WAFY
Managed F5 Advanced WAF (ASM)

Your WAF policies, managed and run for you.

WAFY is a managed F5 Advanced WAF (ASM) service. We take your ASM policies and run them: signature updates, tuning, learning reviews, false positives, OWASP alignment and reporting. You keep the estate; we keep the policies healthy.

Explainer How WAFY runs your policies, coming soon
Every policy is run by a 401-certified F5 engineer and OWASP member, with 30 years across development, mid-tier and backend systems, now including modern API and MCP work.
What WAFY is

The team that runs your Advanced WAF, so your team doesn't have to.

F5 401 (Security) certified OWASP member 30 years: dev, mid-tier, backend Modern API and MCP Signatures kept current Every change documented
A managed service

We manage and run the policies.

WAFY takes responsibility for your Advanced WAF (ASM) policies: signature updates staged and promoted, learning suggestions reviewed, false positives resolved, OWASP alignment kept current, and reporting back to you on a cadence.

Deep, hands-on expertise

Run by a 401-certified engineer and OWASP member.

Thirty years across development, mid-tier and backend systems, now including modern API and MCP work, focused on one thing: building and running F5 Advanced WAF policies that actually enforce. You keep ownership of the estate; we keep the policies healthy and documented.

How it works

Three steps, and your WAF is looked after.

Policy introduction / handover

Pick a tier by how many policies you need managed, then introduce us to them. We baseline what is already there, or build new policies from scratch. No new vendor to onboard, no recruitment.

We run and review them

We analyse the event logs and work through the learning suggestions, apply and stage signature updates, resolve false positives and keep OWASP alignment current, all on a cadence, plus your change requests as they come up. Monthly on Basic and Standard, weekly on Premier.

You get reports, and proposed changes

Every change is documented for audit, and you get a regular report on what was seen and done, plus the changes we propose next for your sign-off. And because every change is staged and reviewed against live traffic before it enforces, nothing we do introduces issues.

Why WAFY exists

You pay for the work, not the waiting.

Building an F5 Advanced WAF policy is an incremental job, not an all-day one. It comes in short passes spread over days or weeks, paced by how quickly real traffic arrives.

Initial phase

The policy is opened up and starts learning from your live traffic. We work through the first, and largest, batch of suggestions, keeping what belongs and removing what does not.

Second phase

As more traffic arrives, we tighten the policy and turn on further protections, clearing the smaller batches of suggestions it raises. Shorter passes, more of them.

Final phase

The policy settles. New traffic rarely raises anything new, so we simply check in from time to time and keep it current.

The duration of each phase depends on the amount of traffic your application sees, not on a fixed schedule.

This is the point: it never takes all day. It might be ten minutes a day for a week, an hour a day the next, or a quiet week followed by a busier one. The work is short and intermittent, an hour or two a day at most, because it is paced by real traffic, not by how long an engineer sits at the keyboard.

A contractor

You pay for the waiting.

Bring in a contractor to build ASM policies for ten applications and you pay for full days, half of which are spent doing nothing, just waiting for real traffic before the next pass.

WAFY

You pay for the work.

WAFY runs many policies at once and checks each on the cadence it needs, daily for a new policy, weekly for a settled one, then moves on while yours waits for traffic. You pay for the time the work actually takes, never for someone sitting idle between passes.

A fraction of the cost, and a better policy.

Because the waiting is shared across every policy we run, you get expert, OWASP-compliant policy work for far less than a dedicated contractor would cost, and it is done more thoroughly. You are paying for the time, not for the person.

Managed tiers

Three feature tiers. Any number of policies.

Pick the feature tier for the depth of protection, then the number of policies, priced independently, both shown below. See what each tier grades on the ASM feature matrix.

