Intelligenceat theEDGE

MTTM < 15m

Turn Vulnerabilities Into Enforced Edge Protection

Zedgenta connects vulnerability intelligence to WAF enforcement: it identifies externally reachable vulnerabilities, probes your own edge to find the WAF bypasses and edge bypasses that leave them exposed, maps existing coverage, and governs the controls required to protect them.

Integrates with Orca, Wiz, Jira, and other security systems to identify coverage gaps and generate and validate new WAF rules.

Cloudflare · AWS WAF · Akamai · Imperva · F5One vendor-neutral layer for vulnerability-to-WAF coverage and governance.

Book a demoExplore the operator queue

Event-driven

A finding arrives, a mitigation is ready

Nobody presses a button. A finding lands from whatever you already run — pushed the moment it is raised, or polled — and the chain has it measured before anyone opens the console.

Sources in

30+

OrcaWizJiraHackerOneBugcrowdIntigritiBurpNucleiQualysSnykNVDCISA KEV+18 more

native connector · everything else posts to /api/ingest

Zedgenta attack variants WAF bypasses encoding · obfuscation structural tricks Your WAF

Sources Zedgenta attack variants & WAF bypasses fired at your WAF what comes out

admitclassifyreachproberesolveauthorre-probe

One admission path behind every entrance — a pushed finding and a polled one are decided identically.

Enforced at the edge

  • Ownership verifiednothing probed outside a grant you signed
  • Reachability establishedinternet-facing, and which edge is really in front
  • WAF rule enabled or authoredCloudflare, AWS WAF, Akamai, Imperva, F5 — you name it
  • Re-proved against the edgeonly a re-measured close is called covered

The operator's queue · interactive

FindingStateConfidence

Sample tenant. Zedgenta proposes; your team reviews and merges every change.

BYOC

Bring your own cloud

Evidence of record — probe records, payloads and raw edge events — is written to a bucket you own, under your KMS key, before a verdict is returned. Our writer role is explicitly denied read; verify it in your console, revoke it without asking us. One CloudFormation stack or Terraform module, one configuration value.

BYO LLM

Bring your own AI infrastructure

The investigation and rule-design agents reach the same pinned, certified model through the infrastructure you already govern — your gateway, Amazon Bedrock in your account, or your provider key — under your keys, your quotas and your logging. Sub-processors and residency are stated per route, for your DPA.

Any source in

Orca, Wiz, Jira, NVD and CISA KEV. Deduplicated and enriched into a single record.

Any WAF out

Cloudflare, AWS WAF, Akamai, Imperva and F5. One rule model, compiled to each vendor dialect.

Never in the path

Read-only credentials, paired-control probing, pull-request delivery. Rules ship in log mode; promotion to block is yours.

WAF bypasses

The rule is there. Does it hold?

Every finding is probed on five axes against the WAF in front of it: the canonical payload, encoding the rule should have normalized, the payload moved to another location, obfuscation by comments, case and whitespace, and structural tricks such as chunking, parameter pollution and content type. An axis that gets through is a bypass, named, with the paired control that proves it.

Edge bypasses

Which layer acted, if any?

A request can reach the origin without meeting the WAF at all: an origin exposed beside the CDN, a second layer that never sees the path, a managed ruleset in count mode. Zedgenta reads your edge's own events for every probe and names the layer that acted and on what basis; when nothing acted, it says so rather than crediting a rule that was never in the way.

Closed, and re-proved

A rule for the bypass, measured again

For a named bypass Zedgenta compiles a vendor-native rule that closes that axis, ships it in log mode with your consent, waits for it to be in force, and probes again. Only a re-measured close is called covered. A rule that would also stop legitimate traffic is not proposed; the finding is routed to a human with the evidence.

Plans · every plan is a custom quote

Startup · hosted · Zedgenta's AI route

Startup

Nothing to install. One source, one edge, read-only. Evidence held for the run; the verdict and its attestation are the record. Model calls on Zedgenta's account, under our DPA.

custom quote

Business · hosted or BYOC evidence · your provider key

Business

Evidence in your bucket, or hosted — your call. BYO LLM on an account you own: Anthropic, Google or OpenRouter, upstream pinned. Several edges, several sources, Terraform PRs into your repo.

custom quote

Enterprise · BYOC evidence · BYO LLM in your network

Enterprise

Your gateway or Bedrock in your AWS account, residency stated per route. Lifecycle you own, data-handling statement for your DPA. Every edge vendor, every source, a named human on every hand-off.

custom quote

Validated protection at the edge,with evidence.

Book a demo