Web & API Security WAF, headers, and domain authentication controls
You built the site. FEDLIN handles the security layer: WAF, headers, DMARC, and domain authentication controls implemented at the edge. Packaged per client, delivered as a scoped engagement, with evidence artifacts ready for compliance review.
An attack at this layer puts your client's customers at risk before it reaches their infrastructure. WAF and OWASP Top 10 coverage, DMARC/SPF/DKIM enforcement, TLS hardening, added to any stack without touching the underlying build. Controls map to SOC 2 CC6.1/CC6.6 and NIST 800-53 SC/SI.
Engineered by Jeremiah Coakley, Principal Security Architect
What's your priority?
Engagements
Two ways to secure the boundary
Every engagement secures the same thing: the domain and edge boundary where traffic, email, and users meet the internet. The difference is who owns it going forward. FEDLIN either runs that boundary for you as a managed subscription, or hardens and validates it inside your own tenant as a one-time engagement.
Managed Edge
Ongoing · we own the boundaryFEDLIN runs your DNS and edge inside a FEDLIN-managed Cloudflare environment; in-scope updates are included and tracked through a formal change workflow with an audit trail. A one-time onboarding brings the boundary under management before the subscription begins. The tier scales with the number of domains and your posture, confirmed on a scoping call.
Foundation
DNS and edge ownership, handled correctly.
The baseline
- →DNS and edge boundary management
- →TLS and security-headers baseline
- →Email-trust sanity check (SPF/DKIM/DMARC presence)
- →Validation after every change
- →Formal change workflow with an audit trail
Best for: Small teams that want the boundary owned and maintained.
Protection
Most chosenActive perimeter defense on top of the baseline.
Everything in Foundation, plus
- →WAF baseline configuration
- →Bot and abuse mitigation
- →Production-safe validation emphasis
Best for: Revenue-generating sites and applications.
Assurance
Governance and evidence for teams under review.
Everything in Protection, plus
- →Quarterly governance review: drift check against baseline
- →Risk memo, vendor-review and board-ready
- →Prioritized remediation action list
- →One remediation batch per quarter
Best for: VC-backed teams, GovCon contractors, and vendor-review pressure.
One-Time Hardening
Your tenant · we harden and hand backFor teams that cannot delegate DNS and edge ownership, FEDLIN hardens and validates the boundary inside your own Cloudflare tenant as a defined engagement with clean handoff. Pick the controls you need; each is scoped on a call and can stand alone or combine.
-
Cloudflare Full Setup
- →DNS review and cleanup
- →TLS configuration
- →Security headers deployment
- →WAF baseline configuration
- →Basic validation and documentation
- →Additional domains and environments scoped per engagement
-
Email Domain Trust Baseline
Per domain- →SPF/DKIM validation and correction
- →DMARC deployment
- →Sender alignment validation
- →Documentation and rollout guidance
-
Email Domain Trust: Enforcement Upgrade
Add-on to Email Domain Trust Baseline- →Quarantine/reject staging
- →Alignment refinement
- →Rollout monitoring and tuning
-
Application Security Policy Engineering
Per app- →Security header optimization
- →TLS posture refinement
- →CSP report-only deployment
- →Validation and rollout guidance
- →Optional: CSP Enforcement Upgrade
- →Optional: Terraform Self-Healing Configuration
-
WAF & Bot Mitigation
- →WAF configuration and ruleset tuning
- →Bot/abuse mitigation controls
- →Rate limiting and advanced security rules
- →Verification and documentation
- →High-abuse environments scoped separately
-
WAF Tuning Retainer
Ongoing · add-on to WAF & Bot Mitigation- →Ongoing WAF rule tuning and adjustments
- →Threat pattern review and mitigation updates
- →Monthly review cadence
-
Quarterly Governance
- →Configuration drift review
- →Risk memo
- →Minor remediation batch
- →Prioritized remediation action list
How it's scoped
The size of the work tracks a few things: the number of domains and hostnames (WAF, headers, and DMARC/SPF/DKIM all scale here), the number of API endpoints, your current posture, and how complex the stack is. We confirm scope on a short call and give you a fixed number before anything starts.
