Provider profile

Imperva.Security first, delivery included.

The inversion of every other profile on this site: at Imperva the application-security platform is the product, and the CDN is the delivery layer it arrives on. A market-leading WAF, a 3-second DDoS mitigation SLA, bot and API protection, all owned since 2024 by French defense-and-security group Thales. The right buy when security is the purchase, and the wrong one when bytes are.

AT A GLANCEImperva
INDEX TRACKED
3 secDDoS mitigation SLA, L3/4
13 Tbpsscrubbing capacity
2002founded
Thalesparent since Jan 2024
WAAPfull stack: WAF, bot, API, DDoS
Enterprisesales model, quote-based
Platform figures as published by Imperva/Thales · verified against public sources, July 2026
3 secguaranteed DDoS mitigation SLA
13 Tbpsglobal scrubbing capacity
L3–L7protection: network to application
90%+of customers run in blocking mode
Measured in your browserWe advise on speed. We practice it.Loaded just now · real numbers from this visit, not a lab score.
Page loaded
First byte
DOM ready
First paint
Largest paint
DNS lookup
TLS handshake
Transferred
Saved by compression
Requests
The CDN World scorecard

Imperva in seven bars.

Our advisory read, scored against the 25+ provider field we benchmark. Blue is where Imperva leads; gray is where the trade-offs live.

WAF depth & accuracy9.7
Bot & API protection9.4
DDoS mitigation & SLA9.4
Compliance & enterprise process9.0
Raw delivery economics5.8
Media & streaming delivery4.8
Self-serve & entry path4.2

Scores are CDN World’s advisory judgment, not a lab measurement.

What Imperva is

The WAAP that happens to deliver your traffic.

Founded in 2002 and acquired by Thales in January 2024, Imperva sits with a handful of vendors that define the web-application-and-API-protection category. Its Secure CDN exists so that the security stack has a global delivery layer to live on, which makes evaluating it as a CDN a category error in both directions: no pure CDN matches its security depth, and it doesn’t try to match their delivery economics.

One platform, six point products replaced

WAF, DDoS, advanced bot protection, API security, client-side and supply-chain protection under one console and one contract, with over 90% of customers confident enough to run it in blocking mode.

The 3-second promise

A contractual 3-second mitigation SLA for L3/4 DDoS attacks, backed by 13 Tbps of scrubbing and Anycast that mitigates attacks on the continent where they start. Four protection tiers cover websites, networks, DNS and individual IPs.

A real, if quiet, CDN underneath

Imperva Secure CDN does the delivery fundamentals, caching, Anycast routing, dynamic-content acceleration, well enough that protected applications get faster, not slower. Users consistently rate the security-policy flexibility above pure-CDN rivals.

Thales-grade enterprise posture

SOC 2, ISO 27001 and PCI attestations, hybrid and on-prem deployment options, and a parent whose core business is defense and data security, which lands well in regulated procurement.

The product stack

The platform, by line.

What Imperva actually sells, in the names its console uses.

APPLICATION SECURITYThe core of the business
Cloud WAF · the flagship

The market-defining web application firewall, tuned for near-zero false positives, which is why blocking mode is the norm rather than the aspiration.

Core
Advanced Bot Protection & API Security · the modern attack surface

Behavioral bot classification plus API discovery and schema enforcement, the two lines where application attacks actually grew this decade.

Core
DDoS Protection · websites, networks, DNS, IPs

Always-on or on-demand BGP-routed protection with the 3-second SLA and 13 Tbps of scrubbing, purchasable per asset class.

Core
DELIVERY & PLATFORMAround the security core
Imperva Secure CDN · delivery layer

Caching, Anycast routing and dynamic acceleration bundled with the security stack, competent delivery whose job is to make protection performance-neutral.

Included
RASP & client-side protection · inside the app

Runtime self-protection and browser-side supply-chain defense (formjacking, skimming), extending coverage past the edge.

Add-on
Data security, via Thales · adjacent estate

Under the same roof: Data Security Fabric, CipherTrust and hardware security modules, relevant when application and data protection are bought as one program.

Separate products
The map

A network sized for scrubbing, not streaming.

Our read of the global Anycast footprint: engineered so attacks are mitigated on the continent where they start, dense where enterprise applications live, deliberately not chasing eyeball-network breadth.

North America9.0
Europe8.8
Asia-Pacific7.8
Middle East7.2
Latin America7.0
Africa6.0
Mainland China3.0

Regional depth is CDN World’s advisory read of published PoP information and our own measurements, July 2026. For bulk delivery breadth or in-country China, this platform is typically paired with a delivery CDN such as CDN77 or CDNetworks.

Commercials

How Imperva is bought.

Enterprise software economics, not per-gigabyte economics.

THE COMMERCIAL PICTUREImperva pricing, decoded
BENCHMARKED
Quoteno public list, enterprise sales
Annualcontracts, per-app licensing
ModularWAF, bot, API, DDoS priced per line
POCproof-of-concept-driven evaluation
The consolidation math is the pitch

Priced against the 6+ point products it replaces, WAF, bot, API, DDoS, RASP, client-side, the platform TCO can beat the sum of the parts.

Deploy where you must

Cloud, hybrid and on-prem options mean regulated estates don’t have to bend their architecture to buy it.

No entry path for small teams

There’s no meaningful self-serve tier; if you can’t justify an enterprise sales cycle, this isn’t your product yet.

Modular licensing needs a map

Each protection line is its own SKU; scope creep between quote and renewal is the classic pattern to watch.

