Features
HEIMWALL brings security, delivery and monitoring together on one platform. All of the features below are included in every plan; there are no add-on modules or extra fees.
Define conditions on 29 request fields (IP type, country/ASN, bot category, path, header, method and more), then block, challenge, redirect or log. No code required.
The managed rule set blocks thousands of known vulnerabilities at the edge and is kept current by our team, so you are covered without writing a single rule. Run it in log-only mode first if you want to see the effect before switching to blocking.
Beyond vulnerability signatures, HEIMWALL covers 110 attack types at the application layer. The range spans injection, protocol-level abuse, flood techniques, bot and credential abuse, and API resource exhaustion. These target the technique an attacker uses rather than an individual vulnerability, so they catch abuse that no signature describes.
Every request gets a 0–100 bot score across 17 bot categories. Act on thresholds you set: let good bots through, challenge the gray zone, block the rest.
Automatic challenges verify suspicious clients, while brute-force protection (failban) bans abusive IPs automatically and lifts the ban when it expires.
During traffic peaks, hold visitors on an ordered waiting page and admit them at a rate you set. Your server is not overloaded.
Show your own branded block and error pages. Even on a blocked request, the visitor sees your page instead of a generic error.
Rule-based rate limits on any request attribute such as IP, path or token, with a separate limit per rule. Abuse is stopped at HEIMWALL before it reaches your server.
Control edge cache and browser cache with separate TTLs, and serve faster with HTTP/3 and automatic compression.
Issue and renew certificates automatically with ACME, or upload your own. TLS terminates at the edge with TLS 1.3 on modern clients, and your origin IP stays hidden.
HEIMWALL supports HTTP/3 over QUIC. Compatible browsers and clients connect over HTTP/3; everything else keeps working over HTTP/2 and HTTP/1.1. Modern clients also negotiate TLS 1.3 for a more efficient encrypted connection.
HEIMWALL manages an ECDSA P-256 and an RSA certificate for the same domain at once. Modern clients get the smaller, more efficient ECDSA certificate; older or special clients that need RSA are served the RSA one automatically. You pick no algorithm and write no compatibility configuration.
On clients that support it, HEIMWALL uses the X25519MLKEM768 hybrid key agreement over TLS 1.3, pairing classical X25519 key exchange with ML-KEM as standardised by NIST. This is not a post-quantum SSL certificate; it is the key agreement used while the TLS session is established.
Run authoritative DNS with geo-routing that sends each visitor to the nearest PoP, plus health checks and automatic failover.
Run multiple origins Active-Active or Active-Passive. Health checks detect an origin going down and traffic fails over automatically.
Distribute requests across servers of different capacity with weights. Add and remove origins from a single console.
Your origin IP stays hidden. HEIMWALL connects to your origin over the port and protocol (HTTP/HTTPS) you choose; attackers cannot reach your server directly.
Brotli compression, auto-minify, image optimization and HTTP/3 are applied automatically in transit.
When your CI/CD starts a deploy, the server is drained from traffic and visitors flow to another with no interruption. Once it finishes, HEIMWALL verifies health and returns it to traffic.
Set up several servers as separate load-balanced groups, and run different backends and upstream pools by rule and condition.
Track visitor trends without cookies, using a privacy-friendly estimated-visitor metric. Compliant with KVKK and GDPR.
Watch live access logs with advanced filtering, and pull usage reports by year, month or day with a per-region traffic breakdown.
Every change is recorded in an audit log, alongside a history of the e-mail notifications the platform has sent.
A highly detailed access log with fast filtering by response time, country or carrier, so everything stays under control and you spot errors quickly.
Add cookies based on visitor consent via IAB TCF v2 (CMP consent string), track consented visitors separately, and see every cookie HEIMWALL uses.
Watch all your origin servers from one screen and take them out or back in with the threshold rules you set. Every status change is reported to you.
Push attack and anomaly events to your systems with HMAC-signed webhooks, and get mobile push notifications on the iOS and Android apps.
Everything in the console is available over the API, with scoped API keys so each integration gets exactly the access it needs.
Resellers can create users across multiple platforms and track each separately, offering seamless support with per-user redirect URLs.
Request a demo
Let's go through the console together using your own scenarios.