Okay, I'll tell you how I really think about it, without so much report formatting.
If I had to choose one thing that "enchants" me about this tool, it would be the automatic policy generation. Anyone who has suffered through the first weeks of a new WAF knows what I'm talking about: that eternal period in "learning" mode where every poorly calibrated rule crashes your production checkout at 2am, and you end up glued to the logs for fear of breaking something. That the system detects new apps on its own and creates rules without me having to sit down and define every exception... that takes years off my life. It's the difference between "tool I manage" and "tool that helps me manage."
And the single portal hits me hard too, but for a more emotional than technical reason: I've lived the nightmare of reconstructing an incident by jumping between three different consoles, trying to piece together the timeline with logs that don't speak the same language. When you're under pressure, with people asking "have we controlled it yet?", the last thing you need is to be doing control-C control-V between tabs. Having everything — WAF, bots, DDoS, API — in one place with decent logs is, honestly, more of a relief than a feature. Review collected by and hosted on G2.com.
that to block an IP you have to call support and wait for hours. That breaks my trust a little. It's like buying a car with excellent brakes but having to call the dealership to activate them. In security, minutes count, and delegating the quick reaction to an external third party would make me nervous if there isn't something automatic as a backup for obvious cases.
The complicated bot manager also sounds to me like those tools that promise a lot in the demo and then, in the real implementation, you end up fighting with configurations that no one documented well. And that alerts only arrive by email or SMS in 2026 feels kind of outdated — I already live glued to Slack or Teams, not my inbox. Review collected by and hosted on G2.com.