Optional managed application protection

Put a managed protection layer in front of web applications and keep it tuned.

Svalinn combines compatible web application firewall technology with Damocles policy, tuning, change handling, traffic visibility and Guardian follow-up.

Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Vendor-neutral WAF modelManaged application policyRule tuning and exceptionsTraffic and attack visibility
Buyer decision summary

Know what Svalinn Managed Web Application Firewall does, what the customer sees and what Damocles is responsible for before activation.

Guardian retains protected-site state, policy and change records, material event summaries, exceptions, actions and approved evidence. Credentials, certificates, keys, raw requests and unrestricted platform payloads remain restricted.

The proposal identifies protected sites or applications, domains, origins, certificates, traffic or request assumptions, policy, bot and rate controls, logging, retention, support, changes and the selected compatible WAF platform.

Coverage depends on the protected traffic path, selected compatible platform, policy, origin architecture, certificate and service availability.

01

What the product does

Available controls depend on the selected compatible WAF platform, traffic architecture and service tier.

02

What the customer sees

Raw platform detail remains available to authorised operators while Guardian provides the business and service view.

03

What Damocles manages

Application remediation and secure-development work remain separate from traffic-layer protection.

The operational problem

A WAF can block useful traffic as easily as malicious traffic if nobody understands the application or maintains the policy.

Default rules provide a starting point, but authentication, APIs, uploads, integrations, bots, rate patterns and regular application releases create false positives and protection gaps. A useful managed WAF service must understand the application and control policy change.

Svalinn is the Damocles managed product. The compatible WAF platform is selected according to the application architecture and commercial schedule. Guardian provides the customer view of protected scope, service state, material events, changes and required actions.

01

Reduce common application attacks

Apply approved rules and controls in front of the protected website or API before traffic reaches the origin.

02

Tune without weakening protection

Review false positives, exclusions and application changes through a controlled policy process.

03

Make material activity actionable

Connect attack patterns, application gaps or policy issues to Guardian actions and deeper testing where needed.

Product capability

Managed traffic-layer protection for approved web applications.

Available controls depend on the selected compatible WAF platform, traffic architecture and service tier.

WP

WAF policy

Apply managed application-security rules to the approved website, API or application scope.

TN

Rule tuning

Review false positives, application-specific behaviour, exclusions and policy changes.

RT

Rate and traffic controls

Apply supported rate, request, geographic or traffic controls where included in the selected platform.

BT

Bot controls

Use supported bot classification and challenge controls where available and approved.

AV

Attack visibility

Present blocked, challenged and monitored activity through customer-readable Guardian records.

CH

Change management

Coordinate certificates, origins, routing, releases, exceptions and policy updates.

What the customer sees

Customers see which applications are protected, what changed and which activity requires follow-up.

Raw platform detail remains available to authorised operators while Guardian provides the business and service view.

PS

Protected-site status

Application, domain, origin, certificate, service health and current managed-policy state.

PA

Policy activity

Blocked, challenged, monitored and allowed activity by supported category and protected site.

ME

Material events

Customer-readable attack patterns, affected application context and required investigation or remediation.

EX

Exceptions and exclusions

Approved rule exclusions, owners, rationale, affected paths and review dates.

CL

Change log

Certificate, origin, policy, routing and application-change history relevant to service operation.

RP

Service reporting

Protected scope, service health, material activity, tuning, exceptions and unresolved customer actions.

What Damocles manages

Damocles manages the approved WAF policy, tuning and service operation.

Application remediation and secure-development work remain separate from traffic-layer protection.

DD

Deployment design

Review application architecture, origin, certificates, traffic, authentication, APIs and availability requirements.

PO

Policy operation

Configure and maintain approved rules, modes, rate controls, bot controls and exclusions.

HM

Health monitoring

Track protected-site, origin, certificate, routing and connector conditions required for service.

ER

Event review

Review material attack or policy activity and identify required customer or provider action.

TM

Tuning and change

Test and apply approved tuning for releases, false positives, integrations and business requirements.

SR

Service review

Report service health, protection scope, material activity, changes, exceptions and recommended follow-up.

Operating lifecycle

From application discovery to managed protection and controlled tuning.

The onboarding and change process is designed to reduce avoidable application disruption.

01

Discover

Map applications, origins, domains, certificates, APIs, authentication, traffic and critical user journeys.

02

Design

Select the compatible WAF implementation and define policy, modes, controls, logging and rollback.

03

Pilot

Validate routing, certificates, origin health, application behaviour, rules and false positives.

04

Protect

Move the approved application scope behind the managed policy and monitor health.

