Software Products
CloudEDGE Security
CloudEDGE Security is the Webscale security product for customers whose applications are hosted outside Webscale. It deploys Webscale’s security layer in front of an existing application. It provides origin protection, DDoS defense, bot management, a Web Application Firewall, OWASP Top 10 coverage, role-based access control, carding attack protection and data loss prevention. It does not include the platform’s performance and delivery features. Those are offered through the Webscale Platform Software paired with a Webscale hosting plan.
Allowances and capabilities
| Allowance | Included |
|---|---|
| Data Transfer | 50 GB |
| Requests | 25 M |
| Application Hostnames | 5 (guidance) |
| Elastic Data Plane | Shared |
| CDN | Included |
| Custom Web Controls | 20 |
| Traffic Viewer storage | 50 GB |
| Monitors | 5 |
Metered allowances are consumption-based above the included amount. Application Hostnames counts are guidance. See the Application Hostnames entry in the features glossary.
Included security features
| Feature | Included |
|---|---|
| Origin Protection (App Shield) | Level 1 |
| Auto HTTPS | Included |
| Bring Your Own SSL Certificate | Included |
| Geo-blocking | Included |
| DDoS Protection | Included |
| Origin Certificates | Included |
| CSP | Included |
| Rate Limiting | Basic |
| Bot Management | Included |
| Bot Mitigation | Included |
| WAF (WAAP) | Basic |
| OWASP Protection | Included |
| Role-based Access Control | Included |
| Carding Attack Protection | Included |
| Trusted Proxies | Included |
| Secure Access | Included |
| Data Loss Prevention | Included |
Included observability features
| Feature | Included |
|---|---|
| Traffic Viewer storage | 50 GB |
| Event Logs (audit) | 5 years, no additional cost |
| Session Tracking | Included |
| Real User Monitoring (RUM) | Included |
| Additional Online Logs | Included |
| Archived Logs | Included |
| Monitors | 5 |
| Custom Log Capture | Included |
Who this product is for
Customers running an application outside Webscale who need a managed security layer in front of it. Customers hosting on Webscale should look at the Webscale Platform Software instead.
Webscale Platform Software
The Webscale Platform Software is sold in four tiers. Each tier includes a fixed set of performance, security and observability capabilities along with a defined allowance for metered resources.
- Essentials. The entry Platform tier, suitable for smaller applications. It includes the core performance and delivery features of the platform with a basic security and observability baseline.
- Advanced. Adds dynamic site caching, image optimization, expanded Traffic Viewer storage, session tracking, real user monitoring, archived logs, OWASP protection, CSP and expanded Web Controls and Monitors allowances.
- Premier. Adds Site Splicing, Bot Management and Bot Mitigation, Advanced WAF, role-based access control, carding attack protection, data loss prevention and custom log capture.
- Ultra. Adds a dedicated elastic data plane, Level 3 origin protection, Advanced rate limiting, Trusted Proxies, Secure Access and the largest included allowances for every metered feature.
All four Platform tiers are paired with a Webscale hosting plan. The available pairings, pricing and upgrade rules are published on webscale.com.
Platform Software comparison matrix
Headline allowances
| Allowance | Essentials | Advanced | Premier | Ultra |
|---|---|---|---|---|
| Included Data Transfer | 50 GB | 250 GB | 500 GB | 1,000 GB |
| Included Requests | 25 M | 125 M | 250 M | 500 M |
| Application Hostnames | 2 | 5 | 20 | 100 |
| Elastic Data Plane | Shared | Shared | Shared | Dedicated |
All metered allowances are consumption-based above the included amount. Rates are published on webscale.com. Application Hostnames counts are guidance. See the Application Hostnames entry in the features glossary.