Scope Your BoundaryEdge controls
What Gets Deployed
The controls that go live on the boundary, whether run for you as a managed subscription or deployed once in your own tenant. Each comes with validation and an evidence artifact produced at implementation time.
ML-KEM Hybrid TLS
X25519+ML-KEM-768 negotiated at the Cloudflare edge: post-quantum key exchange verified and documentedWAF Configuration
Ruleset tuning, bot mitigation, and rate limiting: OWASP Top 10 coverage at the perimeter before traffic reaches originSecurity Headers & CSP
HSTS, CSP, X-Frame-Options, and Permissions-Policy: browser-layer controls enforced and validatedDMARC / SPF / DKIM
Domain authentication controls deployed to enforcement: spoofing prevention with reporting configured and auditableDNSSEC & CAA Records
Cryptographic DNS integrity and certificate authority restrictions: closes the certificate misissuance surfaceEvidence Artifacts
Every control attributed to the framework requirements it satisfies, structured for GRC platform ingestion at implementation timeSecurity headers & CSP
We Implement CSP So You Don't Have To
Content Security Policy is one of the strongest defenses against XSS, but a bad CSP can break scripts, styles, and third-party widgets overnight. We deploy CSP, HSTS, SRI, and Permissions-Policy as code, target an A+ score, and keep the policy working as your site changes.
Nonces, Not Wildcards
We use CSP nonces so only your intended scripts and styles run. The browser gets a unique nonce per page load; we inject it into the policy and into each allowed tag. No 'unsafe-inline' backdoors, no "report-only" forever: real protection without breaking your site.
Doing this yourself usually means either weakening CSP (and losing the security benefit) or chasing down every inline script and third-party snippet. We've done it across many frameworks and CDNs; we know where the traps are.
Rapid Fix When Things Change
You add a new integration, a new script, or a CMS update, and suddenly something breaks. If you rolled out CSP yourself, you're digging through docs and console errors. With us, you send one message: we adjust the policy, add the right nonce or hash, and get you back online quickly.
We treat CSP as ongoing configuration, not a one-and-done header. When your site evolves, we evolve the policy so security stays strong and nothing breaks.
Why have us do it instead of doing it yourself?
- • Time. Getting CSP right across frameworks, CDNs, and third-party widgets takes trial and error. We've already done that work on similar stacks.
- • Breakage risk. One wrong directive can block critical scripts or styles in production. We implement in a way that minimizes risk and we're standing by to fix if something slips through.
- • Ongoing changes. Your site will change. New tools, new deployments, new content. We keep CSP aligned so you don't have to become a CSP expert, and so you're not left holding the bag when a future change breaks something.
Security Headers Checker
See what enterprise security teams see when they evaluate your site. Enter your URL below.
Unable to scan
-
Domain Security
Your domain trust score reflects DNS, TLS, and email authentication. We help you fix gaps in DMARC, SPF, DKIM, DNSSEC, CAA, and TLS so your domain can't be spoofed and passes security reviews.
Check Your Domain Trust Score
Full DNS, TLS, and email security audit: DMARC, SPF, DKIM, DNSSEC, TLS version, and more
Scanning domain trust...
Scan Failed
DMARC, SPF & DKIM: complementary control for your domain
We configure email authentication so your domain can't be spoofed: phishing and brand impersonation drop, deliverability and audit readiness go up.
Why email authentication matters
Without DMARC, SPF, and DKIM, anyone can send emails that appear to come from your domain. Attackers exploit this for phishing, business email compromise, and brand impersonation, damaging your reputation and putting your customers at risk.
What's included
SPF Configuration
Sender Policy Framework records that define which mail servers are authorized to send email for your domain.
DKIM Implementation
DomainKeys Identified Mail signatures that cryptographically verify email authenticity and prevent tampering.
