| Core protection (managed by Cloudflare) |
| Cloudflare Managed RulesetCVE-driven rules, emergency zero-day rules |
✓ |
✓ |
✓ |
| OWASP Core RulesetParanoia levels + anomaly scoring |
✓ |
✓ |
✓ |
| Per-rule sensitivity + log-only modeTune out false positives before you block |
✓ |
✓ |
✓ |
| Rate limitingBasic on lower tiers, Advanced on Ent |
Basic |
Basic |
✓ |
| Your own logic |
| Custom rules (Wirefilter expressions)Match URI, headers, body, geo, IP, ASN, JA3/JA4 |
5 |
20 |
Unlimited |
| Skip / bypass rulesAllowlist admin paths, monitoring IPs, health checks |
✓ |
✓ |
✓ |
| Terraform + full APIManage rules as code |
✓ |
✓ |
✓ |
| Bot score as a rule signalGranular 1–99 score needs Bot Management |
SBFM |
SBFM |
✓ |
| Request-body inspectionDefault 128KB; Enterprise can raise the limit |
128KB |
128KB |
✓ |
| Advanced detections (Enterprise add-ons) |
| Exposed / Leaked Credentials CheckClient-side hashed; password never sent readable |
✓ |
✓ |
✓ |
| Sensitive Data DetectionFlag PII / secrets in responses |
✓ |
✓ |
✓ |
| Account Takeover protectionCredential-stuffing / brute-force signals |
✓ |
✓ |
✓ |
| Firewall for AIGuardrails for LLM-backed endpoints |
✓ |
✓ |
✓ |
| API Shield (on top of WAF)Schema validation, introspection + query-depth abuse |
✓ |
✓ |
✓ |
| Operations + compliance |
| Security Analytics + EventsSee every decision, investigate in ~30 seconds |
✓ |
✓ |
✓ |
| Logpush to your SIEMSplunk, Datadog, Sumo, etc. |
✓ |
✓ |
✓ |
| PCI DSS 6.6 app-layer firewallSatisfies the firewall option; AoC in dashboard |
✓ |
✓ |
✓ |
| Emergency zero-day rules, network-wideLog4Shell rule was live in under 24h |
✓ |
✓ |
✓ |