Web application firewall on your own Gcore account

Protect your sites with your own Gcore WAAP

Connect your own Gcore account and manage its web application and API protection from the dashboard: see which domains are protected and switch a domain's protection mode without opening another control panel. The protection runs on your Gcore account, and Gcore bills you for it directly.

What it is

Gcore WAAP is Gcore's web application and API protection. Connect an API key from your own Gcore account with WAAP enabled, and the dashboard lists the domains that account protects, under Integrations → Your own services.

We do not sell, price or provide Gcore WAAP. Gcore's terms do not allow it to be resold, so it is available here only on your own account: your contract with Gcore, and your bill from Gcore.

A website protected behind layered shields

What you get

The firewall controls you reach for most, next to the sites they protect.

Protected domains, listed

Every domain the connected WAAP account protects appears in the dashboard with its current protection mode.

Switch the protection mode

Move a domain between blocking attacks, monitor only and off from the dashboard — useful while testing a release or chasing a false positive.

Locked settings stay locked

Where Gcore has locked a domain's mode, the dashboard says so and points you to your Gcore control panel instead of pretending to change it.

Checked before it is saved

The key is tested against Gcore before anything is stored, and a key that cannot read your WAAP account is refused with the reason.

Stored encrypted, deleted on disconnect

A key that passes is kept encrypted in our secrets vault, and disconnecting deletes it. Your WAAP configuration stays on your Gcore account.

Step-by-step guides

Each guide shows where to create the key on the provider's side, what it needs, and how to connect it in the dashboard.

How it works

Your rules and domains stay in Gcore; the dashboard gives you the switch you use most.

  1. Enable WAAP with Gcore

    WAAP must be enabled for your own Gcore account, with your domains added there.

  2. Connect an API key

    Paste an API key from your Gcore account into Integrations. It is tested before it is saved.

  3. Manage protection

    Open Your own services to see your protected domains and change a domain's protection mode.

Pricing

There is no Zinn Digital® price for WAAP, because we do not sell it.

We charge nothing for the connection. Gcore bills you directly, on your own account and at Gcore's own prices, for the protection you use. Your Zinn Digital® hosting plan is billed as normal.

WAAP plans, limits and prices are set by Gcore and shown in your Gcore account. We never add to them.

Why it is built this way

A firewall is a contract with whoever runs it. Gcore's agreement does not permit WAAP to be resold, so connecting your own account is the honest way to put it beside your sites.

Switching a domain to monitor only during a release, then back to blocking, is the change people make most often. Having that switch in the same dashboard as the site saves a context switch at exactly the moment it matters.

Questions people ask before they buy

Do you sell Gcore WAAP?

No. It is available only by connecting your own Gcore account. We do not resell, price or provide it — Gcore's terms do not allow resale.

Which protection modes can I choose?

Blocking attacks, monitor only or off, per domain. If Gcore has locked a domain's mode, the dashboard shows it as locked and you change it in your Gcore control panel.

Who bills me for WAAP?

Gcore, directly, on your own account. The connection costs nothing from us, and your hosting plan is billed as normal.

Do I need WAAP enabled first?

Yes. The connection reads the WAAP product on your Gcore account, so it has to be enabled there, with your domains added, before they appear in the dashboard.

How is my API key kept?

It is tested against Gcore before it is saved, stored encrypted in our secrets vault, and deleted when you disconnect.

Connect your Gcore WAAP account

Create an account, open Integrations and paste in a key from your Gcore account, then manage your domains' protection from Your own services.

Get started