Private beta · Guided demos available

Most WAFs guess.
htm8 knows.

htm8 combines traditional WAF protection with application intelligence derived from your actual site responses — reducing false positives without compromising security.

For SaaS applications, APIs, portals, and customer-facing web apps.
The htm8 difference

Smarter than passive traffic learning.

Most security tools learn by watching incoming requests and hoping they're representative. htm8 goes further — it learns what legitimate browser behavior should look like by rendering your application's actual responses through a standards-compliant browser engine.

The result: protection grounded in what your site really is, not what attackers want it to look like.

Traditional tools
Learn from incoming traffic
React to known attack patterns
Manual tuning required
Noise, false positives, alert fatigue
htm8
Learns from your application's responses
Understands expected browser behavior
Adaptive, app-aware detection
Clear, actionable, contextual events
How it works

Protection in depth. Without the noise.

htm8 protects your application with three complementary layers working together.

Layer 1 · WAF

Out-of-the-box protection

Rules-based protection against known attack patterns — SQL injection, XSS, protocol abuse, and OWASP-style threats. You're protected from day one.

Layer 2 · ArbLayer

The intelligence layer

ArbLayer analyzes your application's actual responses to build a model of what legitimate browser requests look like — forms, routes, scripts, cookies, expected navigation.

Layer 3 · WPE

The enforcement engine

WPE sits in the traffic path and applies allow, detect, or block decisions before requests reach your origin — with full visibility into every decision.

Why teams switch

Security that works with your app, not against it.

Traditional WAFs create friction. Legitimate users get blocked. Security teams drown in alerts. Every exception weakens protection. htm8 changes the equation.

01
False positives hurt your business.
htm8 knows what your app's real traffic looks like, so legitimate requests are rarely mistaken for attacks.
02
Manual tuning drains your team.
htm8 adapts as your application evolves — fewer one-off exclusions, less firefighting.
03
Static rules can't keep up with modern apps.
htm8's response-derived intelligence stays current with your forms, endpoints, and scripts.
Start safe. Begin in observation mode — detect and log without blocking. Move to enforcement when you're ready.
Talk to us
Built for trust

Start in observation. Move to enforcement when ready.

htm8 is designed to avoid "turn it on and hope." You control the pace.

Observe
Learn
Tune
Enforce
Optimize

No agents. No SDKs. No code changes. Deploy in front of your existing application and get immediate visibility.

Questions, answered

What you're probably wondering.

How is htm8 different from a traditional WAF?
A WAF blocks known attack patterns. htm8 does that and learns what legitimate traffic should look like for your specific application — from your application's own responses. That means fewer false positives without weakening security.
Is this just another anomaly detection tool?
No. Most anomaly detection learns from historical traffic — which can be polluted by attacks. htm8 derives expected browser behavior from your application's responses, using a standards-compliant rendering engine. It's a fundamentally stronger baseline.
How long does deployment take?
Minutes. Place htm8 in front of your application, verify traffic, and start with detection mode. No code changes required.
Will this break my application?
No. You start in observation mode — detect and log without blocking. Only move to enforcement when you're confident, with full visibility into every decision.
Is htm8 ready for production?
We're in private beta with guided onboarding. That means you get direct access to our team, hands-on setup support, and the ability to shape the product.
How do I get access?
Request a demo below. We'll walk you through the platform, your specific use case, and next steps for beta access.
Private beta

Ready to see what htm8 catches?

Request a guided demo. No sales scripts — just a technical conversation about your application's attack surface.