Built to deliver and defend iGaming.

SecureEdge WAF

Product Overview

Continent 8's web application firewall (WAF) protects your websites, applications and APIs from attacks that target weaknesses in application code. It covers both production and back-office applications. As businesses add integrations, partners and new features, their applications and APIs become more exposed, and the number of ways an attacker can get in grows with them. Our managed WAF inspects incoming traffic at the application layer, blocking malicious requests before they reach your origin. The service is delivered from Continent 8's own global private network and is fully managed. Rather than handing you a rule engine to configure and maintain yourself, we write, apply and update the protection for you, with custom rules and exceptions available on request through your portal or via API. Protection is available at two levels: a basic tier covering the OWASP Top 10 attacks, and an advanced tier with a full managed rule set maintained and updated daily as new threats appear. Basic bot protection is included; advanced bot management is on the roadmap.
  • 246m
    +
    Web application attacks in the gaming industry in 2020

Why Continent 8?

  • Protection at the edge of your own network

    The WAF runs on the same private network that delivers your content, close to your origin servers. Traffic does not need to be diverted to a separate scrubbing network, which avoids the added latency that some cloud WAF services introduce.

  • Managed, not left to you

    The rule set is maintained and tuned for you, with new rules written and applied as threats emerge. You can request custom rules or exceptions without having to run the platform yourself.

  • Part of a layered security stack

    As an internet service provider, Continent 8 can combine application layer protection with upstream filtering, network edge filtering, volumetric DDoS scrubbing and rate limiting, giving defence in depth against both large scale and application specific attacks.

  • iGaming focused

    Built for the demands of the iGaming, online sportsbook, live dealer and live casino market, backed by more than 28 years servicing the industry and deep in-jurisdiction regulatory experience.

Benefits

  • Broad protection

    Defence against the OWASP Top 10, plus advanced injection attacks, malware, brute force and credential attacks, reconnaissance, data loss and Layer 7 denial of service, depending on tier.

  • Virtual patching

    Known vulnerabilities can be shielded at the WAF without changing your application code, which buys time to patch and supports PCI DSS compliance, where an active WAF is a requirement.

  • Low latency by design

    Because protection runs on the network already delivering your content, there is no detour to a third-party scrubbing centre.

  • Compliance support

    Reporting and logging help you demonstrate your security posture against regulatory and industry frameworks.

  • Managed simplicity

    No appliances to install, no rule engine to run. Protection is set up and maintained for you, with the option to tailor rules to your applications.

Use Cases

  • Web application protection

    Blocks application layer attacks including SQL injection, cross site scripting and file inclusion, the kinds of attack that lead to data theft and site compromise.

  • API protection

    Inspects API traffic for malicious payloads and common abuse patterns, including command injection and XML external entity attacks.

  • Bot and scraper control

    Basic bot protection identifies and filters automated traffic such as scanners, content scrapers and known bad user agents. Advanced behavioural bot management is on the roadmap.

  • Brute force and credential attack protection

    Detects and slows automated login attempts that try to break into accounts using guessed or stolen credentials.

  • Data loss prevention

    Rules can detect and redact sensitive data, such as payment card numbers or personal information, in application responses.

  • Denial of service and rate limiting

    Layer 7 rules and request rate limiting help keep applications available under abusive traffic, working alongside Continent 8's network level volumetric DDoS scrubbing.

  • Threat intelligence and reputation filtering

    Traffic is checked against reputation data and blocklists so that requests from known bad sources are stopped early.

Basic and advanced WAF: what's included

The advanced tier is built on a full managed rule set containing tens of thousands of individual rules, that are updated updated daily. The families group rules by the type of threat they address. The main groupings are:
  • Core attack rules covering the OWASP Top 10

  • Advanced injection rules

  • Reputation and threat intelligence

  • Reconnaissance and scanner detection

  • Brute force and credential attack rules

  • Malware and backdoor detection

  • Data loss prevention (DLP) and response redaction

  • Virtual patching

  • Anti-evasion

  • Bot and user-agent rules

The basic tier draws on the core attack family to deliver OWASP Top 10 coverage, plus basic bot protection only. The advanced tier turns on the full set of families.

Secure
SecureEdge WAF

To discover more about our WAF solutions, simply fill out this form.

Get in touch

You may also be interested in:

Connect
Manage
Secure
Intelligence
AWS

AI That Delivers Real Impact | Inside Continent8's intelligence8 Platform

...

READ MORE

iGB Live!

...

READ MORE

NCLGS Summer Meeting 2026

...

READ MORE

Let's work together.

GET IN TOUCH

Asia +65 3165 4649
Europe +44 1624 694625
Latin America +54 11 5168 5637
North America +1 514 461 5120