Features Architecture Enterprise Pricing Start free
Self-learning WAF · at the edge

Block attacks.
Learn normal.
See every decision.

StarkGate is a self-learning Web Application Firewall and reverse proxy at the edge of your sites. It terminates TLS, inspects every request in under a millisecond, and — with AI-assisted rules — flags every anomaly while it learns what your normal traffic looks like.

Negative + positive security · AI-assisted rules · full traffic visibility · high availability

GET /index.php ALLOWED
203.0.113.9·DE·decision 0.21ms
TLS TLS termination · SNI
RULES Negative security
LEARNED Learned allowlist
POLICY Traffic policy
→ origin allowed observed blocked

every request · four layers · one explainable decision

<1ms WAF decision RE2 linear-time matching Shadow → Enforce on every layer Multi-tenant one console
The big idea

Three layers of protection, one request pipeline.

StarkGate combines three complementary models in a single pipeline. Every layer can run in Shadow before you flip it to Enforce.

rules

Negative security

A curated catalog of attack-detection rules — SQLi, XSS, path traversal, command injection, SSRF, scanners and sensitive-file probes. Always on, instantly tunable.

per-rule · Shadow or Enforce
learning

Positive security

StarkGate watches your legitimate traffic and gradually learns the URLs and parameters your site actually uses — then enforces that allowlist, catching novel attacks no signature knows.

Basic · Balanced · Strict
global

Traffic policy

Ordered, first-match rules — per-domain or account-wide — on IP, country and path that route, rate-limit, switch backends or block.

F5-style · first match wins
Safe by design

Measure before you block.

Every layer runs in Shadow first — it logs what would have been blocked, but never blocks — before you flip it to Enforce. We treat a false positive as a product failure.

  • Deploy in parallel on a dedicated IP — zero risk to live traffic.
  • Promote only the rules and allowlists that look clean in the log.
  • Fail-open by design — an empty model never blocks, so it can't take a site down.
rule · sqli-union-select
3 requests would block · 0 blocked

flip to Enforce — same traffic, now actually blocked

AI rule-assist

AI proposes rules from your real traffic.

From a sanitized summary of your recent suspicious traffic — structural signal only, never raw payloads. Every proposal is a candidate you review; approving adds it in Shadow first.

AI proposed rule
id scanner-env-probe
match path ends-with /.env
action block (403, logged)
safety RE2-safe ✓ · starts in Shadow

Choose your provider

Run the AI in the cloud — or fully local. Nothing leaves your network.

Anthropic cloud
Groq cloud
Ollama local · private

Automatic technology detection fingerprints your stack — WordPress, PHP, nginx, IIS — and suggests the matching rule packs.

Who it's for

Built for the people who run the edge.

Hosting providers & agencies

Protect many customer domains from one control plane — multi-tenant, multi-domain.

WordPress & CMS operators

Real WAF coverage without touching the app — start from a ready template.

Teams who fear false positives

Every protection can run observe-only first — measure before you block.

Ops teams that value clarity

Every decision the engine made is searchable and replayable — no black box.

Compare

StarkGate next to Cloudflare and F5 BIG-IP.

The edge, the data and the AI stay on your own infrastructure — and every decision stays explainable and replayable.

Capability StarkGate Cloudflare WAF F5 BIG-IP
Deployment Self-hosted · native Cloud Self-hosted · appliance
Traffic & data stay On your infrastructure On the provider's network On your infrastructure
Negative security (signatures)
Self-learning positive security URL + parameters ~partial ~manual policy
Shadow on every layer, then Enforce ~partial ~partial
Decision Replay — re-run any request
Private, on-prem AI rule-assist Ollama — nothing leaves
Config sync + daily DR backups ~vendor-managed ~HA; backups vary
Starting point Free tier (soon) Usage / subscription Enterprise license

Comparison reflects StarkGate's positioning. Cloudflare and F5 BIG-IP are trademarks of their respective owners; their capabilities vary by plan and configuration.

How it rolls out

Deploy in parallel. Observe. Tune. Go live — reversibly.