Your sites and your APIs,
filtered before they reach you.
A sovereign application firewall in front of your domains: Coraza engine and OWASP CRS rules, observation-then-blocking mode, geo-blocking — without touching your hosting.
A brochure site, an extranet, an API: it is the door to your IS that stays open 24/7, and the only one everyone can push on. SYLink WAF sits in front of your domains via a single DNS record. It inspects every request with the Coraza engine and OWASP CRS rules, starts in observation mode so nothing breaks, then blocks the day you decide.
From threat to evidence, in real time.
The module captures the signal, SYLink AI correlates it and decides — you keep control.
The WAF, from the portal.
Three domains behind the application firewall, and everything it has seen pass — in observation first, in blocking when you decide.
Your domains and what the WAF saw

Where attacks come from

Four-step onboarding

Real screenshots of the UniSOC portal. The data shown comes from a demonstration environment.
The technology, in detail.
What the module actually does — functions, not promises.
Coraza engine + OWASP CRS
- SQL injection, XSS, path traversal
- OWASP Core Rule Set, kept up to date
- Ready-made profiles: e-commerce, SaaS, brochure, API
- Exceptions and custom rules per domain
- Observe first, block when you want
Geographic & source filtering
- Country blocking using the full ISO list
- Preventive blocking, even for a never-before-seen country
- On-demand IP and range blocking
- Top countries and top sources live
DNS-based commissioning
- A CNAME — ALIAS/ANAME on a root domain
- DNS propagation check in the portal
- TLS certificate issued and renewed automatically
- No change to your hosting
- Rollback = a DNS record
Evidence and transparency
- Blocked requests log, rule by rule
- Public status page per domain
- Alerts forwarded to the UniSOC SOC
- Processing and hosting in France
What is it actually for?
Hold out until the patch
A vulnerability drops for your CMS on a Friday night: the CRS rule blocks exploitation while the vendor prepares its patch.
Shut out background noise
Bruteforce on admin pages, automated scans, inventory bots: filtered before reaching the server.
Reduce exposure to the strict minimum
Your extranet only serves France and Italy: all other countries are blocked with one click, with the associated evidence.
Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.
One building block of the SOC — never on its own.
Each module feeds the others through SYLink AI.
Ready to see what is really
happening on your network?
First trial free, no credit card, no commitment. On your existing infrastructure.
