Create Accountor Login

Edge Protection

Edge Protection: your Cloudflare set up properly, then kept that way

Cloudflare can do a great deal, and almost nobody configures it past the defaults. We set the firewall, bot protection, rate limiting, caching and SSL to suit how your site is actually used, then compare the live settings against that every morning.

With Cascadia you get

  • Configured for your site, not a template
  • Firewall and bot rules set up
  • Speed settings tuned
  • Set once, checked daily
  • Drift caught the next morning
  • Changes made for you

Why teams start here

Drift caught the next morning

Nine settings are compared every day against what we set, so a change made yesterday reaches you the morning after rather than during an incident. When it was not you who changed it, we put it back.

Set once, checked daily

Settings drift. Someone turns on development mode to test something and forgets, a rule gets disabled during an incident, a TLS minimum stays where it was set in 2019. The daily comparison is what catches it.

Configured for your site, not a template

We configure for your site rather than applying a template, because a shop, a booking site and a brochure site need different rules. What we set is recorded, so you can see exactly what protects you.

What you get

Everything Edge Protection covers

All of these come with Edge Protection, set up and looked after by our team.

Firewall

  • Firewall rules written for your site
  • Rules for wp-login and xmlrpc
  • Country and ASN blocking where it helps
  • Known bad traffic dropped at the edge
  • Exceptions for the tools you actually use

Bots and abuse

  • Bot protection configured, not left default
  • Rate limiting on the paths that get hammered
  • Scrapers and vulnerability scanners blocked
  • Form spam reduced at the edge
  • Good bots let through

Speed

  • Caching tuned to how the site is built
  • Browser cache set sensibly
  • Always Online for when the origin fails
  • HTTPS enforced, and TLS kept current
  • Development mode never left on by accident

Watching

  • Nine settings compared daily against what we set
  • Told the morning after anything changes
  • 90 days of history, day by day
  • Bot and rate limiting rules checked daily with the rest
  • Put back by us when it was not you

What sets it apart

  • Drift caught the next morning
  • Set once, checked daily
  • Configured for your site, not a template
  • Cloudflare specialists, not a helpdesk
  • Nothing switched on that you did not ask for
  • Your account stays yours

Want your edge configured properly?

Tell us which site to look at and we will read your current edge settings.

What a default setup gives you, and what it misses

Cloudflare’s defaults are safe rather than right. The useful part is further in: rules that match how your site is used, caching that does not break logged-in pages, and somebody checking it still says that tomorrow.

What to compareCloudflare left on defaultsEdge Protection
FirewallGeneric rules, or none at allRules written for how your site is actually used
CachingAggressive until something breaksCaching tuned to how the site is actually built
BotsAll allowed or all blockedRules reviewed as your site changes
TLSWhatever it was set to years agoTLS and SSL kept current, and checked daily
DriftFound during the next incidentCaught the next morning, and put back when it was not you
UpkeepSet once, never revisitedReviewed as your site and its traffic change

What clients say about working with Cascadia

“I’ve always dreaded website management, but Cascadia has done an incredible job with my WordPress site, making it one less thing for me to worry about.”
Alex R.Cascadia client

Want your edge configured properly?

Talk to us

Who Edge Protection fits best

Sites that need more than a default template

A shop, a booking site and a brochure site all need different rules, so we set the firewall, bot protection, rate limiting, caching and SSL for how your site is actually used. What we set is recorded, so you can see exactly what protects you.

Get started

Sites running edge settings nobody has reviewed

A misconfigured edge is invisible until it is not: a rule that blocks your own checkout, a cache that serves a logged-in page to everyone, a TLS setting that quietly fails a card payment.

Get started

Agencies reporting this for their clients

You can sell the outcome without hiring for it. We run the technical and content work under your brand, deliver reporting you can pass straight to a client, and stay out of the relationship.

Get started

Ready to hand off your edge settings?

