ModSecurity
- Company typePrivate
- Founded2024
- HeadquartersSaint-cloud, France
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
ModSecurity firmographics
Firmographics- Name
- ModSecurity
- Legal name
- OWASP ModSecurity Project
- Website
- https://modsecurity.org
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Ownership category
- akta.pro rank
ModSecurity industry classification
Industry- Product category
- Web Application Firewall (WAF)
- NAICS
- Computer Systems Design and Related Services (54151), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (518)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Web Application Security (WAF, RASP) (HDADACAA)
- akta.pro secondary industries
- Web Application Firewall (WAF) Appliances (HDAFAFAJ), Cloud Network Security (Microsegmentation, Cloud Firewall, WAF, DDoS) (HDABAHAJ), Web Application Firewall (WAF) & Bot Management (ADC‑Integrated) (HDAFAHAG), API Security & Service-to-Service Security (mTLS, Service Mesh Security) (HDABAHAN)
Keywords
Where ModSecurity is headquartered
LocationHeadquarters
- HQ city
- Saint-cloud
- HQ country
- France
- HQ region
- Europe
Markets served
ModSecurity business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Operations, Others
Revenue model
- Open Source Distribution: ModSecurity is an open source project distributed freely under the Apache License. The project does not generate direct revenue but operates as a volunteer-driven open-source initiative under OWASP Foundation. The project accepts sponsorships to support activities like summits, hackathons, and conference speaking.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels7 records
ModSecurity product offering
Product offeringCore offering
ModSecurity is an open-source, cross-platform Web Application Firewall (WAF) module that provides real-time application security monitoring, HTTP traffic logging, passive security assessment, and web application hardening. Distributed free of charge under the Apache License, it is available in two actively maintained versions—mod_security2 (Apache module) and libmodsecurity3 (cross-platform C++ library)—and integrates natively with Apache, Nginx, and IIS web servers. It is used by businesses, government organizations, ISPs, and commercial WAF vendors on millions of domains worldwide.
Product overview
ModSecurity is an open source Web Application Firewall (WAF) available in two versions: libmodsecurity3 (v3) is a cross-platform C++ library, and mod_security2 (v2) is an Apache module. Both versions enable real-time application security monitoring, HTTP traffic logging, passive security assessment, and web application hardening. The ModSecurity-nginx connector enables the v3 library to work with Nginx servers. The product works alongside OWASP CRS (Core Rule Set), the dominant WAF rule set, to provide comprehensive protection against HTTP attacks. The engine provides a powerful rules language and API for implementing custom protections.
Differentiator
Problem solved
Functional benefit
Brands
- libmodsecurity3: Cross-platform WAF library supporting Apache, Nginx, and IIS web servers
- mod_security2
- ModSecurity-nginx connector
Products and services
- ModSecurity (libmodsecurity3) An open source, cross-platform C++ Web Application Firewall (WAF) library, known as the 'Swiss Army Knife' of WAFs. It enables web application defenders to gain visibility into HTTP(S) traffic and provides a powerful rules language and API to implement advanced protections, including real-time application security monitoring, access control, HTTP traffic logging, passive security assessment, and web application hardening. Supports Apache, Nginx (via connector), and IIS.
- mod_security2 The Apache-specific WAF module version of ModSecurity (v2.9.x line). An open source WAF engine installed as a module inside Apache HTTP Server for real-time application security monitoring, access control, HTTP traffic logging, and web application hardening.
- ModSecurity-nginx connector A standalone connector product that enables ModSecurity (libmodsecurity3) to work with the Nginx web server. Version 1.0.4 adds Windows port support, a GitHub CI workflow, a fix for recovery context after internal redirect, and corrected hostname handling in nginx logs.
- OWASP Core Rule Set (CRS) The dominant WAF rule set developed by OWASP, used in conjunction with the ModSecurity engine to inspect web application requests for various attacks and block malicious traffic. Provides comprehensive generic attack detection rules that complement ModSecurity's rules language and API.
Companies that use ModSecurity
Customer profileSegments4 records
Ideal customer profiles4 records
ModSecurity technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
Feature4 records
ModSecurity partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- OWASP FoundationcoreOWASP Foundation took custodianship of ModSecurity in January 2024, providing holistic oversight of the project. This joined ModSecurity WAF with the OWASP Core Rule Set (CRS), already under OWASP's roof, enabling tighter integration between the core rule set and the underlying framework. OWASP's vast network of security experts and volunteers contributes to the project's core development.
