Skip to content
Waffinnity
Get started
EUROPEAN EDGE INFRASTRUCTURE

Security enforcement close to your applications.

Waffinnity places a distributed European security edge between the internet and your origin. Gateways enforce policy, terminate TLS, observe traffic and keep protection available when infrastructure changes.

European gateway footprintHealth-aware distributionControlled configuration rollout
European EdgeDistributed
InternetIncoming application traffic
Waffinnity Security EdgeTraffic inspected before origin
TLSReputationDDoSWAFPolicies

Traffic is handled by the available European gateway layer

EU WESTAmsterdamGateway region
EU CENTRALFrankfurtGateway region
EU SOUTHMilanGateway region
Protected application originsOnly accepted traffic continues to the application

The diagram shows the security path: internet traffic enters Waffinnity, is inspected and enforced at the edge, is handled by the European gateway layer and only then continues to the protected origin.

TLSWAFDDoSPoliciesTelemetry
01 — EDGE ARCHITECTURE

One control plane. Distributed enforcement.

Protection policy is managed centrally and distributed to the gateway layer where requests are actually handled.

01

Control Plane

Applications, domains, security policy and lifecycle state are managed centrally.

02

Validated Publish

Configuration is prepared and validated before it becomes active on the edge.

03

Gateway Enforcement

Gateways terminate TLS and enforce traffic controls before forwarding accepted requests.

04

Telemetry

Operational and security evidence flows back to the platform for visibility and response.

02 — RESILIENCE

Designed to keep the security layer operational.

Multi-gateway architecture

Applications can be served through a distributed gateway pool instead of depending on one edge endpoint.

Origin health awareness

Health signals provide context when an origin becomes unavailable or starts responding abnormally.

Last-known-good safety

Controlled configuration lifecycle reduces the risk that a bad configuration disrupts protected traffic.

Controlled reloads

Runtime changes are applied through a managed gateway process rather than ad-hoc origin changes.

03 — EUROPEAN FOOTPRINT

A European edge for European application security.

The current Waffinnity topology is organised around gateway regions in Amsterdam, Frankfurt and Milan. Region capacity can evolve without changing the security model presented to customers.

RegionLocationRoleSecurity stack
EU WestAmsterdamEdge gateway regionTLS · WAF · DDoS · Policies
EU CentralFrankfurtEdge gateway regionTLS · WAF · DDoS · Policies
EU SouthMilanEdge gateway regionTLS · WAF · DDoS · Policies
04 — TRUST BOUNDARIES

Security infrastructure needs operational boundaries too.

Tenant isolation

Application policy, evidence and organisation context remain scoped to the owning organisation.

Origin separation

The edge becomes the public security boundary while the application origin remains behind it.

Signed lifecycle

Policy revisions follow a controlled publish path before gateway activation.

Operational evidence

Gateway and security telemetry make enforcement observable instead of opaque.

EUROPEAN SECURITY EDGE

Put Waffinnity between the internet and your application.

Connect an application and build protection on a managed European edge.