Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Imperva Application Security Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 21, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.5
Cloudflare users experienced increased performance, security, and cost-effectiveness, leading to improved loyalty and revenue despite difficult ROI calculations.
Sentiment score
6.9
AWS WAF enhances security and cost efficiency by integrating with AWS, reducing the need for additional security personnel.
Sentiment score
6.3
Users report Imperva's significant ROI, citing cost recovery, DDoS protection, reduced cloud bills, and improved efficiency and compliance.
For the small project I was working on, using the basic tier provided a huge improvement at zero cost.
Security Specialist at a tech services company with 1,001-5,000 employees
In terms of return on investment with Cloudflare, it costs my time to set them up, but basically once they're set up, it's done.
Owner at Hga consulting
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
They know how much money they are losing while the system is down, so by increasing the possibility of not having a down website or web application, return on investment can be calculated easily.
Head of Sales Services Department at a comms service provider with 51-200 employees
 

Customer Service

Sentiment score
7.0
Cloudflare's customer service is quick, but technical support feedback is mixed, with improvement needed in responsiveness and detailed assistance.
Sentiment score
6.7
AWS WAF support receives mixed reviews, praised for responsiveness and expertise, yet criticized for cost and inconsistent communication.
Sentiment score
7.2
Imperva's customer service is praised for expertise but criticized for inconsistency, with recent improvements noted by some users.
Cloudflare does not offer hands-on technical support to fix customer problems but rather a self-service model.
Senior Consultant CDN at a comms service provider with 10,001+ employees
I would rate the technical support with Cloudflare as excellent every time I've had to call them.
Owner at Hga consulting
I have primarily worked not with the tool's customer support but with the product's sales engineers and technical sales engineers, who seem to know their stuff.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
Security Engineer at a computer software company with 1,001-5,000 employees
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
I would rate the technical support of Imperva DDoS as ten.
Head of Sales Services Department at a comms service provider with 51-200 employees
 

Scalability Issues

Sentiment score
8.1
Users praise Cloudflare for seamless scalability, effective traffic management, easy upgrades, and robust global infrastructure without disruptions.
Sentiment score
7.8
AWS WAF excels in scalability and auto-scaling, efficiently handling traffic for businesses of all sizes, though improvements are possible.
Sentiment score
7.9
Imperva Application Security Platform offers strong scalability and reliability, though costs and on-premises flexibility may present challenges.
It is a SaaS tool, but the fact that they have workloads deployed across the world proves that it is a highly scalable tool.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
The tool offers very good performance, even during high-traffic periods.
Engineer at SITMEXICO
I rate the solution’s scalability an eight out of ten.
Independent Consultant at Unaikui
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
99% of customers are using the cloud version of Imperva DDoS protection, so they just purchase the new license and scale as needed.
Head of Sales Services Department at a comms service provider with 51-200 employees
 

Stability Issues

Sentiment score
7.6
Cloudflare is highly rated for stability and uptime, with few past issues, especially on higher-tier plans.
Sentiment score
8.3
AWS WAF is highly rated for stability due to reliable performance, strong protection, and effective redundancy features.
Sentiment score
7.8
Users find Imperva Application Security Platform reliable and stable, rating its stability highly despite occasional minor issues.
I rate the solution’s stability an eight out of ten.
Independent Consultant at Unaikui
The service is very stable with no impacts during high-traffic periods.
Engineer at SITMEXICO
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
Security Engineer at a computer software company with 1,001-5,000 employees
We faced issues with AWS WAF when writing the custom rules.
Infrastructure Lead at Danat Fz LLC
The stability of Imperva DDoS is very good, as it seems they have a lot of servers around the world.
Head of Sales Services Department at a comms service provider with 51-200 employees
 

Room For Improvement

Enhancements needed in Cloudflare: analytics, CDN latency, API integration, user support, DNS, pricing, documentation, server coverage, WAF, and cache.
AWS WAF requires improved integration, usability, security features, and flexible pricing to better support global users and services.
Imperva needs UI improvements, competitive pricing, better integration, real-time analytics, and enhanced support for efficiency and transparency.
Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor.
Managed Services Manager at Adapture Technology Group
Areas like how assessment, discovery, and payload are dealt with and how it all comes into your organization can be considered when trying to make suggestions to Cloudflare for improvements.
Senior Cloud Solution Architect at Integrated Technology Solution Group (ITSG)
There are some performance considerations when it comes to dynamic content that involves fetching data from databases or using APIs.
Senior Solutions Architect at Think Power Solutions
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
Security Engineer at a computer software company with 1,001-5,000 employees
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
Infrastructure Lead at Danat Fz LLC
Features like bot protection or DDoS mitigation, available with other WAF vendors, do not come natively with AWS WAF.
Security Analyst at M2P Fintech
Maybe Imperva DDoS could use endpoints to get information about the attacks before they commence from the endpoint level or establish cooperation with endpoint vendors to share this information.
Head of Sales Services Department at a comms service provider with 51-200 employees
 

