WAFY
Home › Subscription Services

Managed Advanced WAF, your way.

WAFY manages and runs your F5 Advanced WAF (ASM) policies. Choose a feature tier for the depth of protection, and the number of policies you need managed. The two are priced independently, so a single policy can have the full feature set. We handle signatures, tuning, learning reviews, false positives, OWASP alignment and reporting.

Explainer Short walkthrough, coming soon
Tiers and pricing

Pick a feature tier, and how many policies.

Basic, Standard and Premier set how much of the F5 Advanced WAF toolkit we apply (cumulative). The number of policies sets the scale. The two are priced independently, and both the tiers and the full price grid are right here.

Most subscribed
Feature tier How much of the F5 Advanced WAF toolkit we apply.
Basic
Core managed protection
From £3,000 /year
1 policy; volume pricing below
Included
  • WAFY manages and runs the policy
  • Signature updates, staged monthly
  • Learning reviews, false positives resolved
  • Core protections, every change staged
Standard
The fuller ASM toolkit
From £3,500 /year
1 policy; volume pricing below
Everything in Basic, plus
  • Data Guard, CSRF, hostname handling
  • Parameters, including sensitive
  • Complex API policies (methods / content)
  • Tighter entities and OWASP reporting
Premier
The full advanced feature set
From £4,000 /year
1 policy; volume pricing below
Everything in Standard, plus
  • Bot defence and bot defence tuning
  • Brute force, header and login protections
  • DDoS, IP intelligence, geolocation
  • AV / ICAP, parent policies, templates
Then choose how many policies
1 policy Possible pilot
£3,000
£3,500
£4,000
2 policies
£5,000
£5,750
£6,500
3 policies
£6,500
£7,500
£8,500
4 policies
£8,000
£9,000
£10,000
5 policies
£9,000
£10,250
£11,250
6 policies
£10,000
£11,250
£12,000

Scroll sideways to see every tier →

Feature tier sets how much of the F5 Advanced WAF toolkit we apply; each card shows that tier's price per number of policies.

Basic
Core managed protection
From £3,000 /year
Included
  • WAFY manages and runs the policy
  • Signature updates, staged monthly
  • Learning reviews, false positives resolved
  • Core protections, every change staged
Then choose how many policies
1 policy Possible pilot£3,000
2 policies£5,000
3 policies£6,500
4 policies£8,000
5 policies£9,000
6 policies£10,000
Most subscribed
Standard
The fuller ASM toolkit
From £3,500 /year
Everything in Basic, plus
  • Data Guard, CSRF, hostname handling
  • Parameters, including sensitive
  • Complex API policies (methods / content)
  • Tighter entities and OWASP reporting
Then choose how many policies
1 policy Possible pilot£3,500
2 policies£5,750
3 policies£7,500
4 policies£9,000
5 policies£10,250
6 policies£11,250
Premier
The full advanced feature set
From £4,000 /year
Everything in Standard, plus
  • Bot defence and bot defence tuning
  • Brute force, header and login protections
  • DDoS, IP intelligence, geolocation
  • AV / ICAP, parent policies, templates
Then choose how many policies
1 policy Possible pilot£4,000
2 policies£6,500
3 policies£8,500
4 policies£10,000
5 policies£11,250
6 policies£12,000
Running more than six policies? Most production estates have dozens, even hundreds, of ASM policies. One policy is simply how a pilot starts, prove the service on a single application, then scale. We price larger estates on the same basis; talk to us for a volume quote beyond six.

Small print: attack signature updates are applied per device, so an update covers every ASM policy on the BIG-IP, not only those you place under management. Where a device carries more policies than you manage with WAFY (say 18 on the box, 6 managed), the remaining policies are handled as a fixed-price job.

Two choices, one price. The feature tier sets the depth of protection; the policy count sets the scale. They are independent, so a single high-value application can run on Premier, and a large estate can stay on Basic. Prices are annual, in GBP, exclude VAT, and are provisional. Full grading is on the ASM feature matrix.

