Move traffic to the security edge without guessing.
Waffinnity separates preparation from cutover. Ownership, TLS, gateway routing and origin readiness are checked first. Production DNS changes only when the route is ready and you decide to switch.
Six controlled steps from origin to protected application.
Each stage has a clear purpose, technical evidence and a next action.
Application context
Add the primary domain. Waffinnity discovers the current origin and records the route without changing production traffic.
Ownership verification
Verify control of the domain through a guided DNS record. Your existing route remains untouched.
TLS & edge preparation
Certificates, gateway routing and the security path are prepared before any production cutover.
Readiness checks
Waffinnity validates origin reachability, TLS state, gateway availability and the intended route.
Controlled DNS cutover
You change the production DNS only when the route is ready. Waffinnity then observes convergence and traffic health.
Protection & operations
Choose a protection profile, review evidence and refine policy from the application workspace.
The platform prepares. You control the production switch.
Waffinnity does not need to replace your DNS provider. The onboarding workspace tells you which records must change, validates the target route and then observes the new path after you apply the change.
Onboarding ends where security operations begin.
Observe traffic
Review allowed, challenged and blocked traffic with application context.
Tune policy
Start from a recommended profile and only tighten rules when evidence supports it.
Add modules
Enable Bot, Account, WordPress or other protection where the application needs it.
Use intelligence
Correlate security signals and prioritize follow-up through Security Intelligence.
Connect the first application with a controlled onboarding path.
Start with Foundation and move production traffic only after the route is ready.