Try our new research platform with insights from 80,000+ expert users

Fastly vs Imperva Application Security Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 21, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Ranking in CDN
1st
Ranking in Distributed Denial-of-Service (DDoS) Protection
2nd
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
78
Ranking in other categories
WAN Optimization (4th), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (10th)
Fastly
Ranking in CDN
7th
Ranking in Distributed Denial-of-Service (DDoS) Protection
10th
Average Rating
8.8
Reviews Sentiment
6.3
Number of Reviews
9
Ranking in other categories
Web Application Firewall (WAF) (23rd)
Imperva Application Securit...
Ranking in CDN
3rd
Ranking in Distributed Denial-of-Service (DDoS) Protection
4th
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
135
Ranking in other categories
Web Application Firewall (WAF) (3rd), Bot Management (1st), API Security (2nd)
 

Mindshare comparison

As of March 2026, in the Distributed Denial-of-Service (DDoS) Protection category, the mindshare of Cloudflare is 16.2%, down from 18.2% compared to the previous year. The mindshare of Fastly is 3.2%, up from 2.3% compared to the previous year. The mindshare of Imperva Application Security Platform is 8.5%, up from 7.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Cloudflare16.2%
Imperva Application Security Platform8.5%
Fastly3.2%
Other72.1%
Distributed Denial-of-Service (DDoS) Protection
 

Featured Reviews

M.A. Faisal - PeerSpot reviewer
General Manager at bKash Limited
Advanced protection has secured critical web workloads and provides clear traffic visibility
From a security perspective, there remains a security loophole, as some browsers in the market can bypass the Turnstile solution, which requires approximately 40 seconds to do so. From a performance perspective, this is acceptable. We also tried Google reCAPTCHA, and that can also be bypassed. From a security perspective, I would say neither solution is completely secured. Regarding uptime, we have faced a couple of incidents due to Cloudflare in recent years, so I cannot say we receive 100% uptime for our region. We sometimes face challenges, including downtime and other issues. As a result, we are not receiving 100% uptime from Cloudflare's solution. Since most of our customers are in this region, we need alternatives. We need something more competitive than Cloudflare. Unfortunately, in Bangladesh, Cloudflare has three points of presence already, and we cannot find any other solution provider in Bangladesh as an alternative, which presents another challenge. Competitor solutions have more attack signatures, which ensure better security compared to Cloudflare's predefined configurations. Customers do not have options to modify any configuration parameters in Cloudflare, whereas other competitor solutions, such as F5 Distributed Cloud, allow customers to tune configurations according to their requirements. Cloudflare could improve in this area. Additionally, regarding visibility, Cloudflare has static visibility, but they could adopt dynamic graph features for their customers.
PP
Technical support engineer at Adobe
Optimized ecommerce performance and improved access control through image handling and IP filtering
I believe that Fastly should provide guidelines for their WAF blocking rules. It should be public what the rules are that are blocking their contents. I believe Fastly should provide regional IP addresses instead of POP IPs. Fastly should provide features similar to Cloudflare regarding a block list. Additionally, a POP address should be there with a wide range of IP addresses provided, public static IP addresses, so customers can integrate egress IPs. Fastly should provide WebP image processing on the backend instead of on the fly. It would be a very useful feature to avoid unnecessary time for browser to browser and local cookies. I believe that Fastly service has a few gaps. We are not getting quick responses from Fastly technical support engineers. Sometimes they depend on their D3 developers. There should be transparency.
reviewer1247523 - PeerSpot reviewer
Head of Sales Services Department at a comms service provider with 51-200 employees
Solution ensures website availability and proactive threat mitigation
Over the seven years, the most valuable features of Imperva DDoS that I have found are related to DDoS attacks, which are a group of attacks, and not all of them can be resolved on the endpoint level before the website. Using the web firewall before the website is a common use case to protect against malicious requests to the website. I have utilized Imperva's Intelligent Traffic Filtering feature. This feature helps me understand how the attack is progressing and what is happening inside the requests to our website. It allows me to granularly grant or deny access to certain parts of our website. This helps when we know our customers and the types of requests that can be sent from them, enabling us to block some malicious requests. Imperva DDoS has User Behavior Analytics and Threat Intelligence on its board, and this helps us to be protected proactively. Imperva DDoS connects to its database of threats, storing whole information about attacks all over the world in one simple engine. Everyone can use this feature, which can connect to this engine and get information about what is going on at the world level. That is the way to be protected at the company's level. The integration capabilities of Imperva DDoS are very easy and simple. We can run it in 2 hours.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Even when there is a high load on our servers, Cloudflare is able to cache the data and serve it to users, ensuring they can still access the website."
"Many websites require an SSL certificate because they sell stuff and want SSL. Cloudflare comes with an SSL certificate built in. It's automatic. You sign yourself up for Cloudflare, and an SSL certificate automatically protects your website. You don't necessarily need a certificate if you have a connection between your website and your host, the server, Cloudflare, and the host."
"The solution automatically detects and responds to certain types of traffic based on geolocation."
"From what I've seen so far, there are no negatives to report as of yet"
"I get a lot of value from Cloudflare's API because it enables you to build a separate environment inside the solution. You can create a domain for performing test requests before you move to the production environment and connect various domains."
"The solution is stable, and the DNS servers are simple to use."
"The UI is good."
"The most valuable feature is its usability."
"The product helps our organization to access sites located in different regions quickly."
"Support is good; the product works as advertised. We have a Slack connection with them. So we can basically ask for help, live, engage, and ring when they respond. Very quickly."
"Fastly uses configuration versioning, where you can deploy a new version in less than one minute."
"Compute@Edge features are valuable to me."
"Fastly combines both the CDN side and the Signal Sciences next-generation WAF, which is closely integrated with the CDN, allowing us to use both products seamlessly."
"Rate limiting is a good feature that protects from volumetric attacks."
"The product's initial setup phase is straightforward."
"Its initial setup process is straightforward."
"Learning mode and custom policies are helpful features."
"Imperva has a complete picture of how the applications are utilizing it. It is handy. DDoS is good. It has an internally managed database. It is very easy to integrate. We have integrated it with SIEM services."
"On the real time, you can see live traffic, which is flowing into our website."
"Integration with IBM AS/400 and Db2 is okay."
"Imperva monitors all traffic, even customer access, to the web application. Then, Imperva uses features like signatures to identify attacks like cross-site scripting or SQL injection."
"The solution can be configured in just a couple of minutes."
"One good thing about Imperva Web Application Firewall is it can be on the cloud and also it can be on-premise."
"The most valuable feature of Imperva DDoS is to make our website available for our customers' requests 24 hours a day."
 