How the managed service works

We manage the policies. You keep control of the estate.

You give WAFY access to the policies in scope. From then on we run them: proactive work on a cadence, plus your change requests as they come up. Every change is documented for audit.

Proactive, on a cadence

Signature updates applied and staged, learning suggestions reviewed, false positives resolved against live traffic, event logs reviewed and reported, OWASP alignment kept current. Monthly on Basic and Standard, weekly on Premier.

Your change requests

New entities, tightened enforcement, a selective bypass, onboarding another application: raise it and WAFY makes the change, tests it and documents it. No ticket portal, direct to the engineers running your policies.

Built-in flexibility

A managed service that flexes with you.

Add policies as new applications go live, or step up a feature tier when an application needs deeper protection, and keep the same engineer throughout. More policies means a lower effective price per policy.

  • Add or remove policies as your estate changes, and step up a tier when an application needs deeper protection.
  • Renews annually, with a posture review before it does, so you re-commit on evidence.
  • Keep the record. Your policy configuration and its documentation stay yours; we never hold your keys longer than the work needs.
  • The same engineer every month. The person who tuned your policy last month is the person who answers for it this month.
What's included each month

The work of keeping a WAF policy healthy, done for you.

An Advanced WAF policy is not "set and forget". Signatures move, applications change, and false positives creep in. This is the ongoing work WAFY takes off your team's plate.

Apply, stage and promote the latest attack signature updates.
Work through learning suggestions and accept or refine them.
Resolve false positives against real traffic, without weakening protection.
Tune entities: URLs, file types, parameters and cookies.
Review event logs and report on what was seen and done.
Keep OWASP alignment current and evidence it.
Make your change requests, tested and documented.
Sample monthly activityIllustration only
Signature update, staged and promotedDone
Learning suggestions reviewed, retail policyDone
False-positive tuning, checkout parameterIn progress
Change request: onboard new API policyScheduled
Onboarding a policy

From "switched on but untrusted" to enforcing, safely.

Whether we build a policy new or take on one you already have, the path to reliable blocking is the same, and we walk it with you.

Review

We baseline the policy or the application: what is enforced, what is missing, where the risk sits.

Learn

The policy runs in learning against real traffic, building an accurate model of the application.

Stage

Signatures and entities are held in staging and reviewed for false positives before they bite.

Block

Enforcement is moved to blocking at a pace your traffic supports, then kept healthy every month.

Need a policy built or reviewed as a one-off first? See the fixed-price ASM services.

Procurement will ask

Frequently asked questions.

Is this a managed service?
Yes. WAFY manages and runs your Advanced WAF (ASM) policies: signatures, tuning, learning reviews, false positives, OWASP alignment, reporting and your change requests. Your team keeps ownership of the estate and sets priorities; we do the policy work.
What exactly is a "policy"?
One F5 Advanced WAF (ASM) policy, typically protecting one application or API. Your tier is the number of policies WAFY manages: 1 on Basic, 3 on Standard, 6 on Premier.
Can we start with one policy and add more later?
Yes. Add policies whenever you place another application under management, and pick the feature tier each one needs. The two are independent, so a single policy can run on Premier, and more policies lower the effective price per policy. The full grid is above.
How soon can you start?
Quickly. We baseline or build the policy, run it through learning and staging, and move it to blocking at a pace your traffic supports. Most policies are under active management within days of the introduction.
Who actually does the work?
A 401-certified F5 engineer and OWASP member, with 30 years across development, mid-tier and backend systems, now including modern API and MCP work. The person who tunes your policy is the person who answers for it.
How do the tiers map to features?
Every capability, and how it is graded per tier, is set out on the ASM feature matrix. Higher tiers add entities, API policy depth and the advanced protections.
Do you have a client limit?
No. WAFY is not slot-limited. Each policy is managed on its own cadence, so we can take on your applications whenever you are ready.
Get started

Ready to have your Advanced WAF run for you?

Tell us how many applications you protect and what state the policies are in. We'll tell you which tier fits and how quickly we can pick them up.