Imperva.Security first, delivery included.
The inversion of every other profile on this site: at Imperva the application-security platform is the product, and the CDN is the delivery layer it arrives on. A market-leading WAF, a 3-second DDoS mitigation SLA, bot and API protection, all owned since 2024 by French defense-and-security group Thales. The right buy when security is the purchase, and the wrong one when bytes are.
Imperva in seven bars.
Our advisory read, scored against the 25+ provider field we benchmark. Blue is where Imperva leads; gray is where the trade-offs live.
Scores are CDN World’s advisory judgment, not a lab measurement.
The WAAP that happens to deliver your traffic.
Founded in 2002 and acquired by Thales in January 2024, Imperva sits with a handful of vendors that define the web-application-and-API-protection category. Its Secure CDN exists so that the security stack has a global delivery layer to live on, which makes evaluating it as a CDN a category error in both directions: no pure CDN matches its security depth, and it doesn’t try to match their delivery economics.
WAF, DDoS, advanced bot protection, API security, client-side and supply-chain protection under one console and one contract, with over 90% of customers confident enough to run it in blocking mode.
A contractual 3-second mitigation SLA for L3/4 DDoS attacks, backed by 13 Tbps of scrubbing and Anycast that mitigates attacks on the continent where they start. Four protection tiers cover websites, networks, DNS and individual IPs.
Imperva Secure CDN does the delivery fundamentals, caching, Anycast routing, dynamic-content acceleration, well enough that protected applications get faster, not slower. Users consistently rate the security-policy flexibility above pure-CDN rivals.
SOC 2, ISO 27001 and PCI attestations, hybrid and on-prem deployment options, and a parent whose core business is defense and data security, which lands well in regulated procurement.
The platform, by line.
What Imperva actually sells, in the names its console uses.
The market-defining web application firewall, tuned for near-zero false positives, which is why blocking mode is the norm rather than the aspiration.
CoreBehavioral bot classification plus API discovery and schema enforcement, the two lines where application attacks actually grew this decade.
CoreAlways-on or on-demand BGP-routed protection with the 3-second SLA and 13 Tbps of scrubbing, purchasable per asset class.
CoreCaching, Anycast routing and dynamic acceleration bundled with the security stack, competent delivery whose job is to make protection performance-neutral.
IncludedRuntime self-protection and browser-side supply-chain defense (formjacking, skimming), extending coverage past the edge.
Add-onUnder the same roof: Data Security Fabric, CipherTrust and hardware security modules, relevant when application and data protection are bought as one program.
Separate productsA network sized for scrubbing, not streaming.
Our read of the global Anycast footprint: engineered so attacks are mitigated on the continent where they start, dense where enterprise applications live, deliberately not chasing eyeball-network breadth.
Regional depth is CDN World’s advisory read of published PoP information and our own measurements, July 2026. For bulk delivery breadth or in-country China, this platform is typically paired with a delivery CDN such as CDN77 or CDNetworks.
How Imperva is bought.
Enterprise software economics, not per-gigabyte economics.
Priced against the 6+ point products it replaces, WAF, bot, API, DDoS, RASP, client-side, the platform TCO can beat the sum of the parts.
Cloud, hybrid and on-prem options mean regulated estates don’t have to bend their architecture to buy it.
There’s no meaningful self-serve tier; if you can’t justify an enterprise sales cycle, this isn’t your product yet.
Each protection line is its own SKU; scope creep between quote and renewal is the classic pattern to watch.
Delivery is included to carry the security stack; judged on per-GB economics alone it will lose to every delivery specialist on this site, by design.
Quote-only markets have the widest spreads between informed and uninformed buyers. Bring data or overpay.
Imperva is not sold through our resale tiers, so our role is pure advisory: we help you decide whether a security-first platform or a delivery CDN plus best-of-breed security is the right architecture, and benchmark the quote either way.
The technical checklist.
The green lights and the deliberate gaps, as we’d brief an engineering team.
Near-zero false-positive tuning; 90%+ of customers block, not just alert.
YesContractual L3/4 mitigation time, 13 Tbps scrubbing, always-on or on-demand.
YesBehavioral classification against credential stuffing, scraping and inventory abuse.