Cons

"It would be helpful if the solution could continue evolving to compete with the other solutions on the market."
"The solution could work at being less expensive. It costs a lot to use it."
"They lack a good way to manage DNS as a company, since everything is relegated to single account logins until you get to the higher levels. They have come out with a paid feature to remedy this, but I have not had a chance to fully review it yet to know if it fixes the access problem."
"An integrated SSO feature would be useful for Cloudflare DNS."
"Integration involving API with other products could be more user-friendly."
"Cloudflare does not have an on-premise solution. If they had different approaches they could be better suited to accommodate more customers, such as on-premise and hybrid deployments. For example, hybrid deployments would be useful where you could move the traffic from the enterprise to the cloud."
"The product support needs to be accessible from more places, a wider area of coverage."
"It should be easier to collect the logs with companies like Sumo. However, based on my discussions with the salespeople, I understand that's how they make their money. With the enterprise product, they want people doing those kinds of enterprise features to do the logging. They want them to pay a lot of money, and that's where I have an issue with them. That should be a default. You should be able to get the log no matter what. The logging should be universal."
"The product should provide improved bot detection and management."
"The solution's pricing could be better."
"Stronger analytics would be helpful, like showing configurations that haven't served a certain amount of traffic in a while. With many properties, things can get lost track of - duplicates or unused configurations not properly decommissioned."
"Fastly's customer service area needs improvement."
"It is missing a "staging" platform to deploy a test configuration with all of the real settings, which would allow us to properly test before putting it into production."
"What I don't like about Fastly is that they charge a heavy price."
"We are not getting quick responses from Fastly technical support engineers. Sometimes they depend on their D3 developers."
"Support is not that great."
"In the past, I have bugs on the WAF. I've contacted Imperva about them. Future releases should be less buggy."
"Sometimes, it takes a bit of time for the technical staff of the solution to get back to our company with a resolution for our problems."
"There could be some limitations that from the converged infrastructure perspective: when you want to converge with everything and you want Imperva to get there easily because it's not a cloud component. For example, when you want to build servers and you're using OneView to manage your software-defined networks, implementing Imperva right away is not that simple. But if you're doing just a simple cloud infrastructure with servers in there, you're good to go. Also, we are not able, with Imperva, to block by signatures. Imperva by itself needs to be complemented with another service to do URL filtering."
"I loved the approach of the cloud. The cloud has a lot of new features, like advanced web protection and DDoS protection. If those could also be on-boarded onto the on-prem versions, that would be ideal. They need to pay attention to both deployment options and not just favor one."
"It's a complicated tool to keep."
"I am looking for more data enrichment. We should have the ability to add our own custom data to the system, to the live traffic."
"The signature updates could be faster. Sometimes we have to upload signatures to the Imperva portal for checking and analysis before we can use them."
"The salespeople tend to exaggerate its capabilities, which can cost you money if you don't verify the information."
 

