A managed WAF for your Drupal site
Exploits and bots hit Drupal too. A security module runs inside the site — after the request has already reached your server. We put a managed web application firewall at the edge so /user and public forms stay up, without installing a module.
A module is too late
Drupal is probed for known exploits, brute-force on /user/login, and bot floods against public forms. A module or plugin only sees that traffic after it has already hit PHP and the database.
A WAF at the edge stops malicious requests before they touch Drupal. Hosting stays put — we sit in front via DNS.
Protect /user and admin without blocking editors
We watch /user/login and admin paths for credential stuffing and exploit probes. Rules start in count so editors and form submissions still get through.
Rules start in count. Nothing is blocked on day one. After 24 hours, your dashboard shows what's safe to block — one click.
Promote Copilot is included — you still click once.
Built for campus and agency Drupal
The buyer is usually a university, college, or public-sector team running a Drupal estate — not a one-off brochure site. Same product as every other site: no module, no plugin, we run the firewall.
$150/site/mo, 14-day trial. Experience protecting higher-education and public-sector sites.
For the longer campus cut — multi-site estates, contrib XSS, and count → promote — read Managed WAF for Drupal without a module.
Related
- Managed WAF for Drupal without a module
- Managed WAF for university and college websites
- Managed WAF for government and public-sector websites
- A managed WAF for your WordPress site
- What is WAF count mode? (and why you start there)
- What's safe to block on a WAF?
- WAF false positives on forms: stop blocking legitimate POSTs
- Partner with ProtectMyWebsite
- Managed WAF for multi-site teams
- Pricing
- Free security scan
- A client was taking 90 million requests an hour. The WAF was only half the fight.