CatWAF — a source-available web application firewall
Protect your web services with CatWAF, a modern Web Application Firewall. CatWAF acts as a shield in front of your applications and blocks malicious requests before they ever reach your origin.
Placed as a reverse proxy while offering Web Application Firewall (WAF) functionality, CatWAF integrates into your existing infrastructure to secure your web services.
CatWAF helps defend against common web threats such as those listed in the OWASP Top 10, blocks malicious traffic, and gives you real security controls over your applications.
Use it as a single entry point for your web services and manage incoming traffic and HTTP security policy from one place.
More info on how to install CatWAF on Linux, Docker and your existing infrastructure in our documentation.
CatWAF is built around transparency, auditable security, and control. The security layer stays inspectable, so operators can understand exactly what protects their applications.
CatWAF Free uses the PolyForm Internal Use License 1.0.0, with additional permission for personal noncommercial use. Managed service operation and redistribution require a separate commercial license.
Why inspect the source?
CatWAF puts transparency at the core of its security model, so you can understand the protection applied to your web services.
Make security controls understandable and verifiable, so operators can build real confidence in what guards their applications.
Explore CatWAF by running it yourself. Discover the dashboard, WAF protection, rules, logs, and the ecosystem around the project.
Manage and configure CatWAF from a clean web interface — rules, traffic, and logs in one place.
Read the docInspect the project, follow development, and build with CatWAF.
GitHub repositoryRun CatWAF on your own infrastructure. Internal use and personal noncommercial use are permitted; managed service and redistribution use require a separate license.
Get CatWAF