Software Products

Full reference for CloudEDGE Security and the Webscale Platform Software tiers, including the comparison matrix, per-tier detail and the features glossary.

CloudEDGE Security

CloudEDGE Security is the Webscale security product for customers whose applications are hosted outside Webscale. It deploys Webscale’s security layer in front of an existing application. It provides origin protection, DDoS defense, bot management, a Web Application Firewall, OWASP Top 10 coverage, role-based access control, carding attack protection and data loss prevention. It does not include the platform’s performance and delivery features. Those are offered through the Webscale Platform Software paired with a Webscale hosting plan.

Allowances and capabilities

AllowanceIncluded
Data Transfer50 GB
Requests25 M
Application Hostnames5 (guidance)
Elastic Data PlaneShared
CDNIncluded
Custom Web Controls20
Traffic Viewer storage50 GB
Monitors5

Metered allowances are consumption-based above the included amount. Application Hostnames counts are guidance. See the Application Hostnames entry in the features glossary.

Included security features

FeatureIncluded
Origin Protection (App Shield)Level 1
Auto HTTPSIncluded
Bring Your Own SSL CertificateIncluded
Geo-blockingIncluded
DDoS ProtectionIncluded
Origin CertificatesIncluded
CSPIncluded
Rate LimitingBasic
Bot ManagementIncluded
Bot MitigationIncluded
WAF (WAAP)Basic
OWASP ProtectionIncluded
Role-based Access ControlIncluded
Carding Attack ProtectionIncluded
Trusted ProxiesIncluded
Secure AccessIncluded
Data Loss PreventionIncluded

Included observability features

FeatureIncluded
Traffic Viewer storage50 GB
Event Logs (audit)5 years, no additional cost
Session TrackingIncluded
Real User Monitoring (RUM)Included
Additional Online LogsIncluded
Archived LogsIncluded
Monitors5
Custom Log CaptureIncluded

Who this product is for

Customers running an application outside Webscale who need a managed security layer in front of it. Customers hosting on Webscale should look at the Webscale Platform Software instead.

Webscale Platform Software

The Webscale Platform Software is sold in four tiers. Each tier includes a fixed set of performance, security and observability capabilities along with a defined allowance for metered resources.

  • Essentials. The entry Platform tier, suitable for smaller applications. It includes the core performance and delivery features of the platform with a basic security and observability baseline.
  • Advanced. Adds dynamic site caching, image optimization, expanded Traffic Viewer storage, session tracking, real user monitoring, archived logs, OWASP protection, CSP and expanded Web Controls and Monitors allowances.
  • Premier. Adds Site Splicing, Bot Management and Bot Mitigation, Advanced WAF, role-based access control, carding attack protection, data loss prevention and custom log capture.
  • Ultra. Adds a dedicated elastic data plane, Level 3 origin protection, Advanced rate limiting, Trusted Proxies, Secure Access and the largest included allowances for every metered feature.

All four Platform tiers are paired with a Webscale hosting plan. The available pairings, pricing and upgrade rules are published on webscale.com.

Platform Software comparison matrix

Headline allowances

AllowanceEssentialsAdvancedPremierUltra
Included Data Transfer50 GB250 GB500 GB1,000 GB
Included Requests25 M125 M250 M500 M
Application Hostnames2520100
Elastic Data PlaneSharedSharedSharedDedicated

All metered allowances are consumption-based above the included amount. Rates are published on webscale.com. Application Hostnames counts are guidance. See the Application Hostnames entry in the features glossary.

Performance and delivery

FeatureEssentialsAdvancedPremierUltra
Predictive Auto-scalingIncludedIncludedIncludedIncluded
Self-healingIncludedIncludedIncludedIncluded
Load BalancingIncludedIncludedIncludedIncluded
Elastic Data PlaneSharedSharedSharedDedicated
CDNIncludedIncludedIncludedIncluded
Dynamic Site CacheNot included1 GB5 GB10 GB
Dynamic Site Cache RulesNot included1510
Custom Web ControlsNot included1020100
Site SplicingNot includedNot includedIncludedIncluded
Custom MicrositesNot included1 (5 MB)5 (20 MB)10 (50 MB)
Image OptimizationNot included100K/mo200K/mo500K/mo

Security

FeatureEssentialsAdvancedPremierUltra
Origin Protection (App Shield)Level 1Level 2Level 2Level 3
Auto HTTPSIncludedIncludedIncludedIncluded
Bring Your Own SSLIncludedIncludedIncludedIncluded
Geo-blockingIncludedIncludedIncludedIncluded
DDoS ProtectionIncludedIncludedIncludedIncluded
Origin CertificatesIncludedIncludedIncludedIncluded
CSPNot includedIncludedIncludedIncluded
Rate LimitingNot includedBasicBasicAdvanced
Bot ManagementNot includedNot includedIncludedIncluded
Bot MitigationNot includedNot includedIncludedIncluded
WAF (WAAP)BasicBasicAdvancedAdvanced
OWASP ProtectionNot includedIncludedIncludedIncluded
Role-based Access ControlNot includedNot includedIncludedIncluded
Carding Attack ProtectionNot includedNot includedIncludedIncluded
Trusted ProxiesNot includedNot includedNot includedIncluded
Secure AccessNot includedNot includedNot includedIncluded
Data Loss PreventionNot includedNot includedIncludedIncluded