We watch your Cloudflare settings so you do not have to, and tell you when something moves.

How it works

1. We read your current settings

We start by reading your current settings and telling you what is wrong with them. Most sites have at least one thing that matters: TLS 1.0 still allowed, development mode left on, caching set so aggressively that logged-in users see the wrong page.

Get started

2. We set them the way your site needs

Rules are written for how your site is actually used, then applied at the edge rather than inside WordPress. Anything that could block real traffic, such as a country rule or an aggressive rate limit, is explained to you before it goes on.

Get started

3. You get the picture every month

After that it runs itself. Every morning the live settings are compared with what we set, and anything that moved becomes a ticket naming the setting and its previous value.

Get started

Pricing

What Edge Protection costs

$49/mo per domain

Get startedWe reply within two business days.

Ask us

Answers to common Edge Protection questions

Weighing us against another option? Our comparisons take the main ones in turn.

See the comparisons
What does Edge Protection cover?

The firewall rules, bot protection, rate limiting, caching and SSL on your Cloudflare account, set for how your site is actually used rather than left on the defaults. Nine settings are then compared against what we set every morning, so a change you did not make is something you hear about from us.

How is this different from just turning Cloudflare on?

Turning it on gives you the defaults, which are safe rather than right. The work is deciding which rules suit your traffic, writing them, and then noticing the morning after one of them changes. Almost nobody configures Cloudflare past the defaults, and almost nobody goes back to check it.

Can I do this on Cloudflare’s free plan?

Yes. Cloudflare’s free plan covers most of what a small business needs, and this service is about configuring it properly rather than buying more of it. Where a paid feature genuinely helps, we will say so and why.

Do you need access to my website itself?

We need access to your Cloudflare account, which is usually an invitation you can withdraw at any time. Nothing is installed on your website and no access to the site itself is needed.

How long before I see results?

Setup starts within two business days, and the first full picture arrives within a week.

Do you keep a record of what you change?

Yes. Every setting we change is recorded, and the daily snapshots are kept for 90 days, so you can see what something was, when it changed, and whether it was us.

Are Cloudflare’s defaults good enough on their own?

Cloudflare’s own defaults are a reasonable starting point and nothing more. The work is deciding which rules suit your traffic, then noticing when one of them changes.

Will a firewall rule block my own customers?

That is the risk we plan around. Anything that could block real traffic, such as a country rule or an aggressive rate limit, is explained to you before it goes on, and exceptions are written for the tools you actually use. Good bots are let through rather than caught in the same net.

What happens when a setting drifts?

You hear about it the next morning. The live settings are compared with what we set every day, and anything that moved becomes a ticket naming the setting and the value it had before. If the change was not yours, we put it back.

What do you need from me to get started?

Access to your Cloudflare account, and a note of anything that must not be touched. That is all.

Will caching break logged-in pages or checkout?

That is the usual failure of caching turned up until something gives, and tuning is what avoids it. Caching is set to how the site is built, browser cache is set sensibly, and Always Online covers the origin failing rather than serving a logged-in page to everyone.

Is this worth it for a small site?

A small site is where the edge is most often left exactly as it came, and a misconfigured edge stays invisible until it is not: a rule that blocks your own checkout, a cache that serves the wrong page, a TLS setting that quietly fails a card payment. Nothing is installed anywhere, so there is no overhead in running it on a small site.

What happens to TLS and HTTPS?

HTTPS is enforced and the TLS minimum is kept current rather than left where somebody set it years ago. SSL mode is set correctly and checked daily, which matters because a TLS setting that is quietly wrong tends to show up as a failed card payment rather than as an error anyone sees.

Do I need managed WordPress hosting or maintenance to buy this?

No. It runs as a standalone monthly service on whatever hosting you already use, and the work happens in your own Cloudflare account rather than on your website. It is also part of Domain Pro, if you would rather have DNS, the edge and your domains on one invoice.

Ask Us Anything

We’d love to hear from you!