MessageFlow
MessageFlowPricingBlogAPI docs
EN
EN
  • MessageFlow Documentation
  • 🚀ACCOUNT
    • Dashboard
    • User panel
      • Settlements
      • Settings
        • Security
        • IP Authorization
        • Two-Factor Authentication (2FA)
        • API
        • Webhooks
      • Notifications
      • Operation list
      • File manager
      • GDPR
    • Login and account management
      • How to create an account?
      • Logging into the platform
      • Resetting the password
      • Changing your password in the App
      • Two-step authentication (2FA)
      • Resetting 2FA Settings
    • User and role management
      • Adding a user
      • Assigning permissions
      • User account activation
      • Editing and deleting a user
  • 💬CONTACTS
    • Adding contacts
      • Adding contacts manually
      • Importing contact lists (CSV, Excel)
      • Additional fields
    • Segmentation of customers
    • Archiving groups
  • Deleting groups
  • ✨COMMUNICATION CHANNELS IN THE PANEL
    • E-mail
      • Overview
      • Dashboard
      • Campaigns
        • Campaign list
        • Exporting campaigns from the list
        • Creating e-mail campaigns
          • Designing messages with a drag-and-drop editor
          • Email creation specifications
          • Personalizing email campaigns
          • Creating and downloading message templates
        • Booster for e-mail campaigns
          • Instructions for sending an e-mail campaign with the Booster option
          • Reports & analytics
      • Analytics, audiences and reports
        • Monitoring deliverability, opens, clicks
        • Storage of email campaign reports
        • Email address archiving, removing hard-bouncing addresses, unsubscribes
      • Outgoing
        • Outgoing List
        • Export list
      • Settings
        • Adding a sign-out page
    • SMS
      • Overview
      • Dasboard
      • Campaigns
        • Campaign list
        • Exporting campaigns from the list
        • Creating SMS campaign
        • Booster for SMS campaign
          • Instructions for sending an SMS campaign with the Booster option
          • Reports & analytics
      • Analytics, audiences and reports
        • Reporting and analysis of SMS campaign results
        • Storage of SMS campaign data
        • Archiving recipients, removing recipients with ERROR status
      • Incoming
        • List of incoming
        • Export list
      • Outgoing
        • Outgoing list
        • Export list
      • Settings
        • List of links with suffixes
        • Unsubscribe pages
      • Common settings
        • Sender IDs
      • Integration with short codes
      • SMS Billing
    • Mobile push
      • Overview
      • Dashboard
      • Campaigns
        • Campaign list
        • Export list
        • Push campaign configuration
        • Booster for mobile push campaign
          • Instructions for sending a mobile push campaign with the Booster option
          • Reports & analytics
      • Outgoing
        • Outgoing list
        • Export list
      • Analytics and report
        • Push campaign report
        • Push campaign data storage
      • Common settings
        • Applications
        • Adding test device
      • Segmentation
    • RCS
      • RCS message types
      • What is a Brand Bot?
      • How to run RCS?
      • Tips for creating a campaign
      • Technical specifications of the RCS service
  • 🖥️API CHANNELS
    • E-mail API
      • Dashboard
      • E-mails report
      • Tag report
      • Domains report
      • Blacklist Report
      • Whitelist report
      • Settings
    • Mobile push API
      • Overwiev
      • Dashboard
      • Outgoing
        • Outgoing list
        • Export
    • SMS API
      • Overview
      • Dashboard
      • Incoming
        • Incoming list
        • Export
      • Outgoing
        • Outgoing list
        • Export
  • ⚙️TECHNICAL SUPPORT CENTER
    • Integrations
      • Integration with Salesforce
      • Integration with SalesManago
      • Integration with Synerise
      • Integration with IdoSell
    • Senders Authorization
      • How to Authorize Senders in MessageFlow?
        • Domains Authorization
        • Authorizing domains with web hosts
          • Authorizing a domain hosted at Nazwa.pl
          • Authorization of a domain hosted at Home.pl
          • Authorizing a domain hosted at cyber_Folks
          • Authorizing a domain hosted on Zenbox
          • Authorizing a domain hosted on OVHcloud
          • Authorizing a domain hosted on GoDaddy
        • SPF Record Configuration
    • System requirements
    • Technical assistance
    • API documentation
    • FAQ
  • Trust Center
    • Account Security
      • Password Management
      • Two-Factor Authentication (2FA)
      • IP Access Control
      • User & Role Management
    • Communication Channel Security
      • Email Communication Security
      • SMS Communication Security
      • RCS, Mobile Push & Viber Security
    • Data & Infrastructure Security
      • Our Commitment to Security
      • Data Center Security
      • Technical & Organisational Measures (TOMS)
      • Service Protection (WAF)
      • List of Procedures
    • Data Protection & Compliance
      • Legal Framework
      • Personal Data Processing at MessageFlow
      • Data Processing Agreement (DPA)
      • Document Templates
      • Sub-processors
    • Certifications & Audits
      • ISO Certifications
      • Security & Penetration Testing
      • Industry Standards & Affiliations
    • Abuse Prevention
      • MessageFlow Shield 360: Proactive Threat Protection
      • Recognising and Analysing Suspicious Messages (User Guidance)
      • Abuse Policy and Reporting
    • Security FAQ
Powered by GitBook
On this page
  1. Trust Center
  2. Data & Infrastructure Security

Service Protection (WAF)

Our platform is protected by an industry-leading Web Application Firewall (WAF) provided by our partner, Cloudflare, a global leader in web security. The WAF acts as a powerful shield, operating on a global edge network to filter all traffic before it reaches our core infrastructure. This proactive defence is a critical component of our strategy to ensure the stability and security of the MessageFlow service.

Key benefits of our WAF implementation include:

  • DDoS Mitigation: The WAF automatically detects and mitigates large-scale Distributed Denial-of-Service (DDoS) attacks of all types. By absorbing and filtering malicious traffic at the network edge, it ensures that our platform and API remain available and responsive, even during an attack.

  • Protection Against Common Vulnerabilities: It provides robust protection against the most critical web application security risks, as defined by the OWASP Top 10. This includes defending against common attack vectors such as SQL injection (SQLi), cross-site scripting (XSS), and other attempts to compromise the application layer.

  • Intelligent Bot Management: The WAF intelligently identifies and blocks malicious automated traffic. This prevents bad bots from scraping content, attempting credential stuffing attacks, or otherwise abusing our services, while allowing legitimate bots (like search engine crawlers) to pass through.

See our full list of Sub-processors.

PreviousTechnical & Organisational Measures (TOMS)NextList of Procedures

Last updated 1 day ago