Most subscribed
Feature tier How much of the F5 Advanced WAF toolkit we apply.
Basic
Core managed protection
From £3,000 /year
1 policy; volume pricing below
Included
  • WAFY manages and runs the policy
  • Signature updates, staged monthly
  • Learning reviews, false positives resolved
  • Core protections, every change staged
Standard
The fuller ASM toolkit
From £3,500 /year
1 policy; volume pricing below
Everything in Basic, plus
  • Data Guard, CSRF, hostname handling
  • Parameters, including sensitive
  • Complex API policies (methods / content)
  • Tighter entities and OWASP reporting
Premier
The full advanced feature set
From £4,000 /year
1 policy; volume pricing below
Everything in Standard, plus
  • Bot defence and bot defence tuning
  • Brute force, header and login protections
  • DDoS, IP intelligence, geolocation
  • AV / ICAP, parent policies, templates
Then choose how many policies
1 policy Possible pilot
£3,000
£3,500
£4,000
2 policies
£5,000
£5,750
£6,500
3 policies
£6,500
£7,500
£8,500
4 policies
£8,000
£9,000
£10,000
5 policies
£9,000
£10,250
£11,250
6 policies
£10,000
£11,250
£12,000

Scroll sideways to see every tier →

Feature tier sets how much of the F5 Advanced WAF toolkit we apply; each card shows that tier's price per number of policies.

Basic
Core managed protection
From £3,000 /year
Included
  • WAFY manages and runs the policy
  • Signature updates, staged monthly
  • Learning reviews, false positives resolved
  • Core protections, every change staged
Then choose how many policies
1 policy Possible pilot£3,000
2 policies£5,000
3 policies£6,500
4 policies£8,000
5 policies£9,000
6 policies£10,000
Most subscribed
Standard
The fuller ASM toolkit
From £3,500 /year
Everything in Basic, plus
  • Data Guard, CSRF, hostname handling
  • Parameters, including sensitive
  • Complex API policies (methods / content)
  • Tighter entities and OWASP reporting
Then choose how many policies
1 policy Possible pilot£3,500
2 policies£5,750
3 policies£7,500
4 policies£9,000
5 policies£10,250
6 policies£11,250
Premier
The full advanced feature set
From £4,000 /year
Everything in Standard, plus
  • Bot defence and bot defence tuning
  • Brute force, header and login protections
  • DDoS, IP intelligence, geolocation
  • AV / ICAP, parent policies, templates
Then choose how many policies
1 policy Possible pilot£4,000
2 policies£6,500
3 policies£8,500
4 policies£10,000
5 policies£11,250
6 policies£12,000
Running more than six policies? Most production estates have dozens, even hundreds, of ASM policies. One policy is simply how a pilot starts, prove the service on a single application, then scale. We price larger estates on the same basis; talk to us for a volume quote beyond six.

Small print: attack signature updates are applied per device, so an update covers every ASM policy on the BIG-IP, not only those you place under management. Where a device carries more policies than you manage with WAFY (say 18 on the box, 6 managed), the remaining policies are handled as a fixed-price job.

Two choices, one price. The feature tier sets the depth of protection; the policy count sets the scale. They are independent, so a single high-value application can run on Premier, and a large estate can stay on Basic. Prices are annual, in GBP, exclude VAT, and are provisional. Full grading is on the ASM feature matrix.

Full pricing and detail Prices in GBP, per year, exclude VAT. Provisional.
Why a managed WAF service

Advanced WAF is not "set and forget".

Start in days, not months

No hiring cycle and no new tooling. We baseline your policies, or build new ones, and begin managing them within days.

Signatures always current

Attack signatures applied, staged against live traffic and promoted to blocking, with a clean before/after record every time.

False positives, handled

The tuning that keeps a policy enforcing without breaking the application, done against your real traffic, so blocking stays on.

Direct to the engineer

Change requests go straight to the F5-certified engineer running your policies. Not a ticket portal, not an account manager.

One flat annual price

No day-rate creep, no expenses, no IR35 questions. A single yearly price per tier you can budget cleanly, that falls per policy as you add more.

Documented and evidenced

Every policy change is written up for audit, and OWASP and PCI alignment are treated as baseline, not extra.

Get started

Let us run your Advanced WAF.

Tell us how many applications you protect and what state the policies are in. We tell you which tier fits and how quickly we can pick them up.

Talk to WAFY

A 30-minute call. No obligation.

Tell us how many applications you protect and what state the policies are in. We tell you which tier fits and how quickly we can pick them up. No discovery fee, no obligation.

hello@wafy.ioEmail the team directly.
Book a 30-minute callPick a time that suits you.
Advanced WAF onlyWe do one thing: run your ASM policies well.

Protected by reCAPTCHA. Google's Privacy Policy and Terms of Service apply.