Akamai cloud application and API protection

No hardware to buy, no server room to visit. Point your domain's DNS to Akamai, and attacks are stopped before they reach your server. GN-AI provides planning, deployment, policy tuning, and annual maintenance.

What is Akamai

Akamai Technologies was founded in 1998, is headquartered in Cambridge, Massachusetts, and is listed on NASDAQ (ticker AKAM). It started as a CDN (Content Delivery Network) provider and invented the category. A CDN puts website content in the data center closest to the user, making the site faster. Over the past decade its focus has shifted to security: 2025 security revenue was USD 2.243 billion, now over half of total company revenue.

Point your domain (DNS) to Akamai, and before anyone in the world connects to your site, traffic passes through Akamai's data centers first. Attacks are cleaned out there. Only clean, accelerated traffic reaches your own server.

So it is a different procurement model from buying a box and putting it in your server room. Traffic runs over Akamai's global network, so you don't need to scale your own hardware to absorb peak load or attack volume. For scenarios where conditions differ, see "Matching the option to the scenario" below.

Main products

Names follow the vendor's current official naming. Each entry includes a plain-language explanation and "who needs this".

App & API Protector(AAP)

WAF, application-layer DDoS, bot management, API discovery, and sensitive data protection, bundled into one product. WAF stands for web application firewall, blocking attacks like SQL injection and XSS that a normal firewall cannot recognize. An adaptive security engine automatically fine-tunes rules to reduce false positives.

Who needs this: companies with a public-facing website or app backend that handle payments or member data.

WAFL7 DDoS
Prolexic

Handles attacks that try to saturate the whole network link. It works by using BGP to route the entire IP block to a scrubbing center, filtering the traffic, then sending it back; on-premises and hybrid versions are also available.

Who needs this: companies that need to protect an entire server room or IP block, including non-website services such as mail and VPN.

L3/L4 scrubbingBGP diversion
Bot Manager (with Account Protector, Content Protector)

Bot Manager tells whether a visitor is a human or a script: it lets Google's crawler through and blocks ticket-scalping bots and price-scraping bots. The same family includes two separate products: Account Protector, against account takeover and credential-stuffing attacks, and Content Protector, against bulk content scraping. The three are licensed separately and must be purchased individually.

Who needs this: eCommerce, ticketing, gaming, media, and any site with a login page.

Bot ScoreAccount protection
Akamai API Security

First discovers every API, including ones nobody remembers and ones that should have been shut down long ago. Then runs security testing, behavior monitoring, and compliance mapping. The vendor states it is platform-agnostic, covering multi-cloud, hybrid cloud, and on-premises.

Who needs this: financial, eCommerce, and logistics companies that expose APIs to apps, partners, or third parties.

API inventoryOWASP API Top 10
Client-Side Protection & Compliance

Protects against a specific case: the website itself is not hacked, but a third-party JavaScript file it loads has been tampered with to skim card numbers on the checkout page. Maps directly to PCI DSS 4.0 requirements 6.4.3 and 11.6.1.

Who needs this: eCommerce, booking, ticketing, and payment platforms that take credit cards directly on their own site.

PCI DSS 4.0JS monitoring
Akamai Guardicore Segmentation

The products above defend against attacks coming from outside; this one defends against someone who is already inside moving around freely, which is how ransomware spreads across an internal network. It can be deployed with an agent or agentless, so there is no need to re-plan your VLANs.

Who needs this: mid-size to large companies with an existing server room that don't want a major architecture overhaul.

Lateral-movement blockingZero trust
EAA/SIA/Akamai MFA

Enterprise Application Access (EAA) replaces a traditional VPN, giving employees access only to the specific system they need. Secure Internet Access Enterprise (SIA) blocks phishing sites at the DNS and network layer. Akamai MFA is multi-factor authentication.

Who needs this: companies with remote work or outsourced staff that want to retire an old VPN.

Replaces VPNMFA
Akamai Cloud (formerly Linode)

Akamai's own public cloud, launched after it acquired Linode in March 2022. It offers compute instances, a managed Kubernetes service, object and block storage, and AI inference nodes. Its pitch is transparent pricing and low egress fees.

Who needs this: companies sensitive to cloud bill fluctuations that want an option alongside their own server room.

IaaSKubernetes
Akamai Workforce Protector (formerly LayerX)

A separate new product launched after Akamai completed its acquisition of LayerX in July 2026: it governs what data employees send to generative AI, blocks overly permissive browser extensions, and controls uploads and downloads.

Who needs this: companies that allow staff to use generative AI but need to control data leakage.
Note: it is a standalone product, not part of the EAA/SIA/MFA family.

AI usage governanceDLP

Akamai's platform architecture

Distributed edge network
Nodes sit inside internet service provider networks around the world. Traffic is processed close to the visitor.
Anycast scrubbing centers
Anycast spreads attack traffic across scrubbing nodes worldwide, so it never concentrates on a single entry point.
Dedicated DDoS defense capacity
Defense bandwidth is kept separate from regular content delivery, dedicated to absorbing high-volume attacks.
Vendor security operations command center
Akamai's own SOCC team monitors platform status and publishes threat intelligence.
Platform availability terms
Availability terms Akamai states for its platform; the actual terms are governed by the vendor contract.
The above describes the architecture of the Akamai platform itself, not GN-AI's service scope. GN-AI provides planning, build, migration, training, and annual maintenance (business-hours support).
GN-AI Information Consulting - reference notes

Who this suits

If two or more of the following apply, cloud WAF is usually worth serious evaluation.

