Jurisdictional exposure
Attributes
- SLA Uptime
- 99.95%
- Cloudfront Integration
- Yes
- Rate Based Rules
- Yes
Sub-services (3)
Web ACLs
Define rules to filter and control web traffic
Managed Rule Groups
Pre-configured rules from AWS and marketplace sellers
Bot Control
Manage and block automated bot traffic
Compliance & Certifications
This service is attested for the following frameworks. Always verify with the provider before relying on a specific compliance posture.
Where this runs
Sovereign regions (6)
- AWS European Sovereign Cloud (Brandenburg) · BrandenburgAWS European Sovereign Cloud
- AWS GovCloud (US-East) · AshburnAWS GovCloud (US)
- AWS GovCloud (US-West) · HillsboroAWS GovCloud (US)
- AWS European Sovereign Cloud (Brandenburg) · BrandenburgAWS European Sovereign Cloud
- China (Beijing) · BeijingAWS China (Sinnet)
- China (Ningxia) · YinchuanAWS China (NWCD)
Commercial regions (34)
Europe (8)
- Europe (Paris)
- Europe (Frankfurt)
- Europe (Ireland)
- Europe (Milan)
- Europe (Spain)
- Europe (Stockholm)
- Europe (Zurich)
- Europe (London)
North America (7)
- Canada West (Calgary)
- Canada (Central)
- Mexico (Central)
- US East (N. Virginia)
- US West (Oregon)
- US East (Ohio)
- US West (N. California)
South America (1)
- South America (São Paulo)
Asia (11)
- Asia Pacific (Hong Kong)
- Asia Pacific (Hyderabad)
- Asia Pacific (Mumbai)
- Asia Pacific (Jakarta)
- Asia Pacific (Osaka)
- Asia Pacific (Tokyo)
- Asia Pacific (Malaysia)
- Asia Pacific (Singapore)
- Asia Pacific (Seoul)
- Asia Pacific (Taipei)
- Asia Pacific (Thailand)
Oceania (3)
- Asia Pacific (Melbourne)
- Asia Pacific (Sydney)
- Asia Pacific (New Zealand)
Middle East (3)
- Middle East (Bahrain)
- Israel (Tel Aviv)
- Middle East (UAE)
Africa (1)
- Africa (Cape Town)
Tags
Equivalent services on other platforms
Managed WAF protecting web apps from OWASP Top 10 attacks, bot traffic, API abuse, and data scraping, with global and China regional deployment, custom rule engine, and unified consoles across Anti-DDoS and Security Center
Layer 7 load balancer with integrated web application firewall, SSL termination, URL-based routing, cookie-based session affinity, and autoscaling based on traffic
Web application and API protection with OWASP rule sets, bot management, API schema enforcement, and rate limiting — delivered at the CDN edge with a single configuration surface
Edge DDoS protection and web application firewall with managed rule sets for OWASP Top 10, adaptive bot protection, and reCAPTCHA Enterprise integration
Risk-scored bot and abuse protection for web and mobile traffic, providing a 0.0-1.0 risk score per request, account defender to detect account takeover, fraud-prevention signals for payment and bonus abuse, and password leak detection via k-anonymity hashing
Managed web application firewall with OWASP Top 10 rule sets, bot management, anti-crawler, CC (challenge-collapsar) attack mitigation, custom rule engine, and regional deployment with integrated DDoS protection
Layer-7 protection against OWASP Top 10 attacks (SQLi, XSS, RCE), bot traffic, and DDoS at the application layer. Edge-deployed for global protection or regional for backend-fronted apps.
Managed WAF with bot mitigation, IP / geo blocking, custom rules, and per-route challenges — runs on the edge before any function executes