controls your security.

Health & SSL Alerts

Automatic email the moment an origin goes down (or recovers) or a certificate fails to renew — on every plan, no setup required. Pro adds a configurable webhook for Slack, Discord, or your own tooling.

How it works

Live in minutes, not a migration project

1

Add your domain

Point ShieldIngress at your existing origin server — no code changes required.

2

Configure your rules

Set up WAF, rate-limit, geo, and bot-challenge rules from the dashboard.

3

Update your DNS

Repoint your domain to ShieldIngress's edge — SSL is issued automatically.

4

You're protected

Every request is inspected and filtered before it reaches your origin.

Pricing

Simple, per-domain pricing

Two plans, both starting with a 7-day free trial. No setup fees, no bandwidth surprises. Cancel any time.

Basic
$19.99/month
7-day free trial

For a single site that needs real protection without the overhead.

  • 1 domain
  • +1 free redirect-only domain (e.g. apex → www)
  • Up to 10 rules per rule type
  • Web Application Firewall
  • IP & geo blocking
  • Rate limiting & bot challenge
  • Automatic SSL
  • Revision history
Start Free Trial
FAQ

Questions, answered

How does the free trial work?

Every plan starts with a 7-day free trial. We collect payment details up front, but you're not charged until the trial ends -- cancel any time before then and you won't be billed at all.

Do I need to change my application code?

No. ShieldIngress sits in front of your existing origin server as a reverse proxy — you point DNS at it and configure rules from the dashboard.

What happens if I go over my domain limit?

You won't be cut off. Upgrade to Pro any time from your dashboard, and the new limits apply immediately.

Can I test changes before they go live?

Yes — Pro plans include a staging environment. Deploy a configuration change there first, verify it behaves the way you expect, then push it to production.

What if a rule breaks something?

Every configuration change is saved as a revision. Roll back to any previous revision from the dashboard in seconds.

How do SSL certificates work?

ShieldIngress automatically issues and renews a free Let's Encrypt certificate for every domain you add — no manual renewal, ever.

Do you have any free tools, no account needed?

Yes — a WAF Rule Builder and a Security Headers Checker are free to use for anyone, no signup required. See the full list.

Status

System Status

Live health of the ShieldIngress platform.

Checking system status…

Contact

Still have questions?

Send us a message and we'll get back to you.

Ready to put a real WAF in front of your site?

Set up your first domain in minutes -- free for 7 days, no obligation.

Start Free Trial