Observability

FeatureEssentialsAdvancedPremierUltra
Traffic Viewer storage10 GB50 GB75 GB100 GB
Event Logs (audit, 5yr free)IncludedIncludedIncludedIncluded
Session TrackingNot includedIncludedIncludedIncluded
Real User Monitoring (RUM)Not includedIncludedIncludedIncluded
Additional Online LogsNot includedNot includedIncludedIncluded
Archived LogsNot includedIncludedIncludedIncluded
Monitors (included)Not included51050
Custom Log CaptureNot includedNot includedIncludedIncluded

Event Logs are configuration audit logs. They are retained at no additional cost for 5 years across all products and tiers. Other Traffic Viewer log types such as request logs and custom logs count against the tier’s GB storage allowance.

Add-ons

Add-onEssentialsAdvancedPremierUltra
VarnishOptionalOptionalOptionalOptional

Per-tier detail

Each tier follows the same template: a positioning paragraph, headline allowances, a note on who the tier is for and a pointer to the features glossary for full feature definitions.

Essentials

Essentials is the entry Webscale Platform tier. It includes the core performance and delivery capabilities of the platform such as predictive auto-scaling, self-healing, load balancing and CDN, along with a baseline security layer covering Auto HTTPS, Bring Your Own SSL, geo-blocking, DDoS protection, origin certificates and basic WAF. It is intended for smaller applications and lower-traffic workloads.

AllowanceIncluded
Included Data Transfer50 GB
Included Requests25 M
Application Hostnames2 (guidance)
Elastic Data PlaneShared
CDNIncluded
Custom Web Controls0
Traffic Viewer storage10 GB
Monitors0

Who this tier is for. Customers running smaller applications who need Webscale’s hosting and core delivery features with a baseline security and observability layer. Customers needing dynamic site caching, image optimization, expanded Traffic Viewer storage, RUM or stronger security should consider Advanced.

Advanced

Advanced is the mid Platform tier. It builds on Essentials by adding dynamic site caching at 1 GB, image optimization at 100K transforms per month, expanded Traffic Viewer storage, session tracking, real user monitoring, archived logs, OWASP protection, CSP support, Level 2 origin protection, basic rate limiting and 10 Custom Web Controls and Monitors.

AllowanceIncluded
Included Data Transfer250 GB
Included Requests125 M
Application Hostnames5 (guidance)
Elastic Data PlaneShared
CDNIncluded
Dynamic Site Cache1 GB (1 rule)
Custom Microsites1 (up to 5 MB)
Image Optimization100K transforms/month
Custom Web Controls10
Traffic Viewer storage50 GB
Monitors5
Origin ProtectionLevel 2

Who this tier is for. Mid-sized applications needing serious performance, baseline security and full observability. Customers needing Site Splicing, bot management, advanced WAF, role-based access control, carding attack protection or data loss prevention should consider Premier.

Premier

Premier is the upper Platform tier, suitable for high-traffic applications with substantive performance, security and observability needs. It adds Site Splicing, Bot Management and Bot Mitigation, Advanced WAF, role-based access control, carding attack protection, data loss prevention and custom log capture.

AllowanceIncluded
Included Data Transfer500 GB
Included Requests250 M
Application Hostnames20 (guidance)
Elastic Data PlaneShared
CDNIncluded
Dynamic Site Cache5 GB (5 rules)
Custom Microsites5 (up to 20 MB)
Image Optimization200K transforms/month
Custom Web Controls20
Traffic Viewer storage75 GB
Monitors10
WAFAdvanced
Origin ProtectionLevel 2

Who this tier is for. High-traffic applications needing the platform’s full delivery and security capabilities at substantial scale but able to operate on a shared data plane. Customers needing a dedicated data plane, Level 3 origin protection, advanced rate limiting, trusted proxies or secure access should consider Ultra.

Ultra

Ultra is the top Platform tier. It is differentiated from Premier by a dedicated elastic data plane, Level 3 origin protection, Advanced rate limiting, trusted proxies and secure access, along with the largest included allowances for every metered feature. Ultra is intended for the highest-traffic and most security-sensitive applications on the Webscale platform.

