OWASP Production Project

OWASP Coraza WAF

Firewall de aplicaciones web de código abierto para APIs y aplicaciones web. Protección de nivel empresarial, 100% compatible con OWASP Core Rule Set.

Built for Modern APIs

High-performance protection for REST, GraphQL, and gRPC endpoints. Coraza handles massive throughput with minimal latency impact.

Enterprise Ready

Hardened for mission-critical infrastructure and high-availability environments.

Legacy Systems

Drop-in replacement for ModSecurity, supporting existing rule sets and workflows.

Universal Deployment

Run as a sidecar, proxy, or library in Go, C++, and WebAssembly.

Why Security Teams Choose Coraza

Engineered for the modern security landscape.

Security First

Rigorous testing and full OWASP CRS compatibility ensure your applications are protected against top threats from day one.

High Performance

Written in Go with an optimized engine, Coraza delivers microsecond-level inspection even at peak traffic loads.

Extensible

A modular plugin architecture allows you to create custom rules, operators, and logging backends tailored to your needs.

Deploy Anywhere

Coraza isn't just a standalone service. Integrate it directly into your infrastructure using our versatile connectors and SDKs.

envoy.yaml

Community Driven

Join the open source security movement.

OWASP GitHub Open Source