WAFY is a managed F5 Advanced WAF (ASM) service. We take your ASM policies and run them: signature updates, tuning, learning reviews, false positives, OWASP alignment and reporting. You keep the estate; we keep the policies healthy.
WAFY takes responsibility for your Advanced WAF (ASM) policies: signature updates staged and promoted, learning suggestions reviewed, false positives resolved, OWASP alignment kept current, and reporting back to you on a cadence.
Thirty years across development, mid-tier and backend systems, now including modern API and MCP work, focused on one thing: building and running F5 Advanced WAF policies that actually enforce. You keep ownership of the estate; we keep the policies healthy and documented.
Pick a tier by how many policies you need managed, then introduce us to them. We baseline what is already there, or build new policies from scratch. No new vendor to onboard, no recruitment.
We analyse the event logs and work through the learning suggestions, apply and stage signature updates, resolve false positives and keep OWASP alignment current, all on a cadence, plus your change requests as they come up. Monthly on Basic and Standard, weekly on Premier.
Every change is documented for audit, and you get a regular report on what was seen and done, plus the changes we propose next for your sign-off. And because every change is staged and reviewed against live traffic before it enforces, nothing we do introduces issues.
Building an F5 Advanced WAF policy is an incremental job, not an all-day one. It comes in short passes spread over days or weeks, paced by how quickly real traffic arrives.
The policy is opened up and starts learning from your live traffic. We work through the first, and largest, batch of suggestions, keeping what belongs and removing what does not.
As more traffic arrives, we tighten the policy and turn on further protections, clearing the smaller batches of suggestions it raises. Shorter passes, more of them.
The policy settles. New traffic rarely raises anything new, so we simply check in from time to time and keep it current.
The duration of each phase depends on the amount of traffic your application sees, not on a fixed schedule.
This is the point: it never takes all day. It might be ten minutes a day for a week, an hour a day the next, or a quiet week followed by a busier one. The work is short and intermittent, an hour or two a day at most, because it is paced by real traffic, not by how long an engineer sits at the keyboard.
Bring in a contractor to build ASM policies for ten applications and you pay for full days, half of which are spent doing nothing, just waiting for real traffic before the next pass.
WAFY runs many policies at once and checks each on the cadence it needs, daily for a new policy, weekly for a settled one, then moves on while yours waits for traffic. You pay for the time the work actually takes, never for someone sitting idle between passes.
Because the waiting is shared across every policy we run, you get expert, OWASP-compliant policy work for far less than a dedicated contractor would cost, and it is done more thoroughly. You are paying for the time, not for the person.
Pick the feature tier for the depth of protection, then the number of policies, priced independently, both shown below. See what each tier grades on the ASM feature matrix.
Scroll sideways to see every tier →
Feature tier sets how much of the F5 Advanced WAF toolkit we apply; each card shows that tier's price per number of policies.
Small print: attack signature updates are applied per device, so an update covers every ASM policy on the BIG-IP, not only those you place under management. Where a device carries more policies than you manage with WAFY (say 18 on the box, 6 managed), the remaining policies are handled as a fixed-price job.
Two choices, one price. The feature tier sets the depth of protection; the policy count sets the scale. They are independent, so a single high-value application can run on Premier, and a large estate can stay on Basic. Prices are annual, in GBP, exclude VAT, and are provisional. Full grading is on the ASM feature matrix.
No hiring cycle and no new tooling. We baseline your policies, or build new ones, and begin managing them within days.
Attack signatures applied, staged against live traffic and promoted to blocking, with a clean before/after record every time.
The tuning that keeps a policy enforcing without breaking the application, done against your real traffic, so blocking stays on.
Change requests go straight to the F5-certified engineer running your policies. Not a ticket portal, not an account manager.
No day-rate creep, no expenses, no IR35 questions. A single yearly price per tier you can budget cleanly, that falls per policy as you add more.
Every policy change is written up for audit, and OWASP and PCI alignment are treated as baseline, not extra.
Tell us how many applications you protect and what state the policies are in. We tell you which tier fits and how quickly we can pick them up.
Tell us how many applications you protect and what state the policies are in. We tell you which tier fits and how quickly we can pick them up. No discovery fee, no obligation.