DMARC Policy Rollout
Gradual enforcement from monitoring (p=none) to quarantine to full rejection of unauthorized emails.
DNS Record Validation
Comprehensive validation and optimization of existing DNS records for maximum deliverability.
Automated Key Rotation
DKIM key rotation automation to maintain security without manual intervention.
Audit-Ready Documentation
Configuration records and evidence artifacts ready for security reviews, vendor questionnaires, or compliance audits.
DMARC policy rollout
Gradual enforcement prevents email delivery disruption
Monitor (p=none)
2-4 weeksCollect data on email flows without affecting delivery. Identify legitimate senders and potential issues.
Quarantine (p=quarantine)
2-4 weeksSuspicious emails go to spam. Legitimate email continues normally. Fine-tune based on reports.
Reject (p=reject)
OngoingFull enforcement. Unauthorized emails are rejected. Your domain is fully protected.
Common use cases
Supported DNS providers
Fits compliance programs
Deployable independently or alongside compliance work.
Edge and domain controls are often the fastest path to closing a specific security gap before a deal or audit window. The controls map to SOC 2 and NIST 800-53 requirements with evidence built in.
Why This Matters
Edge and domain controls reduce your attack surface before anything reaches your website or application. WAF blocks OWASP Top 10 threats at the perimeter. Security headers close browser-level attack vectors. DMARC prevents domain spoofing and phishing targeting your customers. A DDoS, a domain compromise, or an unprotected web endpoint are customer-facing failures: service disruptions and breaches that affect the people depending on your product. For companies on a compliance journey, these controls map to SOC 2 CC6.1/CC6.6 and NIST 800-53 SC and SI families.
Common Attacks We Block
These are active exploits that affect thousands of sites daily. Here's what each protection stops:
Content-Security-Policy → XSS Attacks Cross-Site Scripting lets attackers inject malicious scripts into your pages. Once in, they can steal session cookies, redirect users to phishing sites, or silently exfiltrate customer data. CSP tells browsers exactly which scripts are allowed to run; anything else gets blocked.
X-Frame-Options → Clickjacking Attackers embed your site invisibly inside their malicious page, tricking users into clicking hidden buttons: "Transfer Funds," "Delete Account," "Approve Access." Without frame protection, your authenticated users can be hijacked without knowing it.
Strict-Transport-Security → Protocol Downgrade Even with SSL, users typing your URL without "https://" are vulnerable during that first request. On coffee shop WiFi, that split-second is enough to intercept credentials. HSTS tells browsers to always use HTTPS: no redirect window, no interception opportunity.
X-Content-Type-Options → MIME Sniffing Browsers try to "help" by guessing file types, but that lets attackers disguise scripts as images or text files. Upload a .txt that's actually JavaScript, and some browsers execute it. This header forces browsers to respect declared types.
Cloudflare WAF → SQL Injection & Bot Attacks Injection attacks target your database directly: extracting user data, modifying records, or dropping tables entirely. The WAF analyzes every request against OWASP Top 10 attack patterns, blocking malicious payloads before they reach your application.
Cloudflare DDoS → Denial of Service DDoS attacks overwhelm your servers with traffic, taking your website or application offline, sometimes for hours or days, with every minute of downtime affecting customers who depend on your service. Cloudflare's 300+ Tbps network absorbs attacks at the edge, so malicious traffic never reaches your origin.
Use the scanner above to see which of these protections your site currently has, and which gaps remain.
Scan Your Site NowWhat's Included
Cloudflare Proxy Setup
Full DNS migration and proxy configuration to route traffic through Cloudflare's edge network.
WAF Configuration
OWASP Top 10 managed ruleset, custom rules for your website or application, and false positive tuning.
Security Headers
HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy configured for A+ ratings.
Content Security Policy
Custom CSP implementation that works with your website or application's third-party integrations and inline scripts.
Bot Protection
Challenge suspicious traffic, block known bad bots, protect against scraping and credential stuffing.
Rate Limiting
Intelligent rate limiting rules to prevent abuse without affecting legitimate users.
