Skip to content
Waffinnity
Get started
CONTROLLED ONBOARDING

Move traffic to the security edge without guessing.

Waffinnity separates preparation from cutover. Ownership, TLS, gateway routing and origin readiness are checked first. Production DNS changes only when the route is ready and you decide to switch.

No blind cutoverPre-flight checksCustomer-controlled DNS
APPLICATION ONBOARDINGexample.com
Pre-flight ready
1
OwnershipVerified
2
TLS & GatewayPrepared
3
DNS CutoverCustomer action
4
ProtectionObserve & tune
Existing traffic stays on the current route until the DNS cutover.
Preparation before production changeVERIFYPREPAREVALIDATECUTOVER
THE COMPLETE PATH

Six controlled steps from origin to protected application.

Each stage has a clear purpose, technical evidence and a next action.

01

Application context

Add the primary domain. Waffinnity discovers the current origin and records the route without changing production traffic.

02

Ownership verification

Verify control of the domain through a guided DNS record. Your existing route remains untouched.

03

TLS & edge preparation

Certificates, gateway routing and the security path are prepared before any production cutover.

04

Readiness checks

Waffinnity validates origin reachability, TLS state, gateway availability and the intended route.

05

Controlled DNS cutover

You change the production DNS only when the route is ready. Waffinnity then observes convergence and traffic health.

06

Protection & operations

Choose a protection profile, review evidence and refine policy from the application workspace.

CUTOVER SAFETY

The platform prepares. You control the production switch.

Waffinnity does not need to replace your DNS provider. The onboarding workspace tells you which records must change, validates the target route and then observes the new path after you apply the change.

Existing origin remains reachable during preparationTLS prepared before production traffic arrivesGateway and origin readiness checked firstDNS convergence observed after cutover
PRE-FLIGHTReady for cutover
Domain ownership
TLS certificate
Gateway route
Origin health
Production DNSYour action
AFTER CUTOVER

Onboarding ends where security operations begin.

01

Observe traffic

Review allowed, challenged and blocked traffic with application context.

02

Tune policy

Start from a recommended profile and only tighten rules when evidence supports it.

03

Add modules

Enable Bot, Account, WordPress or other protection where the application needs it.

04

Use intelligence

Correlate security signals and prioritize follow-up through Security Intelligence.

READY WHEN YOU ARE

Connect the first application with a controlled onboarding path.

Start with Foundation and move production traffic only after the route is ready.