
Orca WAAP
Protect enterprise web applications and APIs from cyber attacks.
For you whenWhen you have websites, apps or APIs that need proactive attack protection.
Key features
- 01Web application firewall (WAF) against OWASP/CVE
- 02DDoS protection
- 03Bot mitigation & API protection
- 04Self-hosted on your own infrastructure (reverse proxy)
Orca WAAP interface
A look at the actual screens.
Orca WAAP in action
Short clips, one per key function.
More about Orca WAAP
Public web apps and APIs are a constant target
Anything you expose to the internet gets probed around the clock: OWASP/CVE exploits, automated bot scans, DDoS floods, abuse of API endpoints. Orca WAAP sits in front of your application and filters that traffic before it reaches your servers.
It's built for teams running real web apps or APIs in production — ecommerce, service portals, internal tools, company sites — and especially for the ones who'd rather own their defenses than hand them to an outside service.
A web application firewall, and the rest of WAAP
WAAP goes beyond a plain WAF. Alongside application-layer filtering, Orca folds DDoS protection, bot challenges, and API protection into one product.
- WAF against OWASP/CVE — a built-in rule set targeting current web vulnerabilities, which your admin tunes to each application.
- DDoS protection — mitigates denial-of-service attacks.
- Bot challenge — challenges and blocks malicious bots and automated scanners.
- API security — controls and protects your API endpoints.
Orca ships with its own reverse proxy, so there's nothing to stitch together. Put it in front of your app, point the upstream at the service you want to protect, and you're running — no changes to your application code.
Self-hosted: your data stays home
A cloud WAF routes your traffic through the provider's infrastructure. Orca is self-hosted on your own, so every request is inspected on-site and nothing passes through a third party. For organizations that care about data sovereignty or have to keep data in-country, that's the whole point: application-layer protection without giving up control of your traffic.
Free to start, updated to stay safe
Orca is freeware. Download the binary and documentation and run it with the full WAAP feature set and the built-in rules; your admin configures and updates rules manually as needed.
When you'd rather keep those rules current with new CVEs automatically, there's a support pack at 1,000,000đ/month, bought in three-month blocks. The contents are still being finalized, but the plan covers automatic rule sync (managed threat intelligence) against fresh OWASP/CVE issues, plus hands-on support from the Tetra team — questions, rule tuning, fewer false positives. Like any security tool, Orca reduces common attacks rather than promising perfect safety.
Try Orca
Orca WAAP is looking for early design partners to work with at this stage. Download it for free and evaluate it on your own infrastructure; when you want automatic rule updates and a team behind you, get in touch about the support pack.
Want Orca WAAP for your team?
Book a consultation and we'll demo and advise around your workflows.