Setup Cost

Cloudflare offers scalable pricing, from free to enterprise plans, providing significant value especially for mid-sized companies.
AWS WAF offers cost-effective, pay-as-you-go pricing, starting at $5 monthly, valued for integration with AWS services.
The Imperva platform's pricing is competitive with advanced features, ranging from $5,000 to $10,000 annually and no setup costs.
I find it to be cheap.
Engineer at SITMEXICO
I rate the product’s pricing a five out of ten, where one is cheap, and ten is expensive.
Senior Solutions Architect at Think Power Solutions
The tool is a premium product, so it is very expensive.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
Security Engineer at a computer software company with 1,001-5,000 employees
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
Infrastructure Lead at Danat Fz LLC
I would rate the pricing of Imperva DDoS as five, where one is very cheap and ten is very expensive.
Head of Sales Services Department at a comms service provider with 51-200 employees
 

Valuable Features

Cloudflare enhances performance and security with CDN caching, DDoS protection, and an easy-to-use dashboard, benefiting many users.
AWS WAF offers threat blocking, scalability, automation, and seamless integration, enhancing security and performance with easy deployment and affordability.
Imperva's platform offers robust security features, user-friendly integration, real-time analytics, and scalability for diverse enterprise protection needs.
The most valuable features of the solution are performance and security.
Senior Cloud Solution Architect at Integrated Technology Solution Group (ITSG)
Techniques like minification and image compression reduce the size of assets, leading to better performance and faster user load times.
Senior Solutions Architect at Think Power Solutions
The solution has been able to compare it to the market, and I think the product has taken great strides in automating quite a bit of things, and they use a lot of AI.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
Infrastructure Lead at Danat Fz LLC
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
The cloud-native nature of AWS is crucial since most of our workload is in AWS, making AWS WAF native to Amazon Web Services.
Security Analyst at M2P Fintech
I have utilized Imperva's Intelligent Traffic Filtering feature. This feature helps me understand how the attack is progressing and what is happening inside the requests to our website.
Head of Sales Services Department at a comms service provider with 51-200 employees
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
77
Ranking in other categories
CDN (1st), WAN Optimization (4th), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (12th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
61
Ranking in other categories
Web Application Firewall (WAF) (3rd)
Imperva Application Securit...
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
133
Ranking in other categories
CDN (4th), Web Application Firewall (WAF) (4th), Distributed Denial-of-Service (DDoS) Protection (4th), Bot Management (1st), API Security (2nd)
 

Featured Reviews

HA
Owner at Hga consulting
Has helped manage client domains with streamlined access control and threat visibility
I don't know what areas could be improved with Cloudflare WAF; Cloudflare is constantly improving and adding features to their feature set. They're doing a good job, and as far as DNS and support for any domains that I create or my clients create, it's mandatory for me to make sure that they have Cloudflare as their DNS provider. The Cloudflare load balancing capability hasn't really helped in enhancing my website's uptime and resiliency because we don't really get that much traffic; it's mostly remote users, and web hosting is done by a web hosting service. It doesn't pay to try to host your own website.
Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
reviewer1247523 - PeerSpot reviewer
Head of Sales Services Department at a comms service provider with 51-200 employees
Solution ensures website availability and proactive threat mitigation
Over the seven years, the most valuable features of Imperva DDoS that I have found are related to DDoS attacks, which are a group of attacks, and not all of them can be resolved on the endpoint level before the website. Using the web firewall before the website is a common use case to protect against malicious requests to the website. I have utilized Imperva's Intelligent Traffic Filtering feature. This feature helps me understand how the attack is progressing and what is happening inside the requests to our website. It allows me to granularly grant or deny access to certain parts of our website. This helps when we know our customers and the types of requests that can be sent from them, enabling us to block some malicious requests. Imperva DDoS has User Behavior Analytics and Threat Intelligence on its board, and this helps us to be protected proactively. Imperva DDoS connects to its database of threats, storing whole information about attacks all over the world in one simple engine. Everyone can use this feature, which can connect to this engine and get information about what is going on at the world level. That is the way to be protected at the company's level. The integration capabilities of Imperva DDoS are very easy and simple. We can run it in 2 hours.
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
879,455 professionals have used our research since 2012.
 

Comparison Review

it_user68487 - PeerSpot reviewer
Security Expert with 51-200 employees
Nov 6, 2013
CloudFlare vs Incapsula: Web Application Firewall
CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web…
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
9%
Government
6%
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
9%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise8
Large Enterprise25
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise26
By reviewers
Company SizeCount
Small Business83
Midsize Enterprise25
Large Enterprise61
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot mana...
What do you like most about Imperva Incapsula?
We use Imperva DDoS to stop DDoS attacks and reduce the amount of unwanted queries against web services or web scraping.
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provi...
 

Also Known As

Cloudflare DNS
AWS Web Application Firewall
Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
eVitamins, 9Splay, Senao International
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Find out what your peers are saying about AWS WAF vs. Imperva Application Security Platform and other solutions. Updated: December 2025.
879,455 professionals have used our research since 2012.