Overview
Imperva, now part of Thales, sells Cloud WAF as the core of its Application Security platform. Traffic is routed through Imperva's network, where each request is inspected in a single pass for OWASP Top 10 attacks, API abuse and malicious bots, and volumetric and application-layer DDoS is mitigated before it reaches the origin. The same network provides CDN caching.
The selling point is managed rules: Imperva's research team writes and tests rules in production and pushes them to customers, including day-zero rules for newly disclosed CVEs, so over 90% of customers run in blocking mode. Attack Analytics groups thousands of events into readable incidents, and the platform integrates with SIEMs, webhooks and Terraform.
Pricing is by quote. Smaller teams on AWS can subscribe to FlexProtect Pro through AWS Marketplace, which covers up to 10 sites and bills by monthly traffic volume.
Recent additions listed in Imperva's datasheet include file-upload scanning at the edge, post-quantum TLS on by default, plain-language explanations of blocked requests and an AI assistant for querying security events.
Pricing and plans
checked 28 Sept 2026| Plan | Price | What you get |
|---|---|---|
| Imperva Application Security | Custom | Cloud WAF, DDoS, bot protection, API security, CDN; by quote |
| FlexProtect Pro (AWS Marketplace) | Usage-based | Up to 10 sites, WAF, CDN, SIEM integration, Attack Analytics; billed per GB in 5 tiers via AWS |
What it does
- Managed WAF rules
- Rules written and tested by Imperva's research team, including day-zero CVE protection.
- DDoS protection
- L3, L4 and L7 DDoS mitigation at the edge.
- Bot protection
- Classifies over 1,000 bot types, with AI bots and LLM platforms shown separately.
- Attack Analytics
- Machine learning groups security events into incidents for analysts.
- CDN
- Content delivery on the same network as the WAF.
- Automation
- Terraform integration, webhooks and SIEM export.
Strengths and limitations
Strengths
- Managed rules allow blocking mode from the start.
- WAF, DDoS, bot and API protection share one network and console.
- Protects applications in cloud, on-premises or hybrid setups.
- 24/7 SOC and support.
Limitations
- No published prices; enterprise quotes only on imperva.com.
- No free tier or self-serve plan outside AWS Marketplace.
- The AWS Marketplace plan cannot add features or be upgraded in place.
- Not a DNS host.
Who it suits
Good for
- Enterprises with PCI or regulatory requirements
- Security teams protecting many applications
- Organisations facing frequent bot and DDoS attacks
Look elsewhere if
- Hobby and indie projects
- Teams wanting self-serve signup with published prices
Alternatives to Imperva Cloud WAF
| Tool | From | Free option | Stages |
|---|---|---|---|
| Akamai Ion Enterprise CDN and web acceleration | — | ||
| Amazon CloudFront CDN with bundled WAF and DNS plans | $15/mo | Free tier | |
| Amazon Route 53 Managed DNS and traffic routing | $0.5/mo | ||
| Azure DNS Managed public and private DNS | $0.5/mo | ||
| Azure Front Door CDN, global load balancer and WAF | $35/mo | ||
| CacheFly Throughput-focused CDN | $300/mo | Free tier |
Questions
How much does Imperva Cloud WAF cost?
Imperva does not publish prices; plans are quoted by sales, with a usage-billed FlexProtect Pro plan on AWS Marketplace.
Does Imperva include a CDN?
Yes. The Application Security platform includes CDN on the same network as the WAF.
Who owns Imperva?
Imperva is part of Thales.
Sources read for this page