Comprehensive SSL/TLS Hardening
Certificate validation, protocol enforcement (TLS 1.3 preferred, 1.2 minimum), cipher suite optimization, and mixed content detection for web applications.
DNS Security (DNSSEC, CAA)
DNSSEC configuration prevents DNS spoofing. CAA records control certificate issuance. Required for government contracts and enterprise security.
DDoS Protection
Cloudflare's network absorbs attacks before they reach your origin servers.
Frequently Asked Questions
Common questions about web application security
What does FEDLIN's edge security implementation cover?
Cloudflare WAF configuration and ruleset tuning, TLS hardening, security headers, DMARC/SPF/DKIM deployment, DNSSEC, CAA records, DDoS protection, and CSP engineering. Controls are deployed via an automated configuration system, brought live with validation and evidence artifacts produced as part of the implementation.
What is post-quantum-aware key exchange and why does it matter for web infrastructure?
Cloudflare negotiates ML-KEM hybrid TLS (X25519+ML-KEM-768) at the edge: a key exchange mechanism that remains secure against quantum-era cryptanalysis. FEDLIN verifies correct negotiation, documents the cryptographic posture, and produces evidence artifacts for engagements where long-term cryptographic validity is an architectural requirement.
What's the relationship between NIST CSF and the controls implemented here?
NIST CSF's Protect function (specifically PR.AC and PR.DS) maps directly to edge and domain controls. NIST 800-53 SC and SI control families are what get implemented at the infrastructure layer. CSF gives the posture language; the deployed controls produce the evidence.
Does edge security produce GRC-ready evidence?
Every control implemented produces structured artifacts: WAF configuration documentation, TLS validation records, DMARC enforcement reports, header scan results, formatted for ingestion into Vanta or equivalent GRC platforms. Controls are attributed to the specific framework requirements they satisfy at implementation time.
Does edge security stand alone or does it require a broader engagement?
Edge Security stands alone and is also available as part of a broader engagement sequence. Scope is confirmed on the initial call based on your current infrastructure and what the architecture requires.
What tech stacks do you support?
Any stack: Next.js, React, Astro, Vercel, AWS, Azure, GCP, WordPress, Shopify, and others. Whether it's a marketing site, a customer-facing web app, or internal tooling, we proxy through Cloudflare at the DNS level; the underlying stack is irrelevant to most of this work. Edge security controls operate independently of how the site or application is built.
What's the difference between A and A+ ratings on Mozilla Observatory?
An A+ on Mozilla Observatory requires all critical security headers configured at their strongest settings: HSTS with includeSubDomains and preload, a strict Content Security Policy, correct CORS headers, and Permissions-Policy. An A indicates most headers are present but some are missing or misconfigured. Enterprise security questionnaires and some compliance frameworks explicitly reference A+ as a benchmark, particularly when evaluating vendor web security posture.
Not sure where to start?
Start with a scoping call: we map your exposure and scope protection to what's actually at risk.
From the Blog
From the field notes

SPIFFE/SPIRE on OpenShift: Building the Workload Identity Plane Your Zero-Trust Model Is Missing
After locking down human and device access, pod-to-pod communication was still trust-the-network. SPIFFE/SPIRE closes that gap. Short-lived cryptographic identities, attested per-workload, chained under your existing Root CA.

How Araptus' PNPM Security Scanner Caught Malware in My Dependencies
Self-hosting Araptus' PNPM Supply Chain Security Scanner led to discovering protest-ware hiding in transitive dependencies—before it reached production.

Your Security Headers Are Probably Failing. Here's How to Check (Free).
Why your security baseline stops enterprise deals—and how to fix it.
Often scoped together
Add related services to your scope
GRC Engineering
Gap assessment and control gap remediation that maps edge security findings to a structured program: IAM, Kubernetes hardening, and continuous compliance evidence.
Penetration Testing
Adversarially validate the WAF, header policies, and email controls after they are deployed.
What do you need hardened?
Pick the area: we'll scope the engagement from there.