You keep your WAF exactly as it is and add cside as a single first-party script, or the agentless Scan Method, with no DNS change and no traffic routing. Your WAF keeps inspecting inbound requests to your servers; cside analyses the third-party JavaScript that executes in your users' browsers, the layer a WAF cannot see. There is no rule to reconcile and no functional overlap, so deployment takes minutes rather than the weeks a WAF change takes, and you gain the client-side coverage a WAF was never designed to provide.
Can cside work alongside my existing WAF without conflicts?
We monitor an entirely different dimension of the application stack; hence, there is no interference.
How does cside solve the client-side blind spot that WAFs can't address?
Cside analyses every third-party script on our side before it runs, making it easy to stop attacks by analyzing JavaScript content asynchronously and hashing a list of bad scripts, preventing them from being loaded again.
Why is the browser environment invisible to WAF monitoring?
A WAF (Web Application Firewall) operates at the perimeter, analyzing traffic as it crosses between external networks and your internal network towards your web servers.
Can a WAF protect against supply chain attacks on third-party JavaScript libraries?
WAFs cannot protect against client-side supply chain attacks because they don't intercept the fetch to the 3rd party endpoint and therefore have no visibility into the JavaScript files from the 3rd party sources.