WAAP · Web Application & API Protection

One Inline Layer That Protects Every Web App and API

GajWAF is a WAAP (Web Application & API Protection) platform — a web application firewall that inspects every request and response in line — blocking injection, bots, account takeover, API abuse and data leaks — and is run entirely from a browser console. Deploy it on-premises, in the cloud or in a container, in your own environment.

Request a Demo See Capabilities
~0.2 ms
Added latency per request
Agentless
Nothing to install on your servers
6
Compliance report packs
Active-passive
Built-in high availability
Complete WAAP
WAF · API Security · Bots · Layer-7 DoS
Deployment
On-Premises · Cloud · Container
Compliance Evidence
PCI DSS · HIPAA · GDPR · DPDP · CERT-In · ISO 27001
The Patchwork Problem

Four Tools, Four Consoles. Gaps In Between.

Most organisations stitch together a web firewall, an API gateway, a bot tool and a reporting pipeline — each bought, integrated and operated on its own. The result is more to run, more to tune, and blind spots where the products don't overlap. That is why industry analysts now treat these as one category: Web Application and API Protection, or WAAP.

Gap 1 · Watching, Not Blocking

Many tools are alert-only or inspect sampled traffic. Attacks that aren't sampled — or are only alerted on — still reach the application.

Gap 2 · Signatures Only

Signature matching misses attacks it has never seen. Zero-days and novel API abuse pass straight through until a rule is written.

Gap 3 · Data Leaves Your Control

Cloud-hosted WAF services route your traffic and logs outside your environment — and hand auditors raw logs someone has to interpret.

The Solution

GajWAF Is a Complete WAAP Platform in One Layer You Own

GajWAF combines web application protection, API security, bot defence, access control and data-leak prevention in a single inline layer — one that you run, tune and own.

Signature, behavioural and machine-learning detection work together with positive security that learns each site's normal traffic, so GajWAF catches the attacks signatures alone would miss.

Inline, Not Sampled

Full request and response inspection in the traffic path with about 0.2 ms of overhead — it blocks attacks, it doesn't just alert.

Run It From a Browser

Certificates, rules, schemas, sites, bans and reports are all managed in the console — no command line, no files to hand-edit.

Deploy Anywhere

Your own servers, the cloud or a container. No endpoint agents, no cloud dependency, works fully offline.

Audit & Compliance Ready

Branded, scheduled reports and evidence mappings for HIPAA, PCI DSS, GDPR, India DPDP/CERT-In and ISO 27001.

The Console

Your Protection at a Glance

The GajWAF dashboard shows what's being blocked, which sites are protected and what needs your attention — all in the browser, with no command line.

GajWAF WAAP dashboard showing a health banner, requests over the last 7 days, attacks blocked, sites protected, and counts for policy blocks, rate-limited requests, bans, browser checks and security events
Health at the top, detail below. Attacks blocked, rate-limited traffic, bans and policy blocks are counted separately, and anything that needs action — like expiring certificates — is flagged first.
The Difference

Why GajWAF Is Different

How GajWAF as a single WAAP layer compares with the typical stitched-together approach.

Typical ApproachGajWAF
One layer, not manySeparate products for web attacks, APIs, bots and access — each bought, integrated and operated on its ownWeb apps, APIs, bots, access control and data-leak prevention in a single layer
Enforce, don't just watchOften alert-only or inspecting sampled traffic, leaving gapsInline on every request and response — it blocks, with negligible added latency
Anyone can run itSpecialists, command-line tooling and risky manual rule editsGuided browser console, watch-only mode, one-click undo and one-click fixes for false alarms
Catches the unknownSignature matching only — misses attacks it has never seenSignatures plus behaviour, machine learning and a model that learns each site's normal traffic
Your data stays yoursCloud service where your traffic and logs leave your controlRuns in your own environment — on-premises, cloud or offline — so data never leaves it
Proof, not just logsRaw logs that someone has to collect and interpretBoard-ready and compliance-mapped reports, generated on demand or scheduled and emailed
Capabilities

Six WAAP Pillars: Web, API, Bot & Data Protection

Threat detection, API security, bot and abuse defence, data protection, access control and operations — in a single firewall.

01

Threat Protection & Machine Learning

Signature, anomaly-scoring and machine-learning detection work together — with per-endpoint baselines that flag requests that don't look like a site's normal traffic, even when no signature matches.