Never buy it as a bulk CDN

Delivery is included to carry the security stack; judged on per-GB economics alone it will lose to every delivery specialist on this site, by design.

Opaque pricing rewards benchmarks

Quote-only markets have the widest spreads between informed and uninformed buyers. Bring data or overpay.

THE CDN WORLD ANGLEScope it properly →

Imperva is not sold through our resale tiers, so our role is pure advisory: we help you decide whether a security-first platform or a delivery CDN plus best-of-breed security is the right architecture, and benchmark the quote either way.

Commercial structure as publicly described by Imperva/Thales, July 2026 · deal terms vary
Capabilities

The technical checklist.

The green lights and the deliberate gaps, as we’d brief an engineering team.

SECURITYThe reason to buy
WAF in blocking mode

Near-zero false-positive tuning; 90%+ of customers block, not just alert.

Yes
DDoS: 3-second SLA

Contractual L3/4 mitigation time, 13 Tbps scrubbing, always-on or on-demand.

Yes
Advanced bot management

Behavioral classification against credential stuffing, scraping and inventory abuse.

Yes
API discovery & protection

Finds the APIs you forgot you shipped, then enforces schemas on them.

Yes
RASP & client-side defense

Runtime protection and browser supply-chain coverage beyond the edge.

Yes
Compliance attestations

SOC 2, ISO 27001, PCI; hybrid and on-prem deployment for regulated estates.

Yes
DELIVERY & OPSWhat rides along
CDN caching & Anycast

Competent global delivery with dynamic-content acceleration.

Yes
TLS management

Certificate lifecycle handled at the edge; custom certs supported.

Yes
SIEM & SOC integrations

Attack analytics and event streams into enterprise security tooling.

Yes
Edge programmability

Rules and policies, yes; a Workers-class programmable edge, no.

Limited
Media & streaming delivery

Not the workload: no low-latency streaming stack, and per-GB economics aren’t built for video scale.

Not the fit
Self-serve & free tier

Enterprise sales only; evaluation happens through POCs, not signups.

None
Working with them

Docs, humans, status.

Documentation

Thorough enterprise docs now hosted under Thales’ cybersecurity portal, deployment guides for cloud, hybrid and BGP-routed network protection included.

Managed services

SOC-grade managed options and a threat-research team effectively extend your security staff, part of what the enterprise price buys.

During an attack

The 3-second SLA is contractual, and Anycast mitigation engages without human intervention, the operational difference between a promise and a payout clause.

Onboarding

DNS-based deployment for web assets is quick; BGP network protection and hybrid estates are proper projects, plan a POC with production-like traffic.

The verdict

Where it wins. Where it doesn’t.

The two-minute version we give clients before the numbers.

Wins: when security is the purchase

If the deal is driven by WAF accuracy, bot pressure, API exposure or a DDoS SLA with teeth, Imperva belongs on every shortlist, and consolidating six point products into one platform often pays for the premium.

Wins: regulated and attacked enterprises

Compliance attestations, hybrid deployment, Thales parentage and blocking-mode confidence make it a natural fit for finance, healthcare and anyone currently absorbing attacks.

Wins: as the security leg of a split architecture

Imperva in front of the application layer with a delivery CDN handling static and media traffic is a pattern we architect regularly, each vendor doing what it’s actually for.

Loses: bulk delivery and media workloads

Per-gigabyte economics and streaming capability are not the mission; judged as a delivery CDN it loses to every specialist here, deliberately.

Loses: developer-led and self-serve teams

No free tier, no card-signup, no community edition; if your evaluation culture is “try it this afternoon”, the sales motion alone disqualifies it.

Loses: price-led consolidation

If the goal is one cheap vendor for everything, bundled CDN-plus-security challengers will undercut it substantially, at a real cost in security depth you should price consciously.

FAQ

Imperva questions,
answered straight.

Is Imperva actually a CDN?

Technically yes, functionally it’s a security platform with delivery included. Imperva Secure CDN handles caching, Anycast routing and dynamic acceleration competently, but it exists to carry the WAF, bot, API and DDoS stack. Evaluate it as application protection that keeps your app fast, never as a per-gigabyte delivery deal.

What does the 3-second DDoS SLA actually promise?

A contractual guarantee that L3/4 volumetric and protocol attacks are mitigated within three seconds of detection, backed by 13 Tbps of scrubbing capacity and Anycast that absorbs attacks on the continent where they originate. It covers websites, whole networks, DNS and individual IPs as separately purchasable tiers.

Who owns Imperva now?

Thales, the French defense and security group, completed its acquisition of Imperva in January 2024 and runs it alongside its data-security portfolio (CipherTrust, Luna HSMs, Data Security Fabric). For buyers, the practical effects are enterprise stability and a broader combined security estate.

What does Imperva cost?

There is no public price list: licensing is quoted per application and per protection module on annual enterprise contracts. The honest comparison is against the combined cost of the point products it replaces, and because quote-only markets have wide spreads, benchmark data materially changes the negotiation.

Can it replace my separate WAF, bot and API vendors?

That consolidation is precisely the pitch, one platform, one console, one contract, and with over 90% of customers running in blocking mode, the accuracy claims hold up operationally. The evaluation question is whether each module matches the best-of-breed tool it replaces for your specific traffic; that’s what a POC is for.

How does CDN World fit in?

Imperva isn’t part of our resale tiers, so our role is architectural and commercial: we help you decide between a security-first platform and a delivery-CDN-plus-security split, then benchmark whichever quote you pursue. Start with a security-focused assessment.