AllowanceIncluded
Included Data Transfer1,000 GB
Included Requests500 M
Application Hostnames100 (guidance)
Elastic Data PlaneDedicated
CDNIncluded
Dynamic Site Cache10 GB (10 rules)
Custom Microsites10 (up to 50 MB)
Image Optimization500K transforms/month
Custom Web Controls100
Traffic Viewer storage100 GB
Monitors50
WAFAdvanced
Origin ProtectionLevel 3
Rate LimitingAdvanced

Who this tier is for. Customers with the highest performance, isolation and security requirements, including those who require a dedicated data plane for compliance or traffic isolation reasons.

Features glossary

This section is the educational feature reference. Each feature is defined once and used identically across CloudEDGE Security, the Platform comparison matrix and the per-tier detail.

Performance and delivery

FeatureDefinitionAvailable in
Predictive Auto-scalingUses automation and predictive analytics to increase or decrease application resources to maintain consistent performance without over-allocation.All Platform tiers. Not in CloudEDGE Security.
Self-healingAn extension of auto-scaling that ensures failed application components are promptly replaced to avoid timeouts and error pages.All Platform tiers. Not in CloudEDGE Security.
Load BalancingActively distributes requests across application servers and routes around servers experiencing performance or availability issues.All Platform tiers. Not in CloudEDGE Security.
Elastic Data PlaneThe intermediary between web browsers and your application. A shared data plane uses IP addresses socialized with other applications. A dedicated data plane uses addresses unique to your application and can deploy data plane assets into a public subnet of your own VPC for enhanced security.Shared on CloudEDGE Security, Essentials, Advanced and Premier. Dedicated on Ultra.
CDNA globally distributed set of servers that delivers cacheable content from a location close to the visitor, reducing latency and origin load. Includes standard caching rules for static content and media. Additional caching behavior can be configured using Custom Web Controls.All products.
Application HostnamesThe hostnames to which an application responds. No hard limit is enforced today. Included counts are guidance. Auto HTTPS provisions one certificate per group of up to roughly 150 hostnames.CloudEDGE Security 5, Essentials 2, Advanced 5, Premier 20, Ultra 100.
Data TransferThe aggregate volume of data delivered through the Webscale Data Plane to end users in a billing period. Overage is consumption-based.All products. 50, 50, 250, 500, 1,000 GB.
Included RequestsTotal number of HTTP requests handled by the Webscale Data Plane in a billing period. Overage is consumption-based.All products. 25 M, 25 M, 125 M, 250 M, 500 M.
Dynamic Site CacheA cache located in the Webscale Data Plane that provides extremely fast access near application servers. Combined with the CDN it can substantially reduce origin load.Advanced 1 GB, Premier 5 GB, Ultra 10 GB.
Dynamic Site Cache RulesRules that determine what is cacheable, for how long and on which browser or user-state. Multiple cache versions of the same resource can be maintained by request characteristics.Advanced 1, Premier 5, Ultra 10.
Custom Web ControlsA configurable policy and rules engine in the Webscale Portal that combines conditions with actions applied to requests proxied by the Data Plane. Used for both security and performance customization.CloudEDGE Security 20, Advanced 10, Premier 20, Ultra 100. Not in Essentials.
Site SplicingCombines multiple origins into a single site, allowing different application components to serve specific paths or roles within one customer-facing site.Premier, Ultra.
Custom MicrositesAllows content to be injected into a site without modifying the application. For PWA or headless applications, microsites can serve the entire application.Advanced 1 site up to 5 MB, Premier 5 sites up to 20 MB, Ultra 10 sites up to 50 MB.
Image OptimizationAutomated image management that delivers an appropriately sized image to each device, served from the nearest cache. Overage is consumption-based.Advanced 100K/mo, Premier 200K/mo, Ultra 500K/mo.