  • OWASP Top 10 and OWASP API Security Top 10 coverage
  • SQL injection, XSS, remote code execution, path traversal, SSRF and more
  • Anomaly scoring with a configurable blocking threshold and custom rules
  • Virtual patching for zero-days via signed, verified rule updates
  • Successful-attack detection — flags responses that prove a compromise
  • Machine-learning detection of attack-like requests (monitor or enforce)
  • Positive-security learning — per-endpoint baselines flag deviations
  • Behavioural analysis of request, session and client activity
  • Technology fingerprinting with auto-applied protection packs
  • Known-vulnerability & end-of-life software detection; import existing IPS rulesets
02

API Security

Enforce each API's contract, verify tokens and keys, and stop abuse, scraping and malformed requests before they reach the service.

  • OpenAPI / Swagger schema validation (report or enforce)
  • XML / SOAP validation against XSD & WSDL
  • Automatic API discovery from observed traffic
  • JWT verification and API-key enforcement with per-key limits
  • GraphQL guards: depth, aliases, batch limits, introspection block
03

Bots, Layer-7 DoS & Account Takeover

Challenge automated traffic, absorb application-layer floods and defeat credential abuse on login and checkout — without storing passwords.

Bots & DoS

  • Browser challenge & emergency mode; verified search crawlers are exempt
  • Bot traps and security-scanner detection
  • Country rules, IP reputation / threat-intelligence feeds and hosting-network scoring
  • Absorbs Layer-7 request floods
  • Adaptive rate limiting per site, stricter on sign-in endpoints
  • One-click emergency mode during a targeted attack
  • Automatic bans for floods, brute force and scanning
  • Request size, count and timing limits against resource exhaustion

Account takeover

  • Credential stuffing — one client failing across many accounts
  • Password spraying — one password tried across many accounts
  • Protects an account under attack from many clients
  • Flags suspicious successful sign-ins (e.g. from a new country)
  • Passwords are never stored or logged
04

Data-Leak, Client-Side & Malware Protection

Stop sensitive data leaving in responses, watch the scripts running on your pages, and block infected uploads before they reach the application.

  • Data-leak prevention — mask or block card numbers, database errors, stack traces, keys, cloud credentials & custom patterns
  • Security response headers, content-security policy and backend-fingerprint stripping
  • Anti-defacement monitoring with serve-last-good-copy
  • Hidden-field tampering & page-flow (forced-browsing) protection
  • Detects formjacking and card skimming (Magecart) via third-party script monitoring
  • Supports PCI DSS 4.0 client-side requirements (6.4.3 / 11.6.1)
  • Antivirus scanning of form uploads and raw file bodies
  • Fail-open or fail-closed when the scanner is unavailable; full scan audit trail
05

Access & Authentication

Put a modern login in front of internal or legacy applications using your existing directory — with no change to the application.

  • Sign-in gateway (SSO) in front of any app — LDAP / Active Directory, RADIUS and OpenID Connect
  • Console two-factor authentication, users-only mode and enforced 2FA
  • Role-based access (admin / analyst / viewer), site-scoped accounts, full activity audit
06

Operations, Availability & Reporting

A guided browser console, live changes with no dropped connections, built-in high availability and reports your auditors and board can actually read.

  • Console with Simple & Advanced modes, security presets and a setup wizard
  • One-click configuration undo with full version history
  • One-click false-alarm tuning from any event
  • TLS termination with automatic certificate issuance & renewal and HSTS
  • Load balancing, health checks, session persistence & graceful draining
  • High availability — active-passive clustering, floating virtual IPs, encrypted state sync
  • Searchable event store, CSV export and audit stream for SIEM
  • Alerts (email / webhook) for attack spikes, bans, outages, certificate expiry & config changes
  • Branded PDF / HTML / CSV reports, scheduled & emailed, for management, security or developers
Account Takeover Patterns

Three Ways Attackers Abuse Logins — All Detected

Login and checkout pages are where stolen and guessed credentials get tested. GajWAF recognises each pattern of credential abuse — without ever storing or logging a password.

Pattern 1
One client → many accounts

Credential Stuffing

A single client works through stolen username-and-password pairs, failing across many different accounts as it hunts for the ones that still work.

✓ Detected: one client failing across many accounts
Pattern 2
One password → many accounts

Password Spraying

One common password is tried once against many accounts — a slow, quiet approach meant to stay under per-account lockout limits.

✓ Detected: one password tried across many accounts
Pattern 3
Many clients → one account

Distributed Account Attack

Attempts on a single account are spread across many clients, so no one source looks suspicious on its own.