High public-facing traffic, open to the general public

Visitor sources cannot be whitelisted in advance.

High cost of downtime

The loss from an hour of downtime exceeds the annual cost of protection.

Have overseas users

The same budget covers both acceleration and protection.

Need to pass PCI DSS 4.0

Requirements 6.4.3 and 11.6.1 are mandatory audit items.

Have already been hit by DDoS or scraping

What you need is capacity and a response process.

Can't say how many APIs you actually have

You need an inventory before you can talk about protection.

Matching the option to the scenario

Akamai is a cloud-based offering, suited to environments where traffic runs over the public internet. For the three scenarios below, a better-fitting route exists:

  • Traffic must stay within national borders. Some government, financial, and healthcare systems are required by regulation to keep traffic off overseas networks. Two routes fit here. One is App & API Protector Hybrid, applying the same policy set to on-premises, hybrid cloud, or an existing CDN environment; the other is an on-premises option, such as the WAF module on F5® BIG-IP®, or Fortinet FortiWeb in hardware or virtual machine form.
  • The main goal is faster site speed. The fit here is CDN caching strategy and front-end optimization. You can tune these two first, and expand into a full WAAP platform later once you have security needs.
  • A single brochure site with no payment or member data yet. You can start with basic protection and CDN, then add modules once you introduce payments, membership, or an API.

Selection comes down to three things: where traffic originates, where systems sit, and any data residency restrictions. Modules can be deployed in phases. The decision framework is laid out in WAF selection guide, see Web & API Protection for the full picture of options.

Scope of services

We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance services.

1
Requirements interviews and architecture planning
Site survey, requirements interviews, architecture design, selection recommendations, POC, and TCO estimation. Three things are confirmed first: traffic volume, the number of domains and hostnames to protect, and any data residency restrictions. Then we decide how to combine the modules.
2
On-site build and installation
Origin server and certificate setup, rule creation, DNS cutover planning, and go-live switchover. Where server room equipment is also involved, this includes rack mounting, cabling, equipment installation, and configuration tuning.
3
System migration
Migrating policies and settings from an existing CDN or WAF. Existing rules are inventoried and mapped one by one, to avoid under-blocking or over-blocking after the move.
4
Training and knowledge transfer
Training on operating the management console, reading reports, and the internal process for handling false positives, plus handover of configuration and architecture documentation.
5
Annual maintenance contract (business-hours support)
WAF policy tuning and false-positive tuning: real traffic is first collected in monitoring mode, each triggered rule is reviewed individually, and a rule is only allowed through once confirmed as a false positive, with records kept for audit. Also includes regression testing after rule updates, regular health checks and report reviews, and handling vendor renewals.

The most common way a WAF fails is not that it lets attacks through, but that it blocks your own customers the moment it's turned on. Teams often end up switching it to "log only, don't block", which defeats the purpose. False-positive tuning is therefore a core part of annual maintenance. See Services for the full delivery process.

FAQ

Does deployment require downtime?

The main task is a DNS cutover. Configuration and rules are built on Akamai first and verified with a test domain. Once confirmed, the production domain's DNS is switched, keeping a fallback to revert to the origin server at any time. The cutover itself does not require shutting down your server, but you should allow time for DNS propagation.

Will it block legitimate customers?

At launch, it always runs in monitoring mode first, collecting real traffic for a period before blocking is enabled step by step. False-positive tuning is a standing item in annual maintenance.

How is pricing calculated?

The security product line (AAP, Prolexic, API Security, and so on) is quote-based; the vendor's website does not publish prices. Three factors commonly drive pricing: the number of hostnames or domains protected, traffic volume, and which modules are enabled. Akamai Cloud (formerly Linode) is the exception, with published list prices on the vendor's site that you can check yourself. This website does not list prices; quotes are calculated against actual specifications. Send us your domain count and a rough monthly traffic estimate and we can respond.

Older material shows a different name for the API security product?

Akamai's API security product line was formed through two acquisitions in 2023 and 2024 (the latter being Noname Security); its current official name is Akamai API Security. Pre-acquisition names on older documents or quotes refer to the same product line. Use the current name for purchasing.

What is your relationship with Akamai?

We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance. This website refers to Akamai product names in text only, does not use its graphic trademarks, and this content is not authorized, sponsored, or endorsed by Akamai.

Want to know whether your site should use a cloud WAF or a solution in your own server room?

See the WAF solution WAF selection guide

Contact us about Akamai deployment and maintenance

Leave your contact details and a description of your needs, and an engineer will follow up to help assess architecture planning, deployment approach, and the scope of annual maintenance.

Send an enquiry
LINE Ask us on LINE