Chitin is a web application firewall and host intrusion prevention system for Windows Server and IIS — engineered to protect the very servers it runs on, without slowing them down.
Chitin sits in front of your IIS applications as a protective edge. It inspects every request against the proven OWASP Core Rule Set, blocks the OWASP Top 10 — SQL injection, cross-site scripting, remote-code-execution and the rest — and reverse-proxies only clean traffic through to your sites. A separate control plane watches the traffic, correlates attacks, blocks persistent offenders at the host firewall, scans files for malware, and drives a single management dashboard.
It is self-hosted from end to end. There is no cloud dependency and no per-request meter: your traffic and your logs stay on infrastructure you control.
Most web servers sit in an awkward gap. Enterprise WAF appliances are heavy and expensive; cloud WAFs meter every request and route your traffic through someone else's platform. Neither fits the shared-hosting boxes, small-business servers and distributed service networks that quietly run a huge share of the web — often on modest hardware, and holding exactly the personal data that attackers want.
Chitin was created to close that gap: enterprise-grade protection with a footprint small enough that it never becomes the thing degrading the sites it defends. Resource frugality isn't a nice-to-have here — it's a first-class design requirement, measured and enforced like any other.
A small CPU and memory footprint is a condition of adoption, not an afterthought. Heavy work is pushed off the request path.
Everything runs on your infrastructure. Inspection and logs never leave your control — no cloud dependency.
Built on the open OWASP Core Rule Set and standards-based tooling you can audit, rather than a black box.
Sites start in monitor-only mode and move to blocking after tuning; every block expires; the admin allowlist can never be overridden.
Nothing on the box is hand-edited. Rules, TLS and firewall policy are generated from versioned source — consistent and repeatable.
An attack seen on one protected server can harden them all, so the whole community gets stronger together.
Chitin is developed and operated from the Ajman Free Zone in the United Arab Emirates, serving hosting providers, institutions and businesses that want strong, self-hosted protection for their Windows/IIS estates. To talk to us, visit our contact page.
See Chitin protecting real IIS traffic — or bring it to the servers you run.