WAF + host intrusion prevention · Windows Server / IIS

An exoskeleton for your web host.

Chitin wraps your IIS sites in layered armour — blocking web attacks, brute force, bots, and malware — and it's built light enough to run on the very servers it protects.

no cloud dependency  ·  self-hosted on one box  ·  ~1 ms per request
The reality of shared hosting

Every site on the box is a target — all day, every day.

Windows/IIS hosts are hammered around the clock: SQL injection, credential stuffing across RDP and FTP, WordPress bot floods, uploaded webshells. One compromised tenant can put the whole server at risk — and most security tools are so heavy they degrade the sites they're meant to protect. Chitin was built for exactly this environment.

Defence in depth

Every request runs the gauntlet.

The three seams in our mark aren't decoration — they're the three layers a request crosses before it reaches your site. Clean traffic passes in a millisecond; attackers don't.

Plate 01 · the lit seam

Edge WAF

Chitin's WAF engine runs the full OWASP Core Rule Set v4 inline, terminating TLS and scoring every request for SQLi, XSS, LFI/RCE and the rest of the OWASP Top 10 — before IIS ever sees it.

Plate 02

Host firewall

Confirmed attackers are dropped at the kernel by Windows Firewall / WFP — time-bounded, and the admin/monitoring allowlist can never be blocked, so lockout is structurally impossible.

Plate 03 · the deepest plate

Correlation brain

A per-source risk engine turns scattered signals — probes, failed logins, bad reputation — into a decision. Slow-burn attacks that dodge any single rule still add up and get blocked.

▶ attacker → plate 01 → plate 02 → plate 03 → ✓ clean traffic to IIS
One agent · the whole attack surface

More than a WAF — host intrusion prevention for IIS.

Block the web attacks

  • OWASP Top 10: SQLi, XSS, LFI, RCE
  • OWASP Core Rule Set v4, auto-tuned per site
  • Virtual patching — shield a new CVE in minutes
  • Response inspection & data-leak prevention

Stop the brute force

  • RDP, SMB, FTP, SQL Server, mail & web logins
  • Automatic, time-bounded IP blocking
  • Distributed credential-stuffing detection
  • Read straight from the Windows Security log

Keep malware out

  • Built-in Windows Defender scanning — no extra agent
  • Webshell detection with de-obfuscation
  • File-integrity monitoring & quarantine
  • Cross-runtime file-type upload policy

Shut down bots & floods

  • JA4 TLS fingerprinting — survives IP rotation
  • Per-path rate limiting & L7 DoS caps
  • Interactive proof-of-work challenge
  • Verified-bot allowlist (Googlebot, Bingbot…)

Cut off the attacker

  • Country & port geo-blocking
  • Managed threat-intel blocklist feeds
  • Outbound / C2-beacon egress filtering
  • Cross-tenant campaign correlation

Run the operation

  • Live dashboard, alerting to Slack / Teams
  • Scheduled security reports per site
  • Config preview + one-click rollback
  • AppLocker / WDAC host hardening
Built light — on purpose

Security that doesn't tax the servers it protects.

Footprint is a feature. On resource-scarce shared hosting, a bloated agent is a non-starter — so Chitin keeps the hot path lean and pushes the heavy work off it.

1.4M
requests · 30-min soak
~94 MB
working set · held flat
~1 ms
inspection per request
0
restarts · zero leaks

Sustained-load testing on a 2-vCPU box: 1,404,474 requests, working set flat at 93–96 MB (+0.1 MB drift over 1.4M requests), 0 client errors, survives reboot with auto-restart. ~880 requests/sec/core on the full inspection path.

For web hosting providers

Turn security into a service — not an overhead.

  • Multi-tenant by design. Isolate every customer; one compromised site never becomes the whole box's problem.
  • Plugs into your panel. SolidCP today, Plesk on the roadmap — SSO and per-site provisioning from the control panel your customers already use.
  • Tenant self-service. A white-labelled portal lets customers see attacks on their own sites and tune protection — without touching yours.
  • Fleet-wide vantage. Cross-tenant campaign correlation spots one actor sweeping many customers and shuts it down everywhere at once.
  • Runs on what you already have. One small box, no cloud contract, a footprint that won't eat the margin on a shared plan.
See pricing
For small business owners

Peace of mind, without a security team.

  • Your WordPress, defended. One toggle turns on protection tuned for WordPress and forums — xmlrpc abuse, login floods, user enumeration.
  • Patched before you can be. Virtual patching shields fresh CVEs immediately, even if your plugin vendor is slow.
  • No webshells, no defacement. Malicious uploads are caught and quarantined before they ever run.
  • Attackers get locked out. Repeated login attempts on your site, FTP or mail are auto-blocked — and real customers and Google never are.
  • Nothing to install. Your host runs Chitin; you just get a site that stays up and clean.
Ask your host about Chitin
Herd immunity

When one Chitin learns, every Chitin knows.

Opt into the free, community-run threat fabric: the moment one instance confirms an attack source, that intelligence fans out to the fleet — so a first-seen attacker is already known everywhere else. Privacy-first (attacker indicators only, never your data), signed, and it can never blocklist your own allowlisted addresses.

Under the shell
Platform
Windows Server + IIS. Sits in front as a reverse proxy; IIS becomes a loopback-only origin.
Engine
Chitin's WAF engine with OWASP CRS v4 — proven on Windows at parity with the Linux baseline.
Control plane
.NET service + API + dashboard, SQLite by default, built-in Windows Defender for malware scanning.
Enforcement
Windows Firewall / WFP, time-bounded blocks, inviolable allowlist.
Footprint
Single box, no managed cloud services, ~94 MB working set under sustained load.
Deploy
Installs as Windows services, auto-start, survives reboot. Config-as-code.
Choose your shell

Start on one box. Scale to a fleet.

Essential

Sentinel

$70 /mo · per server

The full protection suite on one server — unlimited sites, self-hosted.

  • Core WAF with the OWASP Core Rule Set v4
  • Unlimited protected sites on the server
  • Automatic HTTPS for every site
  • Monitor & blocking modes with auto IP-blocking
  • Brute-force attack protection
  • Virtual patching
  • Herd immunity — shared attacker intelligence
  • Virus & malware scanning + integrity monitoring
  • Live dashboard, attack feed & audit log
  • Email alerts · business-hours support
Get started
Most popular

Carapace

$200 /mo · per server

Adds managed rule tuning and hands-on defence for busier estates.

  • Everything in Sentinel, plus:
  • Up to 50 custom rules
  • Managed Rulesets — advanced OWASP CRS tuning
  • Managed virtual patching
  • Intrusion-detection campaign correlation
  • Extended support hours
  • Priority support · quarterly tuning
Talk to us
Full defence

Exoskeleton

$500 /mo · per server

Complete managed defence with the deepest tuning and round-the-clock cover.

  • Everything in Carapace, plus:
  • Up to 500 custom rules
  • Managed Rulesets — granular tuning, account-level across domains, ML-driven Bot/Attack Score
  • Advanced managed service & trusted signed updates
  • Custom application tuning
  • 24/7 support
  • Onboarding + admin training · SLA · named engineer
Contact sales

Every plan is billed per protected server — unlimited sites, no per-request charges. New sites start in monitor-only mode, then move to active blocking after tuning.

Give your server an exoskeleton.

Layered, light, and hard to get through. See Chitin protecting real IIS traffic — or bring it to the sites you host.