Home /

BlackWall

Back

One managed layer
for bot protection, security and speed

BlackWall sits in front of your website as a managed reverse proxy. It filters malicious bots and attacks, absorbs application-layer DDoS, and speeds the website up with caching and modern protocols, with no change to your hosting beyond a DNS record and allowlisting our edge

At a glance

Bot mitigation, OWASP Top 10 WAF, L7 DDoS, content caching, SSL and load balancing in a single deployment. Server-side and cookieless. Live in hours with a DNS change

2.3M+

Websites protected

100+

Hosting & service partners

30+

Countries

76%

Traffic filtered as malicious

.BlackWall TECHNOLOGY

What BlackWall is

BlackWall is an all-in-one traffic-security layer delivered as a managed reverse proxy. You point your DNS at it, and every request passes through BlackWall before it reaches your origin. In that single hop it classifies the visitor, blocks or challenges automated threats, filters malicious request content, and forwards clean traffic on, cached and compressed.

The engine is built by Blackwall (formerly BotGuard), an AI-enabled security and web-infrastructure company founded in 2019 that protects 2.3M+ websites across 30+ countries. ADPAL adapts this system to the business goals and objectives of SMBs.

It combines six things that are usually separate products:

Bot mitigation

Web application firewall (OWASP Top 10)

Layer 7 DDoS protection and rate limiting

Content caching and compression

SSL/TLS management

Load balancing and failover

. Why it matters

Web threats
are growing exponentially

More than half of all web traffic is now automated, and a large share of it is hostile. Left unfiltered, bots scrape your content and prices, test stolen credentials and cards, hoard inventory, and drown your origin in requests that were never going to buy anything

Over 50% of all website traffic was generated by bots in 2024

94 is the average number of attacks a website receives per day

In 2026, the dynamics of cyberattacks changed from explosive growth in 2024 (+75%) to a qualitative change in threats due to AI

Around a third of all traffic is malicious bots. BlackWall filters 76% across its network

.Inside the engine

How it works

BlackWall inspects and classifies every request at the edge, then acts on it. A human or a useful bot (search engines, AI-search crawlers) gets the real page. A malicious bot is denied, challenged, or served an error, before it ever reaches your server.

The check is invisible and adds only a few milliseconds. There is no interstitial, no cookie placed on your visitors.

Because the decision is server-side, BlackWall does not depend on JavaScript running in the browser, does not build a device fingerprint, and does not track visitors across sessions or sites. It is cookieless by design.

Traffic is sorted into categories (humans, search engines, social networks, cloud services and payments, content scrapers, human-emulating bots, security violators, suspicious behaviour), and each category is set to allow, deny, or challenge. An AI Advisor recommends which rules to enable from your real traffic, and custom rules let you allow or block by IP, ASN, country, user-agent, referrer or path.

Detection happens on our side, from signals the request already carries:

The TLS handshake fingerprint (the client’s cipher and extension signature)

The HTTP/2 handshake (frame ordering, settings, priority) and HTTP headers

IP, ASN, ISP and geolocation reputation, backed by continuously updated threat intelligence

The traffic and request pattern, scored by machine-learning classification

.features

Platform capabilities

Bot mitigation

Machine-learning classification separates legitimate bots (search engines, integrations) from malicious ones (scrapers, spam, credential and card testers, scalpers, vulnerability scanners), and acts per category.

Web application firewall (OWASP Top 10)

Inspects request content and filters common web-application attacks, including SQL injection, cross-site scripting (XSS) and remote code execution, plus exploit attempts against CMS platforms like WordPress and Magento. It runs alongside your existing WAF and vulnerability management. It filters malicious requests, it does not scan your site for vulnerabilities.

Layer 7 DDoS protection and rate limiting

Absorbs application-layer floods at the edge and rate-limits abusive clients (over-the-limit requests get a 403). For volumetric network-layer (L3/L4) attacks, BlackWall integrates with a carrier or network-layer DDoS solution to cover the full L3 to L7 perimeter

AI-crawler control

Allow the AI-search crawlers that send you traffic (ChatGPT, Perplexity, verified search) and block the training-only scrapers, controlled per crawler and verified by user-agent plus published IP and ASN so spoofers cannot impersonate them

Content protection and anti-scraping

Beyond blocking scrapers, Content Encryption (early access) scrambles marked sections of a page so automated scrapers get unreadable output, while real visitors and verified search engines still receive the real content. It is SEO-safe

Content caching and compression

Static and dynamic caching plus dynamic object compression offload the origin and accelerate delivery

SSL/TLS management

Automatic issue, renewal and revocation of free certificates (Let’s Encrypt), or bring your own. SSL/TLS is terminated and offloaded at the edge

Load balancing and failover

Distribute traffic across multiple origins with health checks, so the site stays up if a backend fails

Modern protocols

HTTP/3 (QUIC) and TLS 1.3 with 0-RTT, so the security layer keeps the site fast rather than slowing it down

.Bot mitigation

The bots it stops

Scrapers

copy your content, prices and data for competitors, resale or model training

Credential crackers

brute-force or replay stolen logins to break into accounts

Card testers (carding)

run stolen card numbers against your checkout to find live ones

Scalpers and inventory hoarders

buy or cart scarce stock so real customers see “out of stock”

Spam bots

flood forms, signups and comments with junk and phishing

Vulnerability scanners

probe for exposed admin pages, secrets and known exploits

.Go-live

Deployment

You point your DNS at the managed reverse proxy and go live in hours. Your hosting, CMS, application and database stay where they are. The only origin-side change is allowlisting BlackWall’s edge IPs so traffic cannot bypass the proxy. The real client IP reaches your origin through X-Forwarded-For, or PROXY protocol v2 if your origin prefers it. There is no self-hosted install and no plugin to maintain. CMS-integrated deployment is available through hosting partners.

Every site starts in monitoring mode: BlackWall classifies and reports on real traffic without blocking anything, so you can see exactly what hits your site and tune the rules before you enforce. Traffic is processed in the EU (Frankfurt) with data residency there, and per-request security events power your dashboard as security records, not visitor profiles.

.Product scope

What it is and is not

GateKeeper is an application-layer (L7) security and performance layer. To keep expectations honest:

It filters malicious requests with a WAF. It does not scan your site for vulnerabilities or replace your patching and code review.

It absorbs L7 DDoS and rate-limits abuse. Volumetric L3/L4 attacks need a network-layer solution, which it integrates with.

It challenges uncertain requests with adaptive CAPTCHA, which is off by default. Most genuine users never see one.

It is cookieless and server-side. It does not use device fingerprinting or track users across sessions.

Trust and scale

2.3M+ websites protected across 30+ countries, through
100+ hosting and service-provider partners

Backed by a EUR 45M Series B led by Dawn Capital (March 2025)

Cookieless, no cross-site tracking profiles, EU (Frankfurt) data residency

Monitor first, then enforce: every deployment is reversible with a DNS change