What the product does
Available controls depend on the selected compatible WAF platform, traffic architecture and service tier.
Svalinn combines compatible web application firewall technology with Damocles policy, tuning, change handling, traffic visibility and Guardian follow-up.
Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
Guardian retains protected-site state, policy and change records, material event summaries, exceptions, actions and approved evidence. Credentials, certificates, keys, raw requests and unrestricted platform payloads remain restricted.
The proposal identifies protected sites or applications, domains, origins, certificates, traffic or request assumptions, policy, bot and rate controls, logging, retention, support, changes and the selected compatible WAF platform.
Coverage depends on the protected traffic path, selected compatible platform, policy, origin architecture, certificate and service availability.
Available controls depend on the selected compatible WAF platform, traffic architecture and service tier.
Raw platform detail remains available to authorised operators while Guardian provides the business and service view.
Application remediation and secure-development work remain separate from traffic-layer protection.
Default rules provide a starting point, but authentication, APIs, uploads, integrations, bots, rate patterns and regular application releases create false positives and protection gaps. A useful managed WAF service must understand the application and control policy change.
Svalinn is the Damocles managed product. The compatible WAF platform is selected according to the application architecture and commercial schedule. Guardian provides the customer view of protected scope, service state, material events, changes and required actions.
Apply approved rules and controls in front of the protected website or API before traffic reaches the origin.
Review false positives, exclusions and application changes through a controlled policy process.
Connect attack patterns, application gaps or policy issues to Guardian actions and deeper testing where needed.
Available controls depend on the selected compatible WAF platform, traffic architecture and service tier.
Apply managed application-security rules to the approved website, API or application scope.
Review false positives, application-specific behaviour, exclusions and policy changes.
Apply supported rate, request, geographic or traffic controls where included in the selected platform.
Use supported bot classification and challenge controls where available and approved.
Present blocked, challenged and monitored activity through customer-readable Guardian records.
Coordinate certificates, origins, routing, releases, exceptions and policy updates.
Raw platform detail remains available to authorised operators while Guardian provides the business and service view.
Application, domain, origin, certificate, service health and current managed-policy state.
Blocked, challenged, monitored and allowed activity by supported category and protected site.
Customer-readable attack patterns, affected application context and required investigation or remediation.
Approved rule exclusions, owners, rationale, affected paths and review dates.
Certificate, origin, policy, routing and application-change history relevant to service operation.
Protected scope, service health, material activity, tuning, exceptions and unresolved customer actions.
Application remediation and secure-development work remain separate from traffic-layer protection.
Review application architecture, origin, certificates, traffic, authentication, APIs and availability requirements.
Configure and maintain approved rules, modes, rate controls, bot controls and exclusions.
Track protected-site, origin, certificate, routing and connector conditions required for service.
Review material attack or policy activity and identify required customer or provider action.
Test and apply approved tuning for releases, false positives, integrations and business requirements.
Report service health, protection scope, material activity, changes, exceptions and recommended follow-up.
The onboarding and change process is designed to reduce avoidable application disruption.
Map applications, origins, domains, certificates, APIs, authentication, traffic and critical user journeys.
Select the compatible WAF implementation and define policy, modes, controls, logging and rollback.
Validate routing, certificates, origin health, application behaviour, rules and false positives.
Move the approved application scope behind the managed policy and monitor health.
Review material activity, exceptions, application changes and required customer action.
Retain change history, service evidence and recommendations for testing or remediation.
Svalinn can complement development, testing and incident-response activity without replacing them.
Protect a customer-facing application where the business needs managed policy and change support.
Apply supported request, rate and attack controls in front of approved API traffic.
Operate authorised customer applications, service health, policy, changes and wholesale entitlements.
Use active-testing findings to improve WAF policy while the application owner fixes the underlying weakness.
Apply approved temporary traffic controls while investigation or remediation proceeds.
Protect and monitor an application during hosting, origin, DNS or platform transition.
These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.
Onboarding requires application context, traffic control and a safe change plan. Damocles documents the application, domains, origin addresses, certificates, DNS, hosting, APIs, authentication, uploads, integrations, traffic patterns, availability, deployment pipeline, maintenance windows and support contacts. The pilot validates routing, certificates, origin health, application journeys, rules, false positives, logging, failover and rollback. Critical functions are tested before broad enforcement is applied. Go-live includes protected scope, policy ownership, change workflow, exception approval, release notification, incident contacts, health monitoring, reporting and the boundary to application remediation and testing.
Svalinn remains the managed product while the compatible WAF implementation can vary. A supported WAF connector must expose protected applications, service and origin health, policy state, supported traffic activity, changes and safe error information. The selected implementation may be cloud, hosted, customer-owned or provider-operated. The proposal names the selected platform, traffic or request basis, included controls, logging and service responsibility. The public website does not present that third-party platform as the product. A new compatible WAF option is reviewed for routing, certificates, origin security, logging, policy control, tenant isolation, API maturity, event quality, supportability and commercial impact.
Service records support customer review without exposing unsafe request or platform detail. Guardian retains protected-site state, policy and change records, material event summaries, exceptions, actions and approved evidence. Credentials, certificates, keys, raw requests and unrestricted platform payloads remain restricted. A blocked request is not automatically represented as a confirmed attack. Material patterns may require application, endpoint or security-operations investigation before a conclusion is recorded. Reports show service and origin health, changes and unavailable states so a failed or bypassed protection path is not represented as healthy coverage.
Commercial scope follows protected applications, traffic profile and managed-service tier. The proposal identifies protected sites or applications, domains, origins, certificates, traffic or request assumptions, policy, bot and rate controls, logging, retention, support, changes and the selected compatible WAF platform. Traffic growth, advanced controls, large-scale bot management, emergency response, major application changes, code remediation and penetration testing may require separate pricing or approval. The customer owns application behaviour, release communication, business exceptions and remediation. Damocles owns the managed WAF activities listed in the service schedule.
The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.
Potentially, where a supported connector and operating model provide the policy, health, event and change controls required.
No. It reduces traffic-layer exposure but cannot fix vulnerable code, unsafe business logic or architecture.
Damocles reviews the affected application path, evidence and business requirement before an approved exclusion or tuning change is applied.
Yes where the selected compatible platform, routing and policy support the required API traffic and controls.
Yes through authorised provider relationships, customer ownership, explicit entitlements and agreed support responsibilities.
Routing, origin, failover, support and rollback are defined during design, and Guardian shows degraded or unavailable state.
Coverage depends on the protected traffic path, selected compatible platform, policy, origin architecture, certificate and service availability.
The product does not replace secure development, application testing, code review, incident response or remediation of the underlying weakness.
Application changes, traffic growth, unsupported protocols, advanced bot programs and emergency engineering remain outside scope unless listed in the service schedule.
We will map the application architecture, traffic, origin, certificates, policy, current WAF, support model and Guardian reporting requirements.