Smart WAF vs Myra
An honest, side-by-side capability map — what Smart WAF does, what Myra does as a BSI-certified German incumbent, and where we plainly do not compete.
Comparison pages usually flatter whoever wrote them. This one is built the other way. Myra is a German, BSI-certified incumbent built for critical-infrastructure mandates, and the table below states that plainly — including the credentials we do not hold. Both of us run in the EU, so data residency is a parity here, not a selling point. Every row on the Smart WAF side traces to code running at our edge today; our edge is engineering depth — the graduated challenge ladder, the detection → verify → enforce ML model, per-route dual engines — not compliance breadth. The table says exactly where each of us fits.
Where we don't compete, we say so plainly. This table is not curated to flatter us.
| Smart WAF | Myra | |
|---|---|---|
| WAF engine & OWASP CRS rules | YesDual signature WAF engines — one in an in-process WASM sandbox, one native — run the OWASP ruleset against every request, selectable per route. | YesManaged WAF with its own rule set as part of a broader security platform. |
| Graduated challenge ladder | YesSuspicious clients escalate through proof-of-work, then CAPTCHA, then Web Bot Auth (cryptographic HTTP message signatures) — never an all-or-nothing block. | PartialDeep-learning bot management with its own mitigation mechanisms, not a graduated proof-of-work → CAPTCHA → Web Bot Auth ladder. |
| ML entity-scoring with detection → verify → enforce graduation | YesPer-entity risk scoring proves itself through detection, then verify, before it is ever allowed to enforce. | PartialUses machine learning for DDoS and bot detection, but not this explicit detection → verify → enforce graduation model. |
| L3/L4 edge early-drop | YesConfirmed-malice traffic is dropped in the kernel via nftables/netdev before it reaches the WAF. | YesOperates large-scale network-layer (L3/L4) DDoS mitigation. |
| Per-tenant Let's Encrypt certificates | YesPer-tenant automatic TLS issues and renews a dedicated Let's Encrypt certificate for each tenant domain. | YesIssues and manages TLS certificates for protected domains. |
| EU / German data residency, GDPR-native | YesEdge nodes run in the EU (Hetzner, OVH, Scaleway); residency, retention and deletion are architectural defaults, and this site sets no cookies or trackers. | YesGerman-headquartered and operates data centres in Germany — EU residency is a parity, not a differentiator, here. |
| Full immutable audit trail | YesEvery write lands in an append-only audit log surfaced in the tenant portal. | YesProvides audit and activity logging in its management interface. |
| BSI C5 attestation & KRITIS-qualified operation | NoWe hold no BSI C5 attestation and are not qualified for KRITIS (critical-infrastructure) operators. If a German high-assurance mandate requires those credentials, that requirement is real and we do not meet it today. | YesCertified for German critical-infrastructure (KRITIS) operators with a BSI C5 attestation. |
| Held third-party compliance certifications | NoWe hold no third-party compliance certifications yet, and our claims audit states plainly what we do and do not hold. | YesHolds a broad portfolio of independently audited compliance certifications. |
| Global CDN / content-delivery network | NoWe are not a CDN. We do not run a fleet of edge points of presence or a content cache — if content delivery is your primary need, a CDN is the right tool and we are not it. | YesIncludes a content-delivery network alongside its security services. |
| Production-scale fleet & published throughput benchmarks | PartialWe run a single staging node today; any latency figure is labelled staging-measured against a ≤5 ms design budget, never presented as a production-fleet result. | YesOperates a production fleet serving critical-infrastructure customers. |
See it running on your own domain
We onboard early partners by hand. Tell us your domain and we take it from there.