Performance and delivery
| Feature | Essentials | Advanced | Premier | Ultra |
|---|---|---|---|---|
| Predictive Auto-scaling | Included | Included | Included | Included |
| Self-healing | Included | Included | Included | Included |
| Load Balancing | Included | Included | Included | Included |
| Elastic Data Plane | Shared | Shared | Shared | Dedicated |
| CDN | Included | Included | Included | Included |
| Dynamic Site Cache | Not included | 1 GB | 5 GB | 10 GB |
| Dynamic Site Cache Rules | Not included | 1 | 5 | 10 |
| Custom Web Controls | Not included | 10 | 20 | 100 |
| Site Splicing | Not included | Not included | Included | Included |
| Custom Microsites | Not included | 1 (5 MB) | 5 (20 MB) | 10 (50 MB) |
| Image Optimization | Not included | 100K/mo | 200K/mo | 500K/mo |
Security
| Feature | Essentials | Advanced | Premier | Ultra |
|---|---|---|---|---|
| Origin Protection (App Shield) | Level 1 | Level 2 | Level 2 | Level 3 |
| Auto HTTPS | Included | Included | Included | Included |
| Bring Your Own SSL | Included | Included | Included | Included |
| Geo-blocking | Included | Included | Included | Included |
| DDoS Protection | Included | Included | Included | Included |
| Origin Certificates | Included | Included | Included | Included |
| CSP | Not included | Included | Included | Included |
| Rate Limiting | Not included | Basic | Basic | Advanced |
| Bot Management | Not included | Not included | Included | Included |
| Bot Mitigation | Not included | Not included | Included | Included |
| WAF (WAAP) | Basic | Basic | Advanced | Advanced |
| OWASP Protection | Not included | Included | Included | Included |
| Role-based Access Control | Not included | Not included | Included | Included |
| Carding Attack Protection | Not included | Not included | Included | Included |
| Trusted Proxies | Not included | Not included | Not included | Included |
| Secure Access | Not included | Not included | Not included | Included |
| Data Loss Prevention | Not included | Not included | Included | Included |
Observability
| Feature | Essentials | Advanced | Premier | Ultra |
|---|---|---|---|---|
| Traffic Viewer storage | 10 GB | 50 GB | 75 GB | 100 GB |
| Event Logs (audit, 5yr free) | Included | Included | Included | Included |
| Session Tracking | Not included | Included | Included | Included |
| Real User Monitoring (RUM) | Not included | Included | Included | Included |
| Additional Online Logs | Not included | Not included | Included | Included |
| Archived Logs | Not included | Included | Included | Included |
| Monitors (included) | Not included | 5 | 10 | 50 |
| Custom Log Capture | Not included | Not included | Included | Included |
Event Logs are configuration audit logs. They are retained at no additional cost for 5 years across all products and tiers. Other Traffic Viewer log types such as request logs and custom logs count against the tier’s GB storage allowance.
Add-ons
| Add-on | Essentials | Advanced | Premier | Ultra |
|---|---|---|---|---|
| Varnish | Optional | Optional | Optional | Optional |
Per-tier detail
Each tier follows the same template: a positioning paragraph, headline allowances, a note on who the tier is for and a pointer to the features glossary for full feature definitions.
Essentials
Essentials is the entry Webscale Platform tier. It includes the core performance and delivery capabilities of the platform such as predictive auto-scaling, self-healing, load balancing and CDN, along with a baseline security layer covering Auto HTTPS, Bring Your Own SSL, geo-blocking, DDoS protection, origin certificates and basic WAF. It is intended for smaller applications and lower-traffic workloads.
| Allowance | Included |
|---|---|
| Included Data Transfer | 50 GB |
| Included Requests | 25 M |
| Application Hostnames | 2 (guidance) |
| Elastic Data Plane | Shared |
| CDN | Included |
| Custom Web Controls | 0 |
| Traffic Viewer storage | 10 GB |
| Monitors | 0 |
Who this tier is for. Customers running smaller applications who need Webscale’s hosting and core delivery features with a baseline security and observability layer. Customers needing dynamic site caching, image optimization, expanded Traffic Viewer storage, RUM or stronger security should consider Advanced.