05

Tune and respond

Review material activity, exceptions, application changes and required customer action.

06

Report and improve

Retain change history, service evidence and recommendations for testing or remediation.

Common use cases

Common managed-WAF use cases.

Svalinn can complement development, testing and incident-response activity without replacing them.

BA

Business web application

Protect a customer-facing application where the business needs managed policy and change support.

AP

API protection

Apply supported request, rate and attack controls in front of approved API traffic.

MS

MSP customer portfolio

Operate authorised customer applications, service health, policy, changes and wholesale entitlements.

KA

Katana follow-up

Use active-testing findings to improve WAF policy while the application owner fixes the underlying weakness.

IR

Incident containment support

Apply approved temporary traffic controls while investigation or remediation proceeds.

MG

Application migration

Protect and monitor an application during hosting, origin, DNS or platform transition.

Operating model

How Svalinn Managed Web Application Firewall is onboarded, integrated, evidenced and scoped commercially.

These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.

ON

Onboarding and implementation

Onboarding requires application context, traffic control and a safe change plan. Damocles documents the application, domains, origin addresses, certificates, DNS, hosting, APIs, authentication, uploads, integrations, traffic patterns, availability, deployment pipeline, maintenance windows and support contacts. The pilot validates routing, certificates, origin health, application journeys, rules, false positives, logging, failover and rollback. Critical functions are tested before broad enforcement is applied. Go-live includes protected scope, policy ownership, change workflow, exception approval, release notification, incident contacts, health monitoring, reporting and the boundary to application remediation and testing.

IN

Connector and integration model

Svalinn remains the managed product while the compatible WAF implementation can vary. A supported WAF connector must expose protected applications, service and origin health, policy state, supported traffic activity, changes and safe error information. The selected implementation may be cloud, hosted, customer-owned or provider-operated. The proposal names the selected platform, traffic or request basis, included controls, logging and service responsibility. The public website does not present that third-party platform as the product. A new compatible WAF option is reviewed for routing, certificates, origin security, logging, policy control, tenant isolation, API maturity, event quality, supportability and commercial impact.

EV

Data, evidence and reporting

Service records support customer review without exposing unsafe request or platform detail. Guardian retains protected-site state, policy and change records, material event summaries, exceptions, actions and approved evidence. Credentials, certificates, keys, raw requests and unrestricted platform payloads remain restricted. A blocked request is not automatically represented as a confirmed attack. Material patterns may require application, endpoint or security-operations investigation before a conclusion is recorded. Reports show service and origin health, changes and unavailable states so a failed or bypassed protection path is not represented as healthy coverage.

CM

Commercial unit and responsibilities

Commercial scope follows protected applications, traffic profile and managed-service tier. The proposal identifies protected sites or applications, domains, origins, certificates, traffic or request assumptions, policy, bot and rate controls, logging, retention, support, changes and the selected compatible WAF platform. Traffic growth, advanced controls, large-scale bot management, emergency response, major application changes, code remediation and penetration testing may require separate pricing or approval. The customer owns application behaviour, release communication, business exceptions and remediation. Damocles owns the managed WAF activities listed in the service schedule.

Frequently asked questions

Questions buyers ask about Svalinn Managed Web Application Firewall.

The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.

Q1

Can Svalinn use our existing WAF?

Potentially, where a supported connector and operating model provide the policy, health, event and change controls required.

Q2

Does a WAF replace secure coding?

No. It reduces traffic-layer exposure but cannot fix vulnerable code, unsafe business logic or architecture.

Q3

How are false positives handled?

Damocles reviews the affected application path, evidence and business requirement before an approved exclusion or tuning change is applied.

Q4

Can it protect APIs?

Yes where the selected compatible platform, routing and policy support the required API traffic and controls.

Q5

Can an MSP manage customer sites?

Yes through authorised provider relationships, customer ownership, explicit entitlements and agreed support responsibilities.

Q6

What happens during an outage?

Routing, origin, failover, support and rollback are defined during design, and Guardian shows degraded or unavailable state.

Scope and boundaries

Svalinn is a managed protection layer, not a guarantee that every attack is prevented.

Coverage depends on the protected traffic path, selected compatible platform, policy, origin architecture, certificate and service availability.

The product does not replace secure development, application testing, code review, incident response or remediation of the underlying weakness.

Application changes, traffic growth, unsupported protocols, advanced bot programs and emergency engineering remain outside scope unless listed in the service schedule.

Take the next practical step

Review the applications that need a managed protection layer and controlled policy change.

We will map the application architecture, traffic, origin, certificates, policy, current WAF, support model and Guardian reporting requirements.