Scale indicators3 records
Recent moves8 records
Expansion highlights5 records
ModSecurity competitors and assessment
Company assessmentBroad incumbents
- AWS WAF: Hyperscaler-managed WAF service tightly integrated with CloudFront, ALB, and API Gateway; competes with ModSecurity for application-layer protection of web workloads, especially for cloud-native and serverless architectures.
- Microsoft Azure Web Application Firewall: Cloud-managed WAF integrated with Azure Application Gateway and Front Door; competes with ModSecurity for Azure-hosted web application protection.
- Barracuda WAF: Long-standing commercial WAF appliance and virtual offering for enterprises; overlaps with ModSecurity in self-hosted WAF deployments where organizations want a supported appliance instead of an open-source engine.
- Akamai App & API Protector: Edge-based commercial WAF/API protection offering from a major CDN; competes with ModSecurity by bundling WAF into a managed CDN/security platform rather than self-hosted deployments.
- Cloudflare WAF: Edge-network WAF bundled with DDoS, bot management, and CDN; competes with ModSecurity by offering a managed, low-ops alternative for organizations that would otherwise deploy ModSecurity in front of their own web servers.
- NGINX App Protect (F5): Commercial WAF built on NGINX (originally derived from ModSecurity's nginx connector lineage), offering a hardened, supported WAF for enterprises — directly competing for the same nginx-based WAF deployments that ModSecurity serves via its open-source connector.
- Imperva WAF: Established commercial WAF vendor offering on-premises and cloud WAF, bot protection, and API security; competes for enterprise WAF workloads that ModSecurity open-source deployments also serve.
Direct peers
- OWASP Coraza: An open-source, Golang-based Web Application Firewall that explicitly positions itself as a ModSecurity alternative, supporting the OWASP CRS rule set and targeting the same self-hosted WAF use cases on Apache, Nginx, and IIS-class deployments.
Emerging players
- HAProxy Enterprise WAF: Commercial WAF built on HAProxy's load balancer; competes with ModSecurity for organizations deploying WAF alongside reverse proxies in self-hosted environments.
- Wallarm: Cloud-native API security and WAF platform focused on APIs and modern web apps; partially overlaps with ModSecurity on API and application-layer protection for cloud-native workloads.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks5 records
Key highlights5 records
Customer concentration
ModSecurity social profiles
Digital presenceModSecurity financial estimates
Financial estimateRevenue estimate
Valuation estimate
ModSecurity leadership team
Management profileNumber of profiles
ModSecurity funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ModSecurity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ModSecurity
What does ModSecurity do?
ModSecurity is an open-source, cross-platform Web Application Firewall (WAF) module that provides real-time application security monitoring, HTTP traffic logging, passive security assessment, and web application hardening. Distributed free of charge under the Apache License, it is available in two actively maintained versions—mod_security2 (Apache module) and libmodsecurity3 (cross-platform C++ library)—and integrates natively with Apache, Nginx, and IIS web servers. It is used by businesses, government organizations, ISPs, and commercial WAF vendors on millions of domains worldwide.
Is ModSecurity a public or private company?
ModSecurity is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was ModSecurity founded?
ModSecurity was founded in 2024. It employs 1 to 10 people.
Where is ModSecurity based?
ModSecurity is headquartered in Saint-cloud, France, in the Europe region.
How does ModSecurity make money?
One revenue line is on record: open Source Distribution.
Who are ModSecurity's main competitors?
Broad incumbents on record are AWS WAF, Microsoft Azure Web Application Firewall, Barracuda WAF, Akamai App & API Protector, Cloudflare WAF, NGINX App Protect (F5) and Imperva WAF. OWASP Coraza is listed as a direct peer. Emerging players are HAProxy Enterprise WAF and Wallarm.
Does ModSecurity have an API?
Yes. ModSecurity provides a rules language API that enables web application defenders to implement advanced protections. The C/C++ API has been extended with functions including setHostname()/msc_set_request_hostname(), msc_rules_error_cleanup(), and msc_intervention_cleanup(). Developer documentation is at github.com/owasp-modsecurity/ModSecurity/wiki.
What industry is ModSecurity in?
ModSecurity's product category is Web Application Firewall (WAF). Its primary akta.pro industry code is HDADACAA, Web Application Security (WAF, RASP), with a secondary code of HDAFAFAJ, Web Application Firewall (WAF) Appliances. Its NAICS code is 54151 and its SIC code is 7372.