Advanced
Advanced is the mid Platform tier. It builds on Essentials by adding dynamic site caching at 1 GB, image optimization at 100K transforms per month, expanded Traffic Viewer storage, session tracking, real user monitoring, archived logs, OWASP protection, CSP support, Level 2 origin protection, basic rate limiting and 10 Custom Web Controls and Monitors.
| Allowance | Included |
|---|---|
| Included Data Transfer | 250 GB |
| Included Requests | 125 M |
| Application Hostnames | 5 (guidance) |
| Elastic Data Plane | Shared |
| CDN | Included |
| Dynamic Site Cache | 1 GB (1 rule) |
| Custom Microsites | 1 (up to 5 MB) |
| Image Optimization | 100K transforms/month |
| Custom Web Controls | 10 |
| Traffic Viewer storage | 50 GB |
| Monitors | 5 |
| Origin Protection | Level 2 |
Who this tier is for. Mid-sized applications needing serious performance, baseline security and full observability. Customers needing Site Splicing, bot management, advanced WAF, role-based access control, carding attack protection or data loss prevention should consider Premier.
Premier
Premier is the upper Platform tier, suitable for high-traffic applications with substantive performance, security and observability needs. It adds Site Splicing, Bot Management and Bot Mitigation, Advanced WAF, role-based access control, carding attack protection, data loss prevention and custom log capture.
| Allowance | Included |
|---|---|
| Included Data Transfer | 500 GB |
| Included Requests | 250 M |
| Application Hostnames | 20 (guidance) |
| Elastic Data Plane | Shared |
| CDN | Included |
| Dynamic Site Cache | 5 GB (5 rules) |
| Custom Microsites | 5 (up to 20 MB) |
| Image Optimization | 200K transforms/month |
| Custom Web Controls | 20 |
| Traffic Viewer storage | 75 GB |
| Monitors | 10 |
| WAF | Advanced |
| Origin Protection | Level 2 |
Who this tier is for. High-traffic applications needing the platform’s full delivery and security capabilities at substantial scale but able to operate on a shared data plane. Customers needing a dedicated data plane, Level 3 origin protection, advanced rate limiting, trusted proxies or secure access should consider Ultra.
Ultra
Ultra is the top Platform tier. It is differentiated from Premier by a dedicated elastic data plane, Level 3 origin protection, Advanced rate limiting, trusted proxies and secure access, along with the largest included allowances for every metered feature. Ultra is intended for the highest-traffic and most security-sensitive applications on the Webscale platform.
| Allowance | Included |
|---|---|
| Included Data Transfer | 1,000 GB |
| Included Requests | 500 M |
| Application Hostnames | 100 (guidance) |
| Elastic Data Plane | Dedicated |
| CDN | Included |
| Dynamic Site Cache | 10 GB (10 rules) |
| Custom Microsites | 10 (up to 50 MB) |
| Image Optimization | 500K transforms/month |
| Custom Web Controls | 100 |
| Traffic Viewer storage | 100 GB |
| Monitors | 50 |
| WAF | Advanced |
| Origin Protection | Level 3 |
| Rate Limiting | Advanced |
Who this tier is for. Customers with the highest performance, isolation and security requirements, including those who require a dedicated data plane for compliance or traffic isolation reasons.
Features glossary
This section is the educational feature reference. Each feature is defined once and used identically across CloudEDGE Security, the Platform comparison matrix and the per-tier detail.
