Scores at a glance
Cells are color-coded by score. Hover the column header for the dimension definition. ? means we have not run the test yet — usually because the vendor gates access behind enterprise contracts. Methodology and receipt paths are below the table.
| Vendor | D1Tunnel compat | D2API control | D3L3/L4 API | D4Rate limit | D5Origin conceal | D6gRPC inspect |
|---|---|---|---|---|---|---|
| CloudflareCDN + WAF + Tunnel | 2native (Tunnel) | 3API v4 full parity | ?Magic Transit gated | 2sliding · per-IP+path strong sync · ~10 rpm |
2Tunnel: 2 · CDN: 1 | 0Free tier: 403 at proto no method inspection |
| AWSWAF + CloudFront + Shield Advanced | ?undocumented | 3wafv2 full parity | 2Shield Advanced API | 1sliding · per-IP eventual sync · ~100 rpm |
1CloudFront proxy | 0464/502 · WAF Count did not fire on gRPC |
| AzureFront Door + Azure DDoS | ?untested | 2ARM API, some lag | ?policy depth unverified | 0fixed · per-IP eventual · ~200 rpm |
?Private Link untested | 0403 block at proto level |
| AkamaiKona / Bot Manager / Prolexic | ? | ?OPEN API, scope TBD | ?Prolexic gated | ? | ?Site Shield TBD | ? |
| ImpervaCloud WAF / DDoS | ? | ? | ? | ? | ? | ?pending trial #17 |
| RadwareCloud WAF / Cloud DDoS / DefensePro | ? | ? | ?DefensePro CLI/SNMP | ? | ? | ? |
| Fastly+ Next-Gen WAF (Signal Sciences) | ? | ?VCL + Fastly API | ?n/a (no L3/L4 product) | ? | ? | ? |
| F5 Distributed CloudF5XC + Shape | ?Private Connectivity | ? | ?n/a | ? | ? | ? |
| Tailscale Funnelreference baseline | 2 | n/a | n/a | n/a | 2 | n/a |
| ngrokreference baseline | 2 | n/a | n/a | n/a | 2 | n/a |
The six dimensions
Each dimension corresponds to a real customer hardening decision. Scores are derived from public docs plus first-party lab testing. The internal spec is at docs/standards/VENDOR_SCORING_MATRIX.md.
Tunnel compatibility
Can the vendor sit in front of an origin reachable only through a private tunnel (Cloudflare Tunnel, Tailscale Funnel, ngrok) with no public listener? Native integration vs manual config vs unsupported.
API control completeness
How much of the vendor's protection config is reachable through a stable, documented API rather than dashboard-only? Drives whether DDactic can ship hardening as deployable change sets.
L3/L4 protection API
Whether volumetric / scrubbing controls (BGP, prefix protection, scrubbing policy, on-demand activation) are reachable through an API, and at what plan tier. Many vendors gate L3/L4 behind enterprise contracts.
Rate limit counting
Window type (fixed / sliding / token bucket), counter scope, sync mode (per-PoP vs eventual vs strong distributed), and the minimum threshold below which the limit becomes unreliable. Azure Front Door is documented as unreliable below 200 req/min because of eventual consistency.
Origin concealment
What concealment posture the vendor enables. CDN proxy hides origin from users but historical DNS or CT logs can leak it. Tunneling removes the public listener entirely. We map vendor support to the OPI concealment tiers.
gRPC inspection
Whether the vendor can inspect gRPC payload content at the method level, enforce per-method rate limits, block reflection probing, and handle h2c (cleartext HTTP/2) correctly. Three out of three major WAFs scored 0 in our lab.
Methodology and the receipts rule
The rule
data/ backing it.Every "Tested" score on this page is backed by a measurement file you can audit. If you find a claim without a receipt, that is a bug — write to [email protected] and we will either produce the receipt or retract the claim.
How we run a test
- Deploy a victim service behind the vendor edge using the vendor's documented reference architecture (no exotic config).
- Run the dimension-specific harness against the public endpoint from DDactic load fleet IPs. No customer traffic, no shared infrastructure.
- Capture response codes, timing, rule-fire signals, and any vendor-side telemetry visible to a customer.
- Store the raw output as
data/<lab>/<timestamp>_<vendor>_<pattern>.json. - Score only after the JSON exists. Update the matrix, link the artifact.
Receipts
Every measurement file lives in the DDactic research tree. The internal index is at docs/RESEARCH_INDEX.md; public artifacts are mirrored on request.
Known gaps not captured in the six dimensions
The six dimensions above measure what we can test directly on free or trial tiers. The following gaps were identified in 2025–2026 peer-reviewed research and apply to the tested vendors regardless of their D1–D6 scores. Sources are linked where a publicly accessible paper exists.
Want this run against your edge?
Same harness, your domain. Free, gated by domain ownership verification. No card.
Start a scan →Vendor, and think we got it wrong?
Send the trial access. We will re-run the harness against your product and update this page with the JSON receipt.
Write to research@ →