No hardware to buy, no server room to visit. Point your domain's DNS to Akamai, and attacks are stopped before they reach your server. GN-AI provides planning, deployment, policy tuning, and annual maintenance.
Akamai Technologies was founded in 1998, is headquartered in Cambridge, Massachusetts, and is listed on NASDAQ (ticker AKAM). It started as a CDN (Content Delivery Network) provider and invented the category. A CDN puts website content in the data center closest to the user, making the site faster. Over the past decade its focus has shifted to security: 2025 security revenue was USD 2.243 billion, now over half of total company revenue.
Point your domain (DNS) to Akamai, and before anyone in the world connects to your site, traffic passes through Akamai's data centers first. Attacks are cleaned out there. Only clean, accelerated traffic reaches your own server.
So it is a different procurement model from buying a box and putting it in your server room. Traffic runs over Akamai's global network, so you don't need to scale your own hardware to absorb peak load or attack volume. For scenarios where conditions differ, see "Matching the option to the scenario" below.
Names follow the vendor's current official naming. Each entry includes a plain-language explanation and "who needs this".
WAF, application-layer DDoS, bot management, API discovery, and sensitive data protection, bundled into one product. WAF stands for web application firewall, blocking attacks like SQL injection and XSS that a normal firewall cannot recognize. An adaptive security engine automatically fine-tunes rules to reduce false positives.
Who needs this: companies with a public-facing website or app backend that handle payments or member data.
Handles attacks that try to saturate the whole network link. It works by using BGP to route the entire IP block to a scrubbing center, filtering the traffic, then sending it back; on-premises and hybrid versions are also available.
Who needs this: companies that need to protect an entire server room or IP block, including non-website services such as mail and VPN.
Bot Manager tells whether a visitor is a human or a script: it lets Google's crawler through and blocks ticket-scalping bots and price-scraping bots. The same family includes two separate products: Account Protector, against account takeover and credential-stuffing attacks, and Content Protector, against bulk content scraping. The three are licensed separately and must be purchased individually.
Who needs this: eCommerce, ticketing, gaming, media, and any site with a login page.
First discovers every API, including ones nobody remembers and ones that should have been shut down long ago. Then runs security testing, behavior monitoring, and compliance mapping. The vendor states it is platform-agnostic, covering multi-cloud, hybrid cloud, and on-premises.
Who needs this: financial, eCommerce, and logistics companies that expose APIs to apps, partners, or third parties.
Protects against a specific case: the website itself is not hacked, but a third-party JavaScript file it loads has been tampered with to skim card numbers on the checkout page. Maps directly to PCI DSS 4.0 requirements 6.4.3 and 11.6.1.
Who needs this: eCommerce, booking, ticketing, and payment platforms that take credit cards directly on their own site.
The products above defend against attacks coming from outside; this one defends against someone who is already inside moving around freely, which is how ransomware spreads across an internal network. It can be deployed with an agent or agentless, so there is no need to re-plan your VLANs.
Who needs this: mid-size to large companies with an existing server room that don't want a major architecture overhaul.
Enterprise Application Access (EAA) replaces a traditional VPN, giving employees access only to the specific system they need. Secure Internet Access Enterprise (SIA) blocks phishing sites at the DNS and network layer. Akamai MFA is multi-factor authentication.
Who needs this: companies with remote work or outsourced staff that want to retire an old VPN.
Akamai's own public cloud, launched after it acquired Linode in March 2022. It offers compute instances, a managed Kubernetes service, object and block storage, and AI inference nodes. Its pitch is transparent pricing and low egress fees.
Who needs this: companies sensitive to cloud bill fluctuations that want an option alongside their own server room.
A separate new product launched after Akamai completed its acquisition of LayerX in July 2026: it governs what data employees send to generative AI, blocks overly permissive browser extensions, and controls uploads and downloads.
Who needs this: companies that allow staff to use generative AI but need to control data leakage.
Note: it is a standalone product, not part of the EAA/SIA/MFA family.
If two or more of the following apply, cloud WAF is usually worth serious evaluation.
Visitor sources cannot be whitelisted in advance.
The loss from an hour of downtime exceeds the annual cost of protection.
The same budget covers both acceleration and protection.
Requirements 6.4.3 and 11.6.1 are mandatory audit items.
What you need is capacity and a response process.
You need an inventory before you can talk about protection.
Akamai is a cloud-based offering, suited to environments where traffic runs over the public internet. For the three scenarios below, a better-fitting route exists:
Selection comes down to three things: where traffic originates, where systems sit, and any data residency restrictions. Modules can be deployed in phases. The decision framework is laid out in WAF selection guide, see Web & API Protection for the full picture of options.
We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance services.
The most common way a WAF fails is not that it lets attacks through, but that it blocks your own customers the moment it's turned on. Teams often end up switching it to "log only, don't block", which defeats the purpose. False-positive tuning is therefore a core part of annual maintenance. See Services for the full delivery process.
The main task is a DNS cutover. Configuration and rules are built on Akamai first and verified with a test domain. Once confirmed, the production domain's DNS is switched, keeping a fallback to revert to the origin server at any time. The cutover itself does not require shutting down your server, but you should allow time for DNS propagation.
At launch, it always runs in monitoring mode first, collecting real traffic for a period before blocking is enabled step by step. False-positive tuning is a standing item in annual maintenance.
The security product line (AAP, Prolexic, API Security, and so on) is quote-based; the vendor's website does not publish prices. Three factors commonly drive pricing: the number of hostnames or domains protected, traffic volume, and which modules are enabled. Akamai Cloud (formerly Linode) is the exception, with published list prices on the vendor's site that you can check yourself. This website does not list prices; quotes are calculated against actual specifications. Send us your domain count and a rough monthly traffic estimate and we can respond.
Akamai's API security product line was formed through two acquisitions in 2023 and 2024 (the latter being Noname Security); its current official name is Akamai API Security. Pre-acquisition names on older documents or quotes refer to the same product line. Use the current name for purchasing.
We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance. This website refers to Akamai product names in text only, does not use its graphic trademarks, and this content is not authorized, sponsored, or endorsed by Akamai.
Want to know whether your site should use a cloud WAF or a solution in your own server room?
See the WAF solution WAF selection guideLeave your contact details and a description of your needs, and an engineer will follow up to help assess architecture planning, deployment approach, and the scope of annual maintenance.