Smart WAF vs Cloudflare
An honest, side-by-side capability map — what Smart WAF does, what Cloudflare does, and where we plainly do not compete.
Comparison pages usually flatter whoever wrote them. This one is built the other way. Every row on the Smart WAF side traces to code running at our edge today; every Cloudflare cell is a publicly-true fact, including the rows where an incumbent hyperscaler plainly leads. We are a EU-based managed WAF, not a global platform — the table below says exactly where that helps and where it does not.
Where we don't compete, we say so plainly. This table is not curated to flatter us.
| Smart WAF | Cloudflare | |
|---|---|---|
| WAF engine & OWASP CRS rules | YesDual signature WAF engines — one in an in-process WASM sandbox, one native — run the OWASP ruleset against every request, selectable per route. | YesManaged WAF with its own signature set and an optional managed OWASP Core Rule Set. |
| Graduated challenge ladder | YesSuspicious clients escalate through proof-of-work, then CAPTCHA, then Web Bot Auth (cryptographic HTTP message signatures) — never an all-or-nothing block. | YesOffers managed challenges and its own Turnstile CAPTCHA. |
| ML entity-scoring with detection → verify → enforce graduation | YesPer-entity risk scoring proves itself through detection, then verify, before it is ever allowed to enforce. | PartialShips ML-based bot and threat scoring, but not this explicit detection → verify → enforce graduation model. |
| L3/L4 edge early-drop | YesConfirmed-malice traffic is dropped in the kernel via nftables/netdev before it reaches the WAF. | YesOperates large-scale network-layer (L3/L4) DDoS mitigation. |
| Per-tenant Let's Encrypt certificates | YesPer-tenant automatic TLS issues and renews a dedicated Let's Encrypt certificate for each tenant domain. | YesIssues and manages TLS certificates automatically for proxied domains. |
| EU data residency, GDPR-native, no cookies or trackers | YesEdge nodes run in the EU (Hetzner, OVH, Scaleway); residency, retention and deletion are architectural defaults, and this site sets no cookies or trackers. | PartialUS-headquartered; EU and regional data-localisation are available as configuration rather than the default. |
| Full immutable audit trail | YesEvery write lands in an append-only audit log surfaced in the tenant portal. | YesProvides audit and activity logging across its dashboard. |
| Global CDN / Anycast PoP network | NoWe are not a CDN. We do not run a worldwide fleet of edge points of presence or a content cache — if global static delivery is your primary need, a CDN is the right tool and we are not it. | YesRuns one of the largest global Anycast CDN and PoP networks. |
| Free self-serve tier | NoNo free self-serve plan. Our model is managed onboarding — we bring domains under the edge by hand, so a person is accountable for the config. | YesOffers a long-standing free self-serve tier. |
| Held third-party compliance certifications | NoWe hold no third-party compliance certifications yet, and our claims audit states plainly what we do and do not hold. | YesHolds a broad portfolio of independently audited compliance certifications. |
| Production-scale fleet & published throughput benchmarks | PartialWe run a single staging node today; any latency figure is labelled staging-measured against a ≤5 ms design budget, never presented as a production-fleet result. | YesOperates a global production fleet with published performance figures. |
See it running on your own domain
We onboard early partners by hand. Tell us your domain and we take it from there.