Managed application-protection product

Protect approved web applications with a managed WAF service.

Svalinn provides managed web application firewall policy, tuning and operational visibility for approved applications, with customer-safe status, events and follow-up presented through Guardian.

Product position

Optional managed web application protection

Svalinn is separately entitled by approved website or application scope, traffic profile and service tier. The underlying WAF technology may vary according to the approved architecture.

01

Customer-safe delivery

Customers work through Guardian rather than being forced into disconnected technical consoles.

02

Governed scope

Entitlements, targets, users, data sources, schedules and service commitments are recorded in the applicable package schedule.

03

Accountable outcomes

Material findings can be linked to risks, owners, due dates, All Actions, evidence and remediation review.

Product capabilities

What the product provides through Guardian.

WP

WAF policy

Managed application-security policy is applied to the approved website or application scope.

TN

Tuning

Rules and exclusions are reviewed to reduce avoidable disruption while retaining protection.

AT

Attack visibility

Approved blocked, challenged and monitored activity is summarised through customer-safe records.

BC

Bot and category controls

Supported bot, rate and traffic controls can be applied where included in the selected architecture.

CH

Change handling

Policy changes, exclusions and application updates follow the agreed approval and support model.

GR

Guardian follow-up

Material protection issues can be linked to risks, All Actions, owners and reporting.

Operating model

How the capability is delivered.

Damocles manages the approved WAF configuration and operational review while Guardian provides customer visibility and accountable follow-up.

Svalinn can complement Katana testing: Katana identifies application weaknesses while Svalinn provides ongoing traffic-layer protection.

Providers can package Svalinn with Guardian Core and other managed protection modules for authorised customers.

Commercial and service boundaries

What must be confirmed before activation.

Protected applications, traffic, certificates, origin architecture, rules, bot controls, logging, retention, support and change responsibilities must be defined.

No claim is made that a WAF prevents every application attack, eliminates secure-development requirements or replaces penetration testing.

Major application remediation, code changes and incident response remain separately scoped unless expressly included.

Product selection

Map the product to the customer operating model.

We will confirm the package relationship, covered scope, licensing unit, service level, reporting and any separately scoped engineering or professional services.

Svalinn Managed Web Application Firewall | Damocles Security