A wall between the internet and your website.
Every request to your site passes through Blackwall first. Ordinary visitors carry on without noticing. Attacks stop at the wall, and you get a plain-English list of what was stopped and why. There is nothing to install and no rules to write.
14 days free, no card. Then $19 a month for one website.
A customer opens your home page
Reaches your site
Someone types database commands into your search box
StoppedDatabase injection
A customer sends your contact form
Reaches your site
A scanning tool asks for your settings file, /.env
StoppedFile access
A customer uploads a photo
Reaches your site
Someone hides a script in a comment
StoppedScript injection
How it works
Tell it your website and where it runs
Its address, and the server behind it. Then prove the site is yours with one DNS record, one small file or one tag.
Look at your site through it
A private link shows your site passing through Blackwall before anything changes for your visitors.
Point your DNS at it
Two records, where your domain is managed. If someone else looks after that, Blackwall emails them the steps. The certificate is taken care of.
Watch, then block
It starts by watching: nothing is stopped, and you see what would have been. When the list looks right, you switch blocking on.
What it blocks
The common ways websites are attacked, in 7 kinds. Each has a page that says what it is and why it matters.
- Malformed requestsSomeone tries to send a request no ordinary browser would send.
- Database injectionSomeone tries to slip database commands into your site.
- Script injectionSomeone tries to plant a script in one of your pages.
- File accessSomeone tries to read private files on your website.
- Command and code injectionSomeone tries to run their own commands on your server.
- Attack toolsSomeone tries to scan your site with a known attack tool.
- Session attacksSomeone tries to force a visitor onto a session they control.
What it will not do to you
- It will not block anyone on its first day. It starts by watching. Blocking is your decision, after you have seen what it would stop.
- It will not leave a real customer stuck. A stopped visitor sees a reference. You find the request, press one button, and requests like it are let through.
- It will not take your site down over a bill. If your subscription lapses, your site is passed through uninspected while you move your DNS back.
- It will not keep your visitors' secrets. Only stopped requests are recorded, and never their cookies, passwords or sign-in tokens.
What it does not protect against
A firewall like this stops common attacks on a website. It is one layer, and it is not these:
- Large floods of traffic (DDoS)
- Telling people from bots
- Stolen passwords
- Who may do what inside your site
- Finding weaknesses
- Anything on the server or on computers
What does the inspecting
The rules that judge each request are the OWASP Core Rule Set, version 4.25.0, run by the Coraza engine. Both are open source projects of the OWASP Foundation, written and reviewed in public. What STRATIC adds is everything around them: setting it up for you, keeping it running and up to date, and turning what it reports into words you can act on.
$19 a month.One website.
One plan, with everything in it. No contract. Cancel from the billing page whenever you like.