Pricing and Cost Advice

"We are using the free tier of the solution."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"We don't have any issues with the price."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"There are no additional costs beyond the standard licensing fees."
"The price is reasonable."
"We are using the free version."
"You need to pay a premium price for the tool."
"It is an expensive solution."
"Fastly is less expensive than one of its competitors."
"The pricing has been very competitive."
"The solution is cheaper than other products in the market."
"In my opinion, Fastly is priced competitively."
"I've generally found Fastly to be very competitive in pricing, especially around Compute@Edge."
"I rate the product price a four on a scale of one to ten, where one is a low price, and ten is a high price."
"There is a license or subscription renewal that our customers pay."
"It is a very expensive solution. The price is very high. A lot of customers tell us that they would love to use Imperva more. I have some customers who have 50 websites, but they have only 10 websites on Imperva because of the price. They would love to have all their websites running through Imperva, but they can't. They have to choose the more critical websites to protect because the price is very high. It is a very good product, but it is too expensive. If you buy a plan for 20 megabytes and you don't consume all of your 20 megabytes, it is okay, but if you consume more, you are charged for the superior traffic."
"The price is high compared to other solutions like FortiWeb."
"The license is on a yearly basis."
"The tool is expensive."
"The cost is on par with other solutions such as Cloudflare and Akamai."
"We are satisfied with the pricing."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
884,122 professionals have used our research since 2012.
 

Comparison Review

it_user68487 - PeerSpot reviewer
Security Expert with 51-200 employees
Nov 6, 2013
CloudFlare vs Incapsula: Web Application Firewall
CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web…
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
8%
Comms Service Provider
11%
Financial Services Firm
10%
Computer Software Company
10%
Manufacturing Company
8%
Financial Services Firm
12%
Computer Software Company
9%
Manufacturing Company
9%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise8
Large Enterprise26
By reviewers
Company SizeCount
Small Business5
Large Enterprise5
By reviewers
Company SizeCount
Small Business84
Midsize Enterprise25
Large Enterprise62
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What needs improvement with Fastly?
I believe that Fastly should provide guidelines for their WAF blocking rules. It should be public what the rules are ...
What is your primary use case for Fastly?
I am using Fastly in the Adobe Commerce Cloud project. In this project, it is working as a reverse proxy for CDN and ...
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot mana...
What do you like most about Imperva Incapsula?
We use Imperva DDoS to stop DDoS attacks and reduce the amount of unwanted queries against web services or web scraping.
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provi...
 

Also Known As

Cloudflare DNS
No data available
Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Twitter, Airbnb, Alaska Airlines, Pinterest, Vimeo, The Guardian, The New York Times, Ticketmaster, The Drupal Association, Opera, about.com, imgur, Etsy, Foursquare, GitHub, New Relic, shopify, Shazam, Firebase
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Find out what your peers are saying about Fastly vs. Imperva Application Security Platform and other solutions. Updated: March 2026.
884,122 professionals have used our research since 2012.