Customer-safe delivery
Customers work through Guardian rather than being forced into disconnected technical consoles.
Svalinn provides managed web application firewall policy, tuning and operational visibility for approved applications, with customer-safe status, events and follow-up presented through Guardian.
Svalinn is separately entitled by approved website or application scope, traffic profile and service tier. The underlying WAF technology may vary according to the approved architecture.
Customers work through Guardian rather than being forced into disconnected technical consoles.
Entitlements, targets, users, data sources, schedules and service commitments are recorded in the applicable package schedule.
Material findings can be linked to risks, owners, due dates, All Actions, evidence and remediation review.
Managed application-security policy is applied to the approved website or application scope.
Rules and exclusions are reviewed to reduce avoidable disruption while retaining protection.
Approved blocked, challenged and monitored activity is summarised through customer-safe records.
Supported bot, rate and traffic controls can be applied where included in the selected architecture.
Policy changes, exclusions and application updates follow the agreed approval and support model.
Material protection issues can be linked to risks, All Actions, owners and reporting.
Damocles manages the approved WAF configuration and operational review while Guardian provides customer visibility and accountable follow-up.
Svalinn can complement Katana testing: Katana identifies application weaknesses while Svalinn provides ongoing traffic-layer protection.
Providers can package Svalinn with Guardian Core and other managed protection modules for authorised customers.
Protected applications, traffic, certificates, origin architecture, rules, bot controls, logging, retention, support and change responsibilities must be defined.
No claim is made that a WAF prevents every application attack, eliminates secure-development requirements or replaces penetration testing.
Major application remediation, code changes and incident response remain separately scoped unless expressly included.
We will confirm the package relationship, covered scope, licensing unit, service level, reporting and any separately scoped engineering or professional services.