Skip to content
Orca WAAP
Products
Web Security

Orca WAAP

Protect enterprise web applications and APIs from cyber attacks.

For you whenWhen you have websites, apps or APIs that need proactive attack protection.

Self-host
Deploy
4
Features
tetra://orca-waap
UI preview
Key features

Key features

  • 01Web application firewall (WAF) against OWASP/CVE
  • 02DDoS protection
  • 03Bot mitigation & API protection
  • 04Self-hosted on your own infrastructure (reverse proxy)
Interface

Orca WAAP interface

A look at the actual screens.

preview
Coming soon
Clips

Orca WAAP in action

Short clips, one per key function.

Coming soon
Coming soon
Coming soon
Deep dive

More about Orca WAAP

Public web apps and APIs are a constant target

Anything you expose to the internet gets probed around the clock: OWASP/CVE exploits, automated bot scans, DDoS floods, abuse of API endpoints. Orca WAAP sits in front of your application and filters that traffic before it reaches your servers.

It's built for teams running real web apps or APIs in production — ecommerce, service portals, internal tools, company sites — and especially for the ones who'd rather own their defenses than hand them to an outside service.

A web application firewall, and the rest of WAAP

WAAP goes beyond a plain WAF. Alongside application-layer filtering, Orca folds DDoS protection, bot challenges, and API protection into one product.

  • WAF against OWASP/CVE — a built-in rule set targeting current web vulnerabilities, which your admin tunes to each application.
  • DDoS protection — mitigates denial-of-service attacks.
  • Bot challenge — challenges and blocks malicious bots and automated scanners.
  • API security — controls and protects your API endpoints.

Orca ships with its own reverse proxy, so there's nothing to stitch together. Put it in front of your app, point the upstream at the service you want to protect, and you're running — no changes to your application code.

Self-hosted: your data stays home

A cloud WAF routes your traffic through the provider's infrastructure. Orca is self-hosted on your own, so every request is inspected on-site and nothing passes through a third party. For organizations that care about data sovereignty or have to keep data in-country, that's the whole point: application-layer protection without giving up control of your traffic.

Free to start, updated to stay safe

Orca is freeware. Download the binary and documentation and run it with the full WAAP feature set and the built-in rules; your admin configures and updates rules manually as needed.

When you'd rather keep those rules current with new CVEs automatically, there's a support pack at 1,000,000đ/month, bought in three-month blocks. The contents are still being finalized, but the plan covers automatic rule sync (managed threat intelligence) against fresh OWASP/CVE issues, plus hands-on support from the Tetra team — questions, rule tuning, fewer false positives. Like any security tool, Orca reduces common attacks rather than promising perfect safety.

Try Orca

Orca WAAP is looking for early design partners to work with at this stage. Download it for free and evaluate it on your own infrastructure; when you want automatic rule updates and a team behind you, get in touch about the support pack.

// get started

Want Orca WAAP for your team?

Book a consultation and we'll demo and advise around your workflows.