Web Security
Reduce web attack surface with practical controls for applications, APIs, origins, and users.
Related guides
Web Security guides
A practical WAF configuration guide covering managed rules, safe rollout, exceptions, false-positive analysis, testing, and continuous tuning.
Use this practical security headers checklist to configure CSP, HSTS, frame protection, MIME protection, referrer controls, CORS, cookies, and reporting safely.
Learn how to apply zero trust to web applications with a practical sequence for identity, resource policy, APIs, service-to-service access, and validation.
Learn how to verify AI agents and crawlers with layered controls, signed requests, IP validation, and route-specific bot policies.
A practical guide to TLS, HTTPS, certificates, HSTS, secure headers, edge termination, and the validation steps that keep modern web traffic protected.
Learn how to reduce origin exposure with DNS hygiene, gateway-only access, firewall controls, authenticated edge connections, monitoring, and safe testing.
Understand DDoS protection layers, origin security, traffic controls, observability, and the response preparation required before an attack.
Learn how to distinguish legitimate people, trusted crawlers, and abusive automation using layered signals, careful response rules, and safe monitoring.
A practical, provider-neutral guide to rate limiting APIs and web flows by identity, route, and risk without punishing legitimate customers.
A practical guide to secure webhooks: webhook signature verification, webhook replay protection, idempotency, secret rotation, schemas, and safe incident handling.
Build and rehearse a tested security incident response plan for website incidents: roles, evidence, edge provider escalation, customer communication, recovery, and lessons learned.
Design an ecommerce edge that caches public catalog content safely, keeps account and checkout state private, protects origins, and applies layered bot defense.
Build layered account takeover defenses across the edge, identity, application, and fraud stack without turning legitimate customers into false positives.
Protect payment pages from Magecart and e-skimming with script inventory, authorisation, integrity controls, CSP, SRI, tamper detection, and PCI DSS 4.0.1 guidance.
Prevent broken object level authorization and cross-tenant API exposure with object checks, tenant-scoped data access, adversarial tests, logging, and incident response.
A practical guide to cloud-native configuration management and secrets management: typed contracts, least privilege, config rotation, Kubernetes safeguards, and operational visibility without leaking credentials.
Harden coding agent sandboxes with ephemeral credentials for agents, scoped identity, controlled egress, agent execution isolation, audit evidence, and safe recovery from policy denials.
A practical approach to Cloudflare WAF configuration: deploy managed and custom rules in stages, with scoped exceptions, API-safe decisions, logging practices, testing, and rollback.
Set up and operate Fastly Next-Gen WAF policies safely with scoped signals and exclusions, request rules, simulation, logging, staged enforcement, and rollback.
