koigrid vs Cloudflare WAF
Allow/block rules for your traffic — the flat-rate alternative to Cloudflare WAF and Vercel Firewall.
Cloudflare WAF set the bar for rule-based traffic filtering. koigrid gives you the core — allow/block by IP, CIDR, country, path, method or user-agent — as a fast rule engine your edge or agent calls to decide, at a flat rate and right next to your apps.
| Feature | koigrid | Cloudflare WAF |
|---|---|---|
| Pricing | Flat rate | Per plan / request |
| IP / CIDR / country | Yes | Yes |
| Path / method / UA | Yes | Yes |
| Allow-list overrides (priority) | Yes | Yes |
| Decision API | Yes | Partial |
| Manage by AI agent | Native | API |
What koigrid improves
One platform
Rules live next to the apps they protect.
Flat, predictable
One price — no per-request WAF bill.
Agent-native
An agent blocks abuse the moment it sees it.
Frequently asked questions
Is koigrid cheaper than Cloudflare WAF?
koigrid is flat-rate with bandwidth included — no per-GB egress or per-request fees. For a comparable setup you usually pay a lot less (see the estimate above).
Can I migrate from Cloudflare WAF without lock-in?
Yes. koigrid runs on portable primitives — standard PostgreSQL, S3-compatible storage and containers — so you can move in (or out) whenever you want.
Is my data hosted in the EU?
Yes. koigrid is EU-hosted (on Hetzner) with data sovereignty by default.
Can I run everything from an API or an AI agent?
Yes — koigrid is API-first and agent-native: every action has an API and a scoped token, with llms.txt and OpenAPI so an LLM can operate it end to end.