Chitin wraps your IIS sites in layered armour — blocking web attacks, brute force, bots, and malware — and it's built light enough to run on the very servers it protects.
Windows/IIS hosts are hammered around the clock: SQL injection, credential stuffing across RDP and FTP, WordPress bot floods, uploaded webshells. One compromised tenant can put the whole server at risk — and most security tools are so heavy they degrade the sites they're meant to protect. Chitin was built for exactly this environment.
The three seams in our mark aren't decoration — they're the three layers a request crosses before it reaches your site. Clean traffic passes in a millisecond; attackers don't.
Chitin's WAF engine runs the full OWASP Core Rule Set v4 inline, terminating TLS and scoring every request for SQLi, XSS, LFI/RCE and the rest of the OWASP Top 10 — before IIS ever sees it.
Confirmed attackers are dropped at the kernel by Windows Firewall / WFP — time-bounded, and the admin/monitoring allowlist can never be blocked, so lockout is structurally impossible.
A per-source risk engine turns scattered signals — probes, failed logins, bad reputation — into a decision. Slow-burn attacks that dodge any single rule still add up and get blocked.
Footprint is a feature. On resource-scarce shared hosting, a bloated agent is a non-starter — so Chitin keeps the hot path lean and pushes the heavy work off it.
Sustained-load testing on a 2-vCPU box: 1,404,474 requests, working set flat at 93–96 MB (+0.1 MB drift over 1.4M requests), 0 client errors, survives reboot with auto-restart. ~880 requests/sec/core on the full inspection path.
Opt into the free, community-run threat fabric: the moment one instance confirms an attack source, that intelligence fans out to the fleet — so a first-seen attacker is already known everywhere else. Privacy-first (attacker indicators only, never your data), signed, and it can never blocklist your own allowlisted addresses.
The full protection suite on one server — unlimited sites, self-hosted.
Adds managed rule tuning and hands-on defence for busier estates.
Complete managed defence with the deepest tuning and round-the-clock cover.
Every plan is billed per protected server — unlimited sites, no per-request charges. New sites start in monitor-only mode, then move to active blocking after tuning.
Layered, light, and hard to get through. See Chitin protecting real IIS traffic — or bring it to the sites you host.