See everything. Correct what matters.

Self-hosted edge platform: load balancing, WAF, caching, API security, and an MCP gateway — one control plane, your infrastructure.

For teams that want Cloudflare/Akamai-class controls without sending traffic through someone else's network. Built on HAProxy, Coraza, and Varnish — managed from a modern web GUI, REST API, and Terraform provider.

One proxy. Multiple directions. Zero blind spots.

A complete control plane, data plane, and web GUI — from listeners and backends to WAF, security rules, caching, API security, and AI agent integration.

WAF

OWASP CRS rules, custom SecRules, conditional exceptions, per-rule rate limiting, version snapshots, and SIEM forwarding.

Learn more →

Security Rules + Risk Scoring

Ordered first-match-wins rules with the coreX expression language. Risk scoring assigns 0-99 scores that rules can act on.

Learn more →

Load Balancing

Harness the full power of HAProxy: HTTP/2, QUIC/HTTP3, TLS, multiple load balancing algorithms, health checks, sticky sessions, and FastCGI.

Learn more →

API Security

GraphQL query analysis, JSON schema validation, JWT/API-key auth validation, and multi-dimensional behavioral profiling for API endpoints.

Learn more →

MCP Gateway

Connect AI agents via the Model Context Protocol. Teams, policies, DLP, guardrails, skills, marketplace, and a managed Vector log pipeline.

Learn more →

coreX MCP Server

Internal MCP server exposing the full coreX REST API as MCP tools. Auto-discovers all endpoints, supports curated resources and prompts, and self-registers with the MCP Gateway on enable.

Learn more →

Observability

Real-time metrics dashboards for HAProxy, WAF, and cache. Managed Vector log pipeline with S3, Datadog, Splunk, and Elasticsearch sinks. Audit events and config snapshots.

Learn more →

Page Protections

Content Security Policy management, security headers, script allowlisting, and CSP violation reporting to protect against client-side attacks.

Learn more →

Terraform Provider

Manage coreX resources as infrastructure-as-code. 50+ resource types, 22 data sources, auto-apply on every mutation, and CI/CD-friendly static JWT auth.

Learn more →

Built on proven open source

coreX wraps production-grade components in one control plane — no proprietary black box between you and your traffic.

HAProxy

Data plane proxy — HTTP/2, QUIC/HTTP/3, TLS, load balancing, health checks, and stick tables.

Coraza

WAF engine over SPOA — OWASP CRS, custom SecRules, exceptions, and version snapshots.

Varnish

Disk-tier HTTP cache — PURGE/BAN support behind HAProxy's in-memory L1 cache.

Vector

Managed observability pipeline — S3, Datadog, Splunk, Elasticsearch, and more sinks.

Self-hosted vs cloud WAF/CDN

Cloudflare and Akamai sell a global edge network. coreX is software you run yourself — different product, different tradeoffs.

With coreX (self-hosted)

  • Data plane runs on your servers — traffic never leaves your network
  • Every feature via REST API, Terraform provider, and web GUI
  • Config snapshots, diff, and rollback built in
  • Full request logs and WAF events in your SIEM
  • No per-request pricing or traffic tax

What we don't do

  • A global anycast network — you bring your own infrastructure
  • Managed PoPs in hundreds of cities
  • Someone else's uptime to lean on

Want the full breakdown? Read coreX vs Cloudflare, Akamai, F5, and HAProxy.

Control Plane

FastAPI backend with a full REST API. Every feature is configurable via the API or the web GUI. Config changes are validated, snapshotted, and applied atomically.

Data Plane

Production-grade edge proxy with SPOA WAF, Rust Lua modules for compression, response transforms, image conversion, and GeoIP. Generated config is validated before reload.

Web GUI

React + TypeScript frontend with TailwindCSS. Runtime theme switching, drag-and-drop rule ordering, visual expression builder, and real-time metrics dashboards.

See it in action

Threshold security for the edge. A modern interface for every layer of your proxy stack.

coreX Manager Dashboard

Dashboard — real-time stats, config preview, and apply

Security Rules

Security Rules — ordered first-match-wins with the coreX expression language

WAF Rules

WAF — OWASP CRS, custom rules, exceptions, and SIEM forwarding

Metrics Dashboard

Metrics — HAProxy and WAF event dashboards with breakdowns

Ready to get started?

Deploy coreX Manager in minutes with Docker Compose, or explore the full feature set.