✓ Detected: one account under attack from many clients
And when a login does succeed: GajWAF flags suspicious successful sign-ins — for example, from a new country. Passwords are never stored or logged.
Coverage

What GajWAF Stops

The attack and abuse classes GajWAF detects and blocks across web applications and APIs.

Injection & Exploitation

SQL injection, cross-site scripting (XSS), remote code execution, command injection, path traversal / LFI, SSRF, XXE, template injection (SSTI), insecure deserialization, open redirect and remote file inclusion.

Bots & Abuse

Automated bots & crawlers, content scraping, credential stuffing, password spraying, account takeover, brute force, Layer-7 request floods, vulnerability scanners and carding / fraud probes.

API, Data & Integrity

API schema / contract violations, unauthorized API access, GraphQL abuse, sensitive-data exposure, malware uploads, web defacement, client-side script injection (Magecart), and known-CVE & end-of-life software.

Use Cases

Where Teams Put GajWAF to Work

From legacy apps that can't be patched to APIs, logins and compliance audits.

Protect Apps You Can't Patch

Shield legacy, third-party or unpatched applications from known and zero-day exploits with virtual patching — without touching the code.

Secure Your APIs

Enforce each API's contract, verify tokens and keys, and stop abuse, scraping and malformed requests before they reach the service.

Stop Account Takeover

Defeat credential stuffing, password spraying and bots on login and checkout, and flag suspicious sign-ins — without storing passwords.

Meet Compliance

Satisfy the web-application control in PCI DSS, HIPAA, GDPR and India's DPDP, and hand auditors mapped evidence reports on demand.

Add Single Sign-On

Put a modern login in front of internal or legacy applications using your existing directory — no change to the application.

Ride Out an Attack

Turn on emergency mode in one click during a flood or targeted campaign — every visitor passes a quick check until the storm passes.

Deployment

Deploy the Way You Run

GajWAF sits inline in front of your applications and runs wherever they do — a self-hosted WAAP with one layer, no agents and no cloud dependency.

On-Premises

On a GajShield Firewall Appliance, your own server or a virtual machine — in front of your servers, fully inside your network.

Public or Private Cloud

Run the same software on Microsoft Azure, AWS or any other cloud or region — no vendor lock-in.

Container

Run it alongside your containerised applications and services.

High-Availability Pair

Active-passive with a floating address and automatic failover for zero-downtime protection.

Specifications

Technical Specifications

Form factorInline software appliance. Installs on your own servers, as a container, or through the included installer.
PlatformsGajShield Firewall Appliances, virtual machines, and public cloud on Microsoft Azure and AWS. No endpoint agents and no separate database to run.
DeploymentOn-premises, private or public cloud, or container. Air-gap and offline updates supported.
PerformanceAbout 0.2 ms added inspection latency per request; configuration changes apply live with no downtime.
ProtocolsHTTP/1.1, HTTP/2 and HTTPS; TLS 1.2–1.3; WebSocket pass-through. Multiple sites / virtual hosts per instance.
TLS & certificatesPer-site certificates (upload in the console or automatic issuance & renewal), HSTS, HTTP→HTTPS redirect, private-CA trust for backends.
High availabilityActive-passive clustering with floating virtual IPs and encrypted state sync (configuration, bans, users).
Protection modesPer site: block, watch-only or off; relaxed / balanced / strict security presets.
ManagementHTTPS web console (light/dark), API for automation, role-based access and two-factor authentication.
IntegrationsLDAP / Active Directory, RADIUS and OpenID Connect sign-in; antivirus for upload scanning; location (GeoIP) data; email & webhook alerting; import of existing IPS rulesets.
LoggingBuilt-in searchable event store with configurable retention, CSV export, and an audit log for SIEM forwarding.
Standards

Compliance & Reporting

Generate audience-specific and compliance-mapped reports that document GajWAF's active controls as evidence toward each framework — with a Met / Partial / Gap assessment against each requirement.

HIPAASecurity Rule
PCI DSS v4.0Req 6.4.2
GDPRArticle 32
India DPDP Act2023
CERT-In Directions2022
ISO/IEC 270012022
Reports map the firewall's technical controls — encryption in transit, data-leak prevention, access control, logging & retention, malware protection and authentication — to each framework's requirements. They are supporting evidence, not a certification, and do not cover organisational, physical or application-level controls outside the WAF.
Get Started

Put One Layer in Front of Every App and API

Talk to a GajShield expert about protecting your web applications and APIs with GajWAF, GajShield's WAAP platform — on-premises, in the cloud or in a container.

Request a Demo See Capabilities See the Full Firewall