ALL 218 POPS OPERATIONAL · THREAT LEVEL: GUARDED · 2026-07-01 14:02 UTC

The perimeter is wherever you are

Your office is a laptop in a departure lounge. Palisade fuses zero-trust access, an edge WAF and live threat intelligence into one control plane — policy enforced in 218 cities, 0.4 ms from the request, with nothing to backhaul and no VPN concentrator to babysit.

install · one binary, no agents to herdsh
$ curl -sSL get.palisade.dev | sh -s -- --org yourco
3.1Trequests inspected / 24h
218cities running policy
41msmedian RTT, worldwide
8.7srule push, fleet-wide p95

01 // the threat feed

This is your traffic, ten minutes ago. Every verdict, on the record.

palisade tail --org acme-metals --env prod --live LIVE
14:02:11.084 PASS mTLS handshake · deploy-bot@acme-metals · fra1 · 12ms 14:02:11.319 PASS sso login · n.okafor@acme-metals.com · lhr2 · webauthn touch ok 14:02:12.007 FLAG scanner fingerprint · AS208091 "SafeRoute Hosting Ltd" · 61 req/s · watching 14:02:12.440 BLOCK credential stuffing · POST /login · src 91.240.118.44 · rule CS-0117 · hit 1,022 today 14:02:13.213 BLOCK sqli attempt · GET /api/orders?id=1'+OR+'1'='1 · src 45.155.204.9 · rule WAF-942100 14:02:14.902 PASS service mesh · billing → ledger · iad7 · mTLS · policy 0.3ms 14:02:15.677 FLAG impossible travel · j.reyes@acme-metals.com · lhr2 → sin3 in 41min · step-up issued 14:02:16.208 BLOCK c2 callback · dns query cdn-metrics-sync.example-tld.ru · resolver refused · host quarantined 14:02:16.981 PASS step-up cleared · webauthn · session re-scoped to read-only for 24h 14:02:17.552 INFO rule CS-0117 pushed to 218 pops · propagation 8.7s · fleet consistent
redactions honor least-privilege — in this demo, hovering grants clearance click to skip typing

02 // the modules

Six blades, one hilt. Everything reads from the same policy.

01EDGE-WAF Managed and custom rules compiled to native filters at every PoP. The OWASP core set is re-tuned weekly against live traffic, not a lab corpus from 2023. +0.4ms p50 latency
02ZERO-TRUST ACCESS Per-request identity checks against your IdP. SSH, RDP and internal apps reachable from a café Wi-Fi — safely — with no concentrator and no split-tunnel folklore. 100% requests authenticated
03DNS FIREWALL Resolver-level refusal of C2 domains, typosquats and freshly-registered lookalikes — the connection dies before a socket ever opens. 1.9M domains re-scored hourly
04BOT DEFENSE TLS and behavioral fingerprints separate people from headless fleets. Your real users never see a traffic-light puzzle; the fleets never see your pricing page. 99.97% precision on replay sets
05SECRETS VAULT Short-lived credentials minted per session. Nothing long-lived to steal, nothing static to rotate at 2am after the breach report lands. 15-min max token TTL
06INCIDENT RUNBOOKS One keystroke to isolate a host, revoke a token, or freeze a deploy — rehearsed in game-days, logged to your SIEM, reversible when the all-clear sounds. 8.7s global propagation

03 // the network

One policy. Every packet, every city, same answer.

/01

Identify

Every request carries an identity — user, service or device — verified against your IdP before a route is even chosen.

/02

Evaluate

Policy executes at the PoP nearest the requester, not a distant chokepoint. Allow, step-up or block in 0.4 ms — the packet never notices.

/03

Record

Every verdict streams to your SIEM in OCSF within five seconds. No nightly export job, no second source of truth.

iad7 fra1 sin3 lhr2 scl1 jnb2 gru4 · refused ALLOW · 0.4ms · sin3

04 // the numbers

Scale is the moat. Every attack we see teaches every customer's edge.

3.1T

requests inspected every 24 hours — the training data your WAF rules are tuned against, refreshed nightly.

8.7s

p95 from "block this" to the rule running in all 218 cities. An attacker's second request meets the wall.

218

cities with Palisade compute. Your policy runs where your users stand, not where your data center happens to be.

0*

VPN concentrators left to patch, license and babysit. *We keep one in a glass case in the Kearny St lobby.

05 // pricing

Priced like infrastructure. Because that's what it is.

Perimeter

// side projects & solo operators

$0

forever · no card at signup

  • 1 edge site, 50k inspected requests/day
  • Community WAF ruleset, updated weekly
  • Zero-trust access for 3 seats
  • 7-day verdict log retention
start free
MOST DEPLOYED

Garrison

// teams shipping real products

$349/mo

annual · $419 month-to-month

  • 25 sites, 40M inspected requests/day
  • Custom WAF rules + bot defense
  • Zero-trust for 100 seats, any IdP
  • 90-day retention, SIEM streaming
  • 24/7 pager escalation, 30-min response
deploy garrison

Citadel

// regulated & high-consequence fleets

Custom

talk to an engineer, not a rep

  • Unlimited sites, dedicated PoP compute
  • Threat-intel API + named response team
  • 15-minute incident SLO, contractual
  • FedRAMP-track, audit artifacts under NDA
book a briefing

Stand up your palisade in 14 minutes.

One binary at the edge, your IdP plugged in, first verdicts in the feed before your coffee is cold. Rip it out with one command if we're wrong — you won't.

$ palisade init --org yourco --pop auto
SOC 2 TYPE IIISO 27001PCI DSS 4.0REPORTS UNDER NDA