Performance and delivery
| Feature | Definition | Available in |
|---|---|---|
| Predictive Auto-scaling | Uses automation and predictive analytics to increase or decrease application resources to maintain consistent performance without over-allocation. | All Platform tiers. Not in CloudEDGE Security. |
| Self-healing | An extension of auto-scaling that ensures failed application components are promptly replaced to avoid timeouts and error pages. | All Platform tiers. Not in CloudEDGE Security. |
| Load Balancing | Actively distributes requests across application servers and routes around servers experiencing performance or availability issues. | All Platform tiers. Not in CloudEDGE Security. |
| Elastic Data Plane | The intermediary between web browsers and your application. A shared data plane uses IP addresses socialized with other applications. A dedicated data plane uses addresses unique to your application and can deploy data plane assets into a public subnet of your own VPC for enhanced security. | Shared on CloudEDGE Security, Essentials, Advanced and Premier. Dedicated on Ultra. |
| CDN | A globally distributed set of servers that delivers cacheable content from a location close to the visitor, reducing latency and origin load. Includes standard caching rules for static content and media. Additional caching behavior can be configured using Custom Web Controls. | All products. |
| Application Hostnames | The hostnames to which an application responds. No hard limit is enforced today. Included counts are guidance. Auto HTTPS provisions one certificate per group of up to roughly 150 hostnames. | CloudEDGE Security 5, Essentials 2, Advanced 5, Premier 20, Ultra 100. |
| Data Transfer | The aggregate volume of data delivered through the Webscale Data Plane to end users in a billing period. Overage is consumption-based. | All products. 50, 50, 250, 500, 1,000 GB. |
| Included Requests | Total number of HTTP requests handled by the Webscale Data Plane in a billing period. Overage is consumption-based. | All products. 25 M, 25 M, 125 M, 250 M, 500 M. |
| Dynamic Site Cache | A cache located in the Webscale Data Plane that provides extremely fast access near application servers. Combined with the CDN it can substantially reduce origin load. | Advanced 1 GB, Premier 5 GB, Ultra 10 GB. |
| Dynamic Site Cache Rules | Rules that determine what is cacheable, for how long and on which browser or user-state. Multiple cache versions of the same resource can be maintained by request characteristics. | Advanced 1, Premier 5, Ultra 10. |
| Custom Web Controls | A configurable policy and rules engine in the Webscale Portal that combines conditions with actions applied to requests proxied by the Data Plane. Used for both security and performance customization. | CloudEDGE Security 20, Advanced 10, Premier 20, Ultra 100. Not in Essentials. |
| Site Splicing | Combines multiple origins into a single site, allowing different application components to serve specific paths or roles within one customer-facing site. | Premier, Ultra. |
| Custom Microsites | Allows content to be injected into a site without modifying the application. For PWA or headless applications, microsites can serve the entire application. | Advanced 1 site up to 5 MB, Premier 5 sites up to 20 MB, Ultra 10 sites up to 50 MB. |
| Image Optimization | Automated image management that delivers an appropriately sized image to each device, served from the nearest cache. Overage is consumption-based. | Advanced 100K/mo, Premier 200K/mo, Ultra 500K/mo. |
Security
| Feature | Definition | Available in |
|---|---|---|
| Origin Protection (App Shield) | Because the Data Plane sits between users and the application, application servers are not directly exposed. Level 1 hides server addresses behind the Data Plane. Level 2 manages a cloud Security Group or Firewall so only Webscale proxies can connect. Level 3 places a dedicated Data Plane on the same private network as application servers, isolating them from the internet. | Level 1 on CloudEDGE Security and Essentials. Level 2 on Advanced and Premier. Level 3 on Ultra. |
| Auto HTTPS | Webscale automatically obtains and renews site certificates so HTTPS is always functional. Adding a new hostname triggers automatic certificate handling. | All products. |
| Bring Your Own SSL Certificate | The Data Plane supports management of one or more customer-provided certificates alongside Auto HTTPS. | All products. |
| Geo-blocking | Requests are geo-located by origin country and Web Controls rules can allow or block access by country. | All products. |
| DDoS Protection | Always-on protection that limits the maximum number of concurrent requesters and uses dynamic address sets to block repeat requesters. Predictive Auto-scaling of the Data Plane absorbs the attacks. | All products. |
| Origin Certificates | Long-lasting certificates that protect communication from the Data Plane to application servers, avoiding downtime caused by unexpected expiry of publicly trusted certificates. | All products. |
| CSP (Content Security Policy) | Over-the-top CSP support independent of the application’s implementation, separating policy from the site so injected attacks cannot succeed. | CloudEDGE Security, Advanced, Premier, Ultra. Not in Essentials. |
