We are an implementer for clients within the financial services looking to protect their internet, mobile devices, etc.
Chief Information Security Consultant at V-Tech
Good WAF solution with many antivirus features
Pros and Cons
- "There are a number of features that are valuable such as the account takeover and various antivirus features."
- "It would be nice to have more security control over mobile applications so I would suggest adding more mobile security features. It would also be beneficial to see improvements in regards to interface bandwidth performance, CPU time, and RAM size. Learning capability of the device is quite weak."
What is our primary use case?
What is most valuable?
There are a number of features that are valuable such as the account takeover and various antivirus features.
What needs improvement?
It would be nice to have more security control over mobile applications so I would suggest adding more mobile security features.
It would also be beneficial to see improvements in regards to interface bandwidth performance, