About Chitin

A lightweight shell for the servers that run the web.

Chitin is a web application firewall and host intrusion prevention system for Windows Server and IIS — engineered to protect the very servers it runs on, without slowing them down.

What Chitin is

Chitin sits in front of your IIS applications as a protective edge. It inspects every request against the proven OWASP Core Rule Set, blocks the OWASP Top 10 — SQL injection, cross-site scripting, remote-code-execution and the rest — and reverse-proxies only clean traffic through to your sites. A separate control plane watches the traffic, correlates attacks, blocks persistent offenders at the host firewall, scans files for malware, and drives a single management dashboard.

It is self-hosted from end to end. There is no cloud dependency and no per-request meter: your traffic and your logs stay on infrastructure you control.

Why we built it

Most web servers sit in an awkward gap. Enterprise WAF appliances are heavy and expensive; cloud WAFs meter every request and route your traffic through someone else's platform. Neither fits the shared-hosting boxes, small-business servers and distributed service networks that quietly run a huge share of the web — often on modest hardware, and holding exactly the personal data that attackers want.

Chitin was created to close that gap: enterprise-grade protection with a footprint small enough that it never becomes the thing degrading the sites it defends. Resource frugality isn't a nice-to-have here — it's a first-class design requirement, measured and enforced like any other.

What we stand for

Principle 01

Featherweight by mandate

A small CPU and memory footprint is a condition of adoption, not an afterthought. Heavy work is pushed off the request path.

Principle 02

Self-hosted & sovereign

Everything runs on your infrastructure. Inspection and logs never leave your control — no cloud dependency.

Principle 03

Standards, not lock-in

Built on the open OWASP Core Rule Set and standards-based tooling you can audit, rather than a black box.

Principle 04

Fail-safe operations

Sites start in monitor-only mode and move to blocking after tuning; every block expires; the admin allowlist can never be overridden.

Principle 05

Config as code

Nothing on the box is hand-edited. Rules, TLS and firewall policy are generated from versioned source — consistent and repeatable.

Principle 06

Herd immunity

An attack seen on one protected server can harden them all, so the whole community gets stronger together.

Where we are

Chitin is developed and operated from the Ajman Free Zone in the United Arab Emirates, serving hosting providers, institutions and businesses that want strong, self-hosted protection for their Windows/IIS estates. To talk to us, visit our contact page.

Give your server an exoskeleton.

See Chitin protecting real IIS traffic — or bring it to the servers you run.