Technical FAQ
The questions a security lead actually asks.
Twelve answers covering the crawler, the blocklist methodology, alert contents, false positives, performance, compliance, and integration.
Most malware on legitimate websites is delivered through embedded third-party JavaScript — a compromised tag manager, a hijacked CDN script, an outdated plugin, a backdoored npm dependency loaded over the wire. Traditional WAFs only see traffic hitting your origin server, so they are blind to anything injected client-side. We render your site as a real visitor every five minutes and watch what it actually loads.