Fastly
Public edge cloud platform whose Next-Gen WAF, born from the 2020 Signal Sciences acquisition, provides web application, API, and bot protection at scale.
Visit Website ↗ + Add to CompareOverview
Fastly is best known as an edge cloud and content delivery network operator, but its security line — Fastly Next-Gen WAF — is a substantial, distinct product business built around web application firewall, runtime application self-protection (RASP), API security, bot management, and rate limiting. The product traces to Fastly’s $775 million acquisition of Signal Sciences in 2020, which the company folded into its edge network to inspect and block malicious traffic close to the request origin rather than relying on a bolted-on legacy WAF appliance.
Founded in 2011 and headquartered in San Francisco, Fastly went public on the NYSE in 2019 (ticker: FSLY) and has since built its security portfolio into a meaningful share of overall revenue alongside its core CDN and compute business. The company reported roughly 1,140 employees as of the end of 2025.
As a public infrastructure company operating at internet scale, Fastly brings operational credibility that pure-play application security startups typically cannot match — its WAF inspects traffic across a network built to handle some of the internet’s largest content and API workloads. It competes against both dedicated WAF/bot vendors (Cloudflare, Akamai, Imperva) and the security add-ons of other CDN platforms, and its security business is best understood as a well-integrated extension of its infrastructure footprint rather than an independent security-first product line.
Innovation Matrix Assessment
Since folding Signal Sciences into Next-Gen WAF in 2021, Fastly has iterated steadily on API security and bot management additions, a pace typical of a mature public infrastructure vendor rather than a fast-moving startup.
Delivers WAF, RASP, API protection, and bot management running on Fastly's own global edge network, giving it operational scale and latency advantages that bolt-on WAF appliances lack.
As a public company, Fastly's overall growth has been modest and security revenue is not broken out separately, making momentum specifically for the security line difficult to verify independently.
A large, publicly traded incumbent infrastructure company; per this site's convention, scaled incumbents are treated as less disruptive by definition regardless of individual product quality.
Operates at genuine internet scale with a long public-company track record and disclosure requirements, and the underlying Signal Sciences technology has years of production deployment, providing reasonable indirect confidence in reliability even without a specific named MITRE-style evaluation.
Web application and API attacks remain a core enterprise risk, and running WAF/bot protection at the CDN edge is an increasingly common architecture, though Fastly competes with larger edge-security incumbents in the same space.
Why CISOs Should Care
Offers WAF, API, and bot protection built directly into the same edge network already handling an organization's content delivery, reducing the latency and integration overhead of a separate bolt-on WAF appliance.
What Makes It Different
Runs application security inline on its own global edge infrastructure rather than as a separate appliance or overlay service, an architecture inherited from the 2020 Signal Sciences acquisition.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
A capable, well-integrated application security offering backed by real infrastructure scale, but it is a product line within a larger public CDN business rather than a security-first company, which caps its disruption score under this site's methodology.
Editorial Note: Claims vs. Verified Findings
Fastly's public-company financials, the Signal Sciences acquisition price ($775M, 2020), and IPO/headcount figures are independently verifiable through SEC filings and news coverage. Specific customer security-outcome claims and case studies are vendor-published and not independently verified here.
Sources
Alternatives to Fastly
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…