YesFinds the APIs you forgot you shipped, then enforces schemas on them.
YesRuntime protection and browser supply-chain coverage beyond the edge.
YesSOC 2, ISO 27001, PCI; hybrid and on-prem deployment for regulated estates.
YesCompetent global delivery with dynamic-content acceleration.
YesCertificate lifecycle handled at the edge; custom certs supported.
YesAttack analytics and event streams into enterprise security tooling.
YesRules and policies, yes; a Workers-class programmable edge, no.
LimitedNot the workload: no low-latency streaming stack, and per-GB economics aren’t built for video scale.
Not the fitEnterprise sales only; evaluation happens through POCs, not signups.
NoneDocs, humans, status.
Thorough enterprise docs now hosted under Thales’ cybersecurity portal, deployment guides for cloud, hybrid and BGP-routed network protection included.
SOC-grade managed options and a threat-research team effectively extend your security staff, part of what the enterprise price buys.
The 3-second SLA is contractual, and Anycast mitigation engages without human intervention, the operational difference between a promise and a payout clause.
DNS-based deployment for web assets is quick; BGP network protection and hybrid estates are proper projects, plan a POC with production-like traffic.
Where it wins. Where it doesn’t.
The two-minute version we give clients before the numbers.
If the deal is driven by WAF accuracy, bot pressure, API exposure or a DDoS SLA with teeth, Imperva belongs on every shortlist, and consolidating six point products into one platform often pays for the premium.
Compliance attestations, hybrid deployment, Thales parentage and blocking-mode confidence make it a natural fit for finance, healthcare and anyone currently absorbing attacks.
Imperva in front of the application layer with a delivery CDN handling static and media traffic is a pattern we architect regularly, each vendor doing what it’s actually for.
Per-gigabyte economics and streaming capability are not the mission; judged as a delivery CDN it loses to every specialist here, deliberately.
No free tier, no card-signup, no community edition; if your evaluation culture is “try it this afternoon”, the sales motion alone disqualifies it.
If the goal is one cheap vendor for everything, bundled CDN-plus-security challengers will undercut it substantially, at a real cost in security depth you should price consciously.
Imperva in context.
Where this profile connects to the rest of our research.
Imperva questions,
answered straight.
Is Imperva actually a CDN?
Technically yes, functionally it’s a security platform with delivery included. Imperva Secure CDN handles caching, Anycast routing and dynamic acceleration competently, but it exists to carry the WAF, bot, API and DDoS stack. Evaluate it as application protection that keeps your app fast, never as a per-gigabyte delivery deal.
What does the 3-second DDoS SLA actually promise?
A contractual guarantee that L3/4 volumetric and protocol attacks are mitigated within three seconds of detection, backed by 13 Tbps of scrubbing capacity and Anycast that absorbs attacks on the continent where they originate. It covers websites, whole networks, DNS and individual IPs as separately purchasable tiers.
Who owns Imperva now?
Thales, the French defense and security group, completed its acquisition of Imperva in January 2024 and runs it alongside its data-security portfolio (CipherTrust, Luna HSMs, Data Security Fabric). For buyers, the practical effects are enterprise stability and a broader combined security estate.
What does Imperva cost?
There is no public price list: licensing is quoted per application and per protection module on annual enterprise contracts. The honest comparison is against the combined cost of the point products it replaces, and because quote-only markets have wide spreads, benchmark data materially changes the negotiation.
Can it replace my separate WAF, bot and API vendors?
That consolidation is precisely the pitch, one platform, one console, one contract, and with over 90% of customers running in blocking mode, the accuracy claims hold up operationally. The evaluation question is whether each module matches the best-of-breed tool it replaces for your specific traffic; that’s what a POC is for.
How does CDN World fit in?
Imperva isn’t part of our resale tiers, so our role is architectural and commercial: we help you decide between a security-first platform and a delivery-CDN-plus-security split, then benchmark whichever quote you pursue. Start with a security-focused assessment.
Imperva is a trademark of Imperva, Inc., a Thales company. CDN World is an independent advisory and is not affiliated with or endorsed by Imperva or Thales. Platform figures are as published by Imperva/Thales or reported in public sources as of July 2026 and may change.
