FortiWeb Cloud

Protect your web applications and APIs with this comprehensive all-in-one web application firewall. 100% Cloud-based WAF-as-a-Service by FortiGuard Labs.

To see our range of licenses, please click the ‘Subscription Options’ tab below.

What is FortiWeb Cloud?

As a part of FortiCloud’s unified platform, FortiWeb is Fortinet’s fully cloud-hosted Web Application Firewall (WAF) and API-protection service. Delivered as a SaaS WAF-as-a-Service, it enables organisations to protect web applications and APIs hosted in public cloud environments (or elsewhere) without deploying or managing physical hardware or virtual appliances.

With FortiWeb Cloud, you get enterprise-grade web application and API security through machine-learning-enhanced threat detection, bot mitigation, DDoS protection, and automated deployment — all via a cloud-native, on-demand service.

FortiWeb Cloud provides core enterprise-grade web application security capabilities, including:

  • Cloud-native WAF as a Service for protecting web applications hosted on AWS, Microsoft Azure and Google Cloud
  • OWASP Top 10 and zero-day attack protection using machine-learning-driven detection and FortiGuard threat intelligence
  • API discovery and protection for REST, JSON and OpenAPI-based services
  • Automated bot mitigation to block scraping, credential stuffing and automated abuse
  • Application-layer DDoS protection to maintain service availability
  • Centralised cloud management and security analytics without local infrastructure

Whether you operate public-facing applications, SaaS platforms or API-driven services, FortiWeb Cloud delivers automated, continuously updated application security from a fully managed cloud service.

As a certified Fortinet partner, we support the deployment of FortiWeb Cloud subscriptions for organisations requiring scalable, cloud-native web and API security without the operational overhead of traditional WAF appliances.

FortiWeb Cloud: Features & Benefits


Cloud-Native WAF & API Security
  • Fully SaaS-delivered Web Application Firewall with no infrastructure to deploy
  • Protects web applications and APIs against OWASP Top 10 and zero-day attacks
  • Machine-learning–driven detection combined with FortiGuard threat intelligence

Bot & Application-Layer DDoS Protection
  • Automated detection and mitigation of malicious bot traffic
  • Protection against credential stuffing, scraping, and automated abuse
  • Application-layer DDoS protection to maintain service availability

Rapid Deployment & Low Operational Overhead
  • Deployed directly from public cloud marketplaces (AWS, Azure, Google Cloud)
  • Default security policies with optional advanced tuning
  • No hardware lifecycle management, patching, or capacity planning

Visibility, Analytics & Compliance Support
  • Built-in analytics for attack activity, bot traffic, and application behaviour
  • Centralised security reporting for audit and compliance
  • Continuous cloud-based signature and policy updates
FortiWeb Cloud Subscription Options
FortiWeb Cloud
FC1-10-WBCLD-604-02-12FortiWeb Cloud — 5 Mbps average throughput — annual subscription.
FC2-10-WBCLD-604-02-12FortiWeb Cloud — 10 Mbps average throughput — annual subscription.
FC3-10-WBCLD-604-02-12FortiWeb Cloud — 25 Mbps average throughput — annual subscription.
FC4-10-WBCLD-604-02-12FortiWeb Cloud — 50 Mbps average throughput — annual subscription.
FC5-10-WBCLD-604-02-12 FortiWeb Cloud — 100 Mbps average throughput — annual subscription.
FC6-10-WBCLD-604-02-12 FortiWeb Cloud — 500 Mbps average throughput —annual subscription.
C1-10-WBCLD-605-02-12FortiWeb Cloud — additional 1 website — annual subscription.
FC2-10-WBCLD-605-02-12FortiWeb Cloud — additional 5 websites — annual subscription.
FC3-10-WBCLD-605-02-12FortiWeb Cloud — additional 10 websites — annual subscription.

Documentation