Security

FeatureDefinitionAvailable in
Origin Protection (App Shield)Because the Data Plane sits between users and the application, application servers are not directly exposed. Level 1 hides server addresses behind the Data Plane. Level 2 manages a cloud Security Group or Firewall so only Webscale proxies can connect. Level 3 places a dedicated Data Plane on the same private network as application servers, isolating them from the internet.Level 1 on CloudEDGE Security and Essentials. Level 2 on Advanced and Premier. Level 3 on Ultra.
Auto HTTPSWebscale automatically obtains and renews site certificates so HTTPS is always functional. Adding a new hostname triggers automatic certificate handling.All products.
Bring Your Own SSL CertificateThe Data Plane supports management of one or more customer-provided certificates alongside Auto HTTPS.All products.
Geo-blockingRequests are geo-located by origin country and Web Controls rules can allow or block access by country.All products.
DDoS ProtectionAlways-on protection that limits the maximum number of concurrent requesters and uses dynamic address sets to block repeat requesters. Predictive Auto-scaling of the Data Plane absorbs the attacks.All products.
Origin CertificatesLong-lasting certificates that protect communication from the Data Plane to application servers, avoiding downtime caused by unexpected expiry of publicly trusted certificates.All products.
CSP (Content Security Policy)Over-the-top CSP support independent of the application’s implementation, separating policy from the site so injected attacks cannot succeed.CloudEDGE Security, Advanced, Premier, Ultra. Not in Essentials.
Rate LimitingRejects requests from a single source that exceed a defined rate for a defined blocking period. Basic provides a built-in rate with automatic enforcement. Advanced provides per-area configurable rates and configurable blocking periods.Basic on CloudEDGE Security, Advanced and Premier. Advanced on Ultra. Not in Essentials.
Bot ManagementSeparates legitimate bots from malicious ones using Webscale-provided, dynamically updated Address Sets. Automatically detects and categorizes malicious bot behavior.CloudEDGE Security, Premier, Ultra.
Bot MitigationA coordinated set of mechanisms for distinguishing automated traffic from legitimate users and challenging or blocking suspect requests. Today it is delivered as a combination of reCAPTCHA integration, user-agent classification rules configured in Web Controls and forthcoming ASN-level blocking. These mechanisms will be unified under a single feature surface in a future UI release.CloudEDGE Security, Premier, Ultra.
WAF (WAAP)The Cloud WAF protects applications by examining HTTP requests and blocking or modifying malicious ones. Basic provides automatic blocking of known attack signatures. Advanced provides custom configurable conditions for advanced attacks.Basic on CloudEDGE Security, Essentials and Advanced. Advanced on Premier and Ultra.
OWASP ProtectionAutomated protection against the OWASP Top 10 and other common web vulnerabilities such as SQL Injection, XSS and CSRF.CloudEDGE Security, Advanced, Premier, Ultra. Not in Essentials.
Role-based Access Control (RBAC)Fine-grained permission assignment for users managing application configurations and other resources.CloudEDGE Security, Premier, Ultra.
Carding Attack Protection (CAP)Uses knowledge of user behavior on e-commerce sites to recognize and stop carding attacks before they occur.CloudEDGE Security, Premier, Ultra.
Trusted ProxiesAllows another technology in front of the Data Plane to be registered as trusted, so requests passing through it are correctly identified and can be restricted to come only from a trusted proxy.CloudEDGE Security, Ultra.
Secure AccessRole-based permissions applied to sections of the application to restrict access from the general internet to authenticated, role-authorized users.CloudEDGE Security, Ultra.
Data Loss PreventionPrevents exfiltration of data by limiting access or request volume to sensitive parts of the site.CloudEDGE Security, Premier, Ultra.

Observability

FeatureDefinitionAvailable in
Traffic ViewerA real-time view inside the Webscale Portal of CDN requests, application server requests, Data Plane requests, monitor-generated events, configuration changes and custom application logs. Storage is measured in gigabytes and retention duration is configurable per application and account.All products.
Event Logs (configuration audit)Logs that record configuration changes and access to the Webscale platform, including who made what changes and when. These are the platform’s audit trail.All products. Retained 5 years at no additional cost.
Session TrackingAutomatically tracks user sessions and makes session IDs available in the Traffic Viewer so requests belonging to a session can be analyzed together.CloudEDGE Security, Advanced, Premier, Ultra.
Real User Monitoring (RUM)Collects performance data from end users’ browsers to inform Core Web Vitals tuning and measure the impact of site changes.CloudEDGE Security, Advanced, Premier, Ultra.
Additional Online LogsAll online logs are viewed via the Traffic Viewer. Online log storage counts against the Traffic Viewer GB allowance for the tier and retention is configurable.CloudEDGE Security, Premier, Ultra.
Archived LogsLogs that no longer need to be viewable in the Traffic Viewer but must be retained for audit. Available for download via API. Archived log storage is billed on consumption separately from Traffic Viewer storage.CloudEDGE Security, Advanced, Premier, Ultra.
MonitorsA configurable observer of an application component, used to notify or take action when a condition is met, for example average response time exceeding a threshold for critical pages.CloudEDGE Security 5, Advanced 5, Premier 10, Ultra 50. Not in Essentials.
Custom Log CaptureA feature of the Webscale Monitoring Agent that captures logs from files in real-time and stores them as online custom logs viewable in the Traffic Viewer. Captured logs count against the tier’s Traffic Viewer GB allowance.CloudEDGE Security, Premier, Ultra.

Add-ons

FeatureDefinitionAvailable in
VarnishAn industry-standard caching solution integrated completely with Webscale’s core features. Webscale operates and maintains the Varnish layer so customers receive its caching benefits with zero maintenance overhead and automatic failover.Optional on all Platform tiers. Not offered with CloudEDGE Security.
Have questions not answered here? Contact Support to get more help.

Last modified on August 18, 2026