Source-available, self-hosted WAF

CatWAF — a source-available web application firewall

Make your web services
secure by default

Protect your web services with CatWAF, a modern Web Application Firewall. CatWAF acts as a shield in front of your applications and blocks malicious requests before they ever reach your origin.

BLOCKED YOUR LEGITIMATE CLIENTS THE ATTACKER YOUR WEB APPLICATIONS CAT WAF

Web security without any hassle

Placed as a reverse proxy while offering Web Application Firewall (WAF) functionality, CatWAF integrates into your existing infrastructure to secure your web services.

CatWAF helps defend against common web threats such as those listed in the OWASP Top 10, blocks malicious traffic, and gives you real security controls over your applications.

Use it as a single entry point for your web services and manage incoming traffic and HTTP security policy from one place.

Seamless integration into your existing infrastructure
Source-available and inspectable
Reverse proxy with built-in security features
Fully configurable to meet your needs
◉ GitHub repository ▣ Report an issue
CatWAF license

A source-available solution

CatWAF is built around transparency, auditable security, and control. The security layer stays inspectable, so operators can understand exactly what protects their applications.

CatWAF Free uses the PolyForm Internal Use License 1.0.0, with additional permission for personal noncommercial use. Managed service operation and redistribution require a separate commercial license.

Why inspect the source?

  • Total transparency — inspect the source and understand the security mechanisms.
  • Visible development — follow changes and report issues in public.
  • Sovereignty — keep control of your infrastructure and your data.
  • Customization — tailor CatWAF to your project's needs.

Our vision

Transparency

CatWAF puts transparency at the core of its security model, so you can understand the protection applied to your web services.

Our mission

Auditability

Make security controls understandable and verifiable, so operators can build real confidence in what guards their applications.

FreeFor internal use
24/7WAF protection
PL1–PL4CRS paranoia levels
100%Self-hosted control

Let's CatWAF your web services

Explore CatWAF by running it yourself. Discover the dashboard, WAF protection, rules, logs, and the ecosystem around the project.

An easy to use and user-friendly web UI

Manage and configure CatWAF from a clean web interface — rules, traffic, and logs in one place.

Read the doc

Secure by default

Enforce a security-by-default policy across every protected service.

Read the doc

Documentation

Install guides and rule tuning notes to help you get running.

Browse the docs

Inspectable security

Inspect the project, follow development, and build with CatWAF.

GitHub repository

Self-hosted control

Run CatWAF on your own infrastructure. Internal use and personal noncommercial use are permitted; managed service and redistribution use require a separate license.

Get CatWAF

Ready to protect your web services?

Deploy CatWAF in front of your application and start inspecting traffic with a dedicated Web Application Firewall.

Get CatWAF