update page now

New: EU CAPTCHA – GDPR-compliant bot protection. Try it free for 3 months!

Icon WAF

Made in Germany

Myra WAF

The Cloud WAF blocks malicious requests at the application layer before they reach your servers. Stay secure against OWASP risks such as cross-site scripting (XSS) and SQL injection (SQLi), as well as known zero-day exploits, with our scalable web application firewall.

  • Protect your web applications against data theft and manipulation

  • Legally GDPR-compliant and Made in Germany

  • Managed WAF Service as an add-on: cybersecurity expertise on demand

Request a DemoCalculate Your Price

You're in Good Company When You Choose Myra

1&1 VersatelLogo BarmeniaMunich Security ConferenceSparkasse LogoEdekadpallb1861 LogoLogo of Aleph Alpha, German AI company and customer of Myra SecurityCancomPartner of Myra: Witcom]init[NFONPartner of Myra: heinleinLogo calensoLogo Staatsministerium Baden-WürttembergStadt Regensburg LogoSecuritas1822direkt LogoHugendubel Logokik LogoBreuninger LogoAKDB LogoLogo of KDVZ, German municipal IT service provider and customer of Myra Security

We Tackle Your Toughest Security Challenges

Icon Company on Attack

No Protection Against the OWASP Top 10

Lack of safeguards leaves apps vulnerable to injection attacks such as SQLi and XSS. Attackers exploit these flaws to steal data, hijack sessions, and take control.

Icon Financial Damage

Inability to Mitigate API Threats

Weak API security makes data vulnerable to injections, exploits and leaks. Attackers take advantage of faulty authentication and missing protection measures, which leads to interruptions.

Icon Warning

Complex and Disruptive Implementation

Difficult setups and compatibility issues can cause delays. They also increase costs and disrupt operations. Plus, extra hardware may be needed.

Icon Financial Damage

Overwhelming Compliance Challenges

Meeting strict regulations like NIS-2, DORA, and GDPR is tough without certified solutions. This gap can expose organizations to legal risks and data breaches.

Key Benefits of Myra WAF

Icon DDoS Schutz

Protection for Your Applications

Myra WAF provides protection against Cross-Site Scripting (XSS), SQL Injection, Directory Traversal and other OWASP Top 10 vulnerabilities.

Icon HTTPS Protection

Managed Service with Expert Support

Myra's optional Managed WAF service helps protect your web resources. Experts tailor rule sets just for you. They also offer ongoing support and optimization.

Fast response Icon

Get up and Running in No Time

Get started right away with no extra hardware or complicated setups. Myra's Cloud WAF works seamlessly with your existing infrastructure.

Icon Compliance

Ensure Full Compliance with Key Regulations

Myra itself is NIS-2-, DORA-, and GDPR-compliant and can help you meet regulatory requirements, especially in highly regulated sectors.

Certified Security You Can Rely On

Certificate ISO 27001 BSI certified on the basis of IT-GrundschutzCertificate PCI DSSBSIG KRITIS qualified logoBSI C5 Testat Typ2Zertifikat Trusted CloudIDW WPS 951 Type 2 CertificateISO 9001

Intuitive WAF Management


Myra WAF Features

Scalable HTTP/S traffic filtering
Immediate scaling to manage variable web traffic loads.

Handling traffic before and after the customer infrastructure
Filtering and rule enforcement both before and after traffic reaches your servers.

Easy rule management
Myra provides standard rules (Myra Tags) to protect against common attack patterns such as XSS, SQLi, or directory traversal. In addition, you can define your own WAF rules to defend against other threats according to your requirements. 

Flexible action options
Choose between various actions for blocking, allowing, challenging (e.g., via CAPTCHA), and logging requests, as well as for modifying header information and rate limiting.

General and path-specific f iltering rules
Precise control over the domains and paths that are to be protected by the WAF.

Geo-IP blocking at the application level
Use predefined conditions in the WAF rules to select the countries and continents for which traffic is allowed or blocked.

Custom error messages
Tailored error messaging to enhance user experience and security transparency.

No impact on midgress traffic regarding costs and performance
WAF operation as part of the Myra Security as a Service platform does not affect data traffic between your and Myra’s infrastructure.

API and automation support for integration
Programmatic access for integration with CI/CD pipelines and management systems.

Scalable HTTP/S traffic filtering
Immediate scaling to manage variable web traffic loads.

Handling traffic before and after the customer infrastructure
Filtering and rule enforcement both before and after traffic reaches your servers.

Easy rule management
Myra provides standard rules (Myra Tags) to protect against common attack patterns such as XSS, SQLi, or directory traversal. In addition, you can define your own WAF rules to defend against other threats according to your requirements. 

Flexible action options
Choose between various actions for blocking, allowing, challenging (e.g., via CAPTCHA), and logging requests, as well as for modifying header information and rate limiting.

General and path-specific f iltering rules
Precise control over the domains and paths that are to be protected by the WAF.

Geo-IP blocking at the application level
Use predefined conditions in the WAF rules to select the countries and continents for which traffic is allowed or blocked.

Custom error messages
Tailored error messaging to enhance user experience and security transparency.

No impact on midgress traffic regarding costs and performance
WAF operation as part of the Myra Security as a Service platform does not affect data traffic between your and Myra’s infrastructure.

API and automation support for integration
Programmatic access for integration with CI/CD pipelines and management systems.

See Who Relies on Myra WAF

Protect Your Web Applications from Modern Attacks

Experience our Cloud WAF in a 30-minute demo.

We will show you the most important features and answer your questions – after you submit the form, we will contact you promptly to schedule an appointment.

Hundreds of millions of HTTP requests can be processed per second to provide protection against the latest attacks.

Filter Icon Small

Guaranteed availability with up to 99.9% SLA.

SLA Icon

Legally GDPR-compliant and made in Germany.

Compliance Icon Small

Over 500 companies from highly regulated sectors such as finance, government institutions, healthcare, and critical infrastructure place their trust in us.

"Myra puts us in a solid position in terms of cybersecurity, web-performance and compliance."
– Hendrik Hoffmann, Division Manager Technology at Sparkassen-Finanzportal GmbH

Portrait photo of Hendrik Hoffmann

All information on data processing can be found in our privacy policy.

Cloud WAF – Frequently Asked Questions (FAQ)

The cost of WAF Security varies depending on the deployment model, WAF provider, and the number of domains that need to be protected. You can use our price calculator to get an indication of the price for your specific requirements.