

Imperva Application Security Platform and Cloudflare Web Application Firewall both compete in the web application security category. Cloudflare has the upper hand due to its ease of use and straightforward deployment.
Features: Imperva offers tailored protection with custom profiling policies and DDoS protection, ideal for industries requiring strict compliance. It excels in both positive and negative traffic analysis. Cloudflare, on the other hand, is known for its simplicity, integrated CDN and DNS management, and real-time traffic analysis, making it an attractive choice for organizations seeking robust security with minimal effort.
Room for Improvement: Imperva users suggest enhanced analytics, more intuitive policy configurations, and better support response times. There are also concerns about pricing complexity and licensing issues. Cloudflare users recommend strengthening WAF/DDoS capabilities, minimizing false positives, and improving support for third-party integrations while acknowledging its ease of setup.
Ease of Deployment and Customer Service: Imperva allows deployment across various environments, such as public and hybrid clouds, with detailed configuration paths for complex needs. Although generally reliable, support response times can vary. Cloudflare is praised for its seamless deployment within public cloud infrastructure, requiring minimal interaction with support. Its overall support experience is often considered more efficient.
Pricing and ROI: Imperva is recognized for its high pricing and advanced protection, often justified by the high ROI in critical sectors with extensive WAF needs. Pricing complexity remains a challenge. Cloudflare offers transparent, affordable pricing, making it appealing for businesses focused on cost control without compromising essential security features. Its competitive pricing and high ROI potential make it attractive for enterprises seeking cost-effective solutions.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
They know how much money they are losing while the system is down, so by increasing the possibility of not having a down website or web application, return on investment can be calculated easily.
Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
I would rate the technical support of Imperva DDoS as ten.
The response is satisfactory, though the gaps in enablement and lab sessions are clear.
My experience with technical support from Imperva Application Security Platform was good when I reached out to them.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
I have not even needed support after deployment, since it has remained stable.
99% of customers are using the cloud version of Imperva DDoS protection, so they just purchase the new license and scale as needed.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
It is also a stable product without much glitch or downtime.
One notable drawback is that, unlike Fortinet, which offers fast track labs and continuous enablement, Imperva Application Security Platform lacks lab access and fast track labs for enablement and product advertising.
The stability of Imperva DDoS is very good, as it seems they have a lot of servers around the world.
Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
The product can improve by having more multitenancy capability, which is currently not available.
To convince my clients, a purely on-prem solution would be ideal since they are financial institutions.
Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform.
Maybe Imperva DDoS could use endpoints to get information about the attacks before they commence from the endpoint level or establish cooperation with endpoint vendors to share this information.
I would rate the pricing of Imperva DDoS as five, where one is very cheap and ten is very expensive.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
All the DNS and everything is routed through Cloudflare, so anybody coming to any of the sites has to go through Cloudflare first, making them the first wall of defense.
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
Imperva Application Security Platform has basic features as part of WAF, its dedicated API protection solution is a strong point.
I have utilized Imperva's Intelligent Traffic Filtering feature. This feature helps me understand how the attack is progressing and what is happening inside the requests to our website.
I see valuable benefits from advanced detection and traffic profiling during DDoS attacks.
| Product | Mindshare (%) |
|---|---|
| Imperva Application Security Platform | 8.1% |
| Cloudflare Web Application Firewall | 5.4% |
| Other | 86.5% |
| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 6 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 84 |
| Midsize Enterprise | 25 |
| Large Enterprise | 62 |
Cloudflare Web Application Firewall's intuitive dashboard enables users to build powerful rules through easy clicks and also provides Terraform integration. Every request to the WAF is inspected against the rule engine and the threat intelligence curated from protecting over 27 Million websites. Suspicious requests can be blocked, challenged or logged as per the needs of the user while legitimate requests are routed to the destination, agnostic of whether it lives on-premise or in the cloud. Analytics and Cloudflare Logs enable visibility into actionable metrics for the user.
Imperva Application Security Platform delivers comprehensive and continuous web threat protection. Renowned for its ease of use, it shields web applications and databases from various cyber threats while integrating seamlessly with cloud and on-premises environments.
Imperva Application Security Platform protects web environments by offering advanced security measures against threats like DDoS attacks, SQL injections, and cross-site scripting. As a robust web application firewall, it provides extensive monitoring and bot management capabilities. The platform integrates content delivery networks for enhanced performance and scalability, while real-time traffic analysis ensures consistent protection. Despite its strengths, improvements can be made in policy management and customization options. Users seek better integration with third-party tools and more competitive pricing models. The inclusion of AI for enhanced analytics is also anticipated.
What are the key features of Imperva Application Security Platform?Imperva Application Security Platform is implemented in industries needing strong database and application protection. Companies use it to enforce geolocation restrictions and manage bots, benefiting sectors like finance and e-commerce where data security and threat monitoring are critical. Its ability to protect and ensure data accessibility makes it integral to business operations prioritizing cyber resilience.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.