| Rate Limiting | Rejects requests from a single source that exceed a defined rate for a defined blocking period. Basic provides a built-in rate with automatic enforcement. Advanced provides per-area configurable rates and configurable blocking periods. | Basic on CloudEDGE Security, Advanced and Premier. Advanced on Ultra. Not in Essentials. |
| Bot Management | Separates legitimate bots from malicious ones using Webscale-provided, dynamically updated Address Sets. Automatically detects and categorizes malicious bot behavior. | CloudEDGE Security, Premier, Ultra. |
| Bot Mitigation | A coordinated set of mechanisms for distinguishing automated traffic from legitimate users and challenging or blocking suspect requests. Today it is delivered as a combination of reCAPTCHA integration, user-agent classification rules configured in Web Controls and forthcoming ASN-level blocking. These mechanisms will be unified under a single feature surface in a future UI release. | CloudEDGE Security, Premier, Ultra. |
| WAF (WAAP) | The Cloud WAF protects applications by examining HTTP requests and blocking or modifying malicious ones. Basic provides automatic blocking of known attack signatures. Advanced provides custom configurable conditions for advanced attacks. | Basic on CloudEDGE Security, Essentials and Advanced. Advanced on Premier and Ultra. |
| OWASP Protection | Automated protection against the OWASP Top 10 and other common web vulnerabilities such as SQL Injection, XSS and CSRF. | CloudEDGE Security, Advanced, Premier, Ultra. Not in Essentials. |
| Role-based Access Control (RBAC) | Fine-grained permission assignment for users managing application configurations and other resources. | CloudEDGE Security, Premier, Ultra. |
| Carding Attack Protection (CAP) | Uses knowledge of user behavior on e-commerce sites to recognize and stop carding attacks before they occur. | CloudEDGE Security, Premier, Ultra. |
| Trusted Proxies | Allows another technology in front of the Data Plane to be registered as trusted, so requests passing through it are correctly identified and can be restricted to come only from a trusted proxy. | CloudEDGE Security, Ultra. |
| Secure Access | Role-based permissions applied to sections of the application to restrict access from the general internet to authenticated, role-authorized users. | CloudEDGE Security, Ultra. |
| Data Loss Prevention | Prevents exfiltration of data by limiting access or request volume to sensitive parts of the site. | CloudEDGE Security, Premier, Ultra. |
Observability
| Feature | Definition | Available in |
|---|---|---|
| Traffic Viewer | A real-time view inside the Webscale Portal of CDN requests, application server requests, Data Plane requests, monitor-generated events, configuration changes and custom application logs. Storage is measured in gigabytes and retention duration is configurable per application and account. | All products. |
| Event Logs (configuration audit) | Logs that record configuration changes and access to the Webscale platform, including who made what changes and when. These are the platform’s audit trail. | All products. Retained 5 years at no additional cost. |
| Session Tracking | Automatically tracks user sessions and makes session IDs available in the Traffic Viewer so requests belonging to a session can be analyzed together. | CloudEDGE Security, Advanced, Premier, Ultra. |
| Real User Monitoring (RUM) | Collects performance data from end users’ browsers to inform Core Web Vitals tuning and measure the impact of site changes. | CloudEDGE Security, Advanced, Premier, Ultra. |
| Additional Online Logs | All online logs are viewed via the Traffic Viewer. Online log storage counts against the Traffic Viewer GB allowance for the tier and retention is configurable. | CloudEDGE Security, Premier, Ultra. |
| Archived Logs | Logs that no longer need to be viewable in the Traffic Viewer but must be retained for audit. Available for download via API. Archived log storage is billed on consumption separately from Traffic Viewer storage. | CloudEDGE Security, Advanced, Premier, Ultra. |
| Monitors | A configurable observer of an application component, used to notify or take action when a condition is met, for example average response time exceeding a threshold for critical pages. | CloudEDGE Security 5, Advanced 5, Premier 10, Ultra 50. Not in Essentials. |
| Custom Log Capture | A feature of the Webscale Monitoring Agent that captures logs from files in real-time and stores them as online custom logs viewable in the Traffic Viewer. Captured logs count against the tier’s Traffic Viewer GB allowance. | CloudEDGE Security, Premier, Ultra. |
Add-ons
| Feature | Definition | Available in |
|---|---|---|
| Varnish | An industry-standard caching solution integrated completely with Webscale’s core features. Webscale operates and maintains the Varnish layer so customers receive its caching benefits with zero maintenance overhead and automatic failover. | Optional on all Platform tiers. Not offered with CloudEDGE Security. |
Last modified on August 18, 2026