WAFY manages and runs your F5 Advanced WAF (ASM) policies. Choose a feature tier for the depth of protection, and the number of policies you need managed. The two are priced independently, so a single policy can have the full feature set. We handle signatures, tuning, learning reviews, false positives, OWASP alignment and reporting.
Basic, Standard and Premier set how much of the F5 Advanced WAF toolkit we apply (cumulative). The number of policies sets the scale. The two are priced independently, and both the tiers and the full price grid are right here.
Scroll sideways to see every tier →
Feature tier sets how much of the F5 Advanced WAF toolkit we apply; each card shows that tier's price per number of policies.
Small print: attack signature updates are applied per device, so an update covers every ASM policy on the BIG-IP, not only those you place under management. Where a device carries more policies than you manage with WAFY (say 18 on the box, 6 managed), the remaining policies are handled as a fixed-price job.
Two choices, one price. The feature tier sets the depth of protection; the policy count sets the scale. They are independent, so a single high-value application can run on Premier, and a large estate can stay on Basic. Prices are annual, in GBP, exclude VAT, and are provisional. Full grading is on the ASM feature matrix.
You give WAFY access to the policies in scope. From then on we run them: proactive work on a cadence, plus your change requests as they come up. Every change is documented for audit.
Signature updates applied and staged, learning suggestions reviewed, false positives resolved against live traffic, event logs reviewed and reported, OWASP alignment kept current. Monthly on Basic and Standard, weekly on Premier.
New entities, tightened enforcement, a selective bypass, onboarding another application: raise it and WAFY makes the change, tests it and documents it. No ticket portal, direct to the engineers running your policies.
Add policies as new applications go live, or step up a feature tier when an application needs deeper protection, and keep the same engineer throughout. More policies means a lower effective price per policy.
An Advanced WAF policy is not "set and forget". Signatures move, applications change, and false positives creep in. This is the ongoing work WAFY takes off your team's plate.
Whether we build a policy new or take on one you already have, the path to reliable blocking is the same, and we walk it with you.
We baseline the policy or the application: what is enforced, what is missing, where the risk sits.
The policy runs in learning against real traffic, building an accurate model of the application.
Signatures and entities are held in staging and reviewed for false positives before they bite.
Enforcement is moved to blocking at a pace your traffic supports, then kept healthy every month.
Need a policy built or reviewed as a one-off first? See the fixed-price ASM services.
Tell us how many applications you protect and what state the policies are in. We'll tell you which tier fits and how quickly we can pick them up.