Cloud Armor

GCPNetworking

Edge DDoS protection and web application firewall with managed rule sets for OWASP Top 10, adaptive bot protection, and reCAPTCHA Enterprise integration

Jurisdictional exposure

Provider HQ
USMountain View, USA

Subject to CLOUD Act, FISA-702, DPF

Region locations
APACCNEEAEUUKUSOther44 regions across 7 jurisdictions
Sovereign option
Yes — 2 sovereign-flagged regions available

Attributes

Ddos Protection
Yes
Owasp Rules
Yes
Rate Limiting
Yes

Sub-services (2)

Security Policies

Custom rules for filtering incoming traffic

Adaptive Protection

ML-based automatic threat detection and response

Compliance & Certifications

This service is attested for the following frameworks. Always verify with the provider before relying on a specific compliance posture.

Where this runs

44 regions
28 countries
2sovereign
Sovereign regions (2)
  • T-Systems Sovereign Cloud · FrankfurtT-Systems Sovereign Cloud powered by Google Cloud
  • S3NS Sovereign Cloud · ParisS3NS — Google Cloud + Thales joint venture
Commercial regions (42)

Europe (13)

  • Belgium
  • Finland
  • Paris
  • Berlin
  • Frankfurt
  • Milan
  • Turin
  • Netherlands
  • Warsaw
  • Madrid
  • Stockholm
  • Zurich
  • London

North America (12)

  • Montréal
  • Toronto
  • Querétaro
  • Northern Virginia
  • Columbus
  • Iowa
  • Dallas
  • Las Vegas
  • Los Angeles
  • South Carolina
  • Salt Lake City
  • Oregon

South America (2)

  • São Paulo
  • Santiago

Asia (9)

  • Hong Kong
  • Delhi
  • Mumbai
  • Jakarta
  • Osaka
  • Tokyo
  • Singapore
  • Seoul
  • Taiwan

Oceania (2)

  • Melbourne
  • Sydney

Middle East (3)

  • Tel Aviv
  • Doha
  • Dammam

Africa (1)

  • Johannesburg

Tags

Equivalent services on other platforms

Alibaba Web Application FirewallAlibaba

Managed WAF protecting web apps from OWASP Top 10 attacks, bot traffic, API abuse, and data scraping, with global and China regional deployment, custom rule engine, and unified consoles across Anti-DDoS and Security Center

AWS Network FirewallAWS

Managed stateful firewall, IDS/IPS, and TLS inspection service deployed as VPC endpoints with Suricata-compatible rule syntax, AWS Managed Threat Signatures rule groups, and centralised deployment via AWS Firewall Manager across Organizations

AWS WAFAWS

Web application firewall that protects against common exploits with managed rule groups, custom rules, rate-based rules, Bot Control, and CAPTCHA challenges

AWS ShieldAWS

Managed DDoS protection service with always-on Standard tier for CloudFront and Route 53 edge, and Advanced tier adding 24/7 DDoS Response Team access, cost protection, and enhanced Layer 7 detection

Azure Application GatewayAzure

Layer 7 load balancer with integrated web application firewall, SSL termination, URL-based routing, cookie-based session affinity, and autoscaling based on traffic

Azure FirewallAzure

Cloud-native, stateful firewall-as-a-service with built-in high availability, unrestricted scale, threat intelligence-based filtering, and centralised policy

Azure DDoS ProtectionAzure

Managed Distributed Denial-of-Service protection for Azure resources with always-on traffic monitoring, adaptive real-time tuning, cost-guarantee protection against scale-out attacks, and integration with Azure Monitor for attack analytics and telemetry

Gcore DDoS ProtectionGcore

Always-on L3/L4/L7 DDoS mitigation delivered at Gcore's edge POPs, with traffic scrubbing, capacity in the multi-Tbps range, and SLAs against volumetric and application-layer attacks

Gcore WAAPGcore

Web application and API protection with OWASP rule sets, bot management, API schema enforcement, and rate limiting — delivered at the CDN edge with a single configuration surface

Huawei Web Application FirewallHuawei

Managed web application firewall with OWASP Top 10 rule sets, bot management, anti-crawler, CC (challenge-collapsar) attack mitigation, custom rule engine, and regional deployment with integrated DDoS protection

OCI Web Application FirewallOracle

Layer-7 protection against OWASP Top 10 attacks (SQLi, XSS, RCE), bot traffic, and DDoS at the application layer. Edge-deployed for global protection or regional for backend-fronted apps.

Pricing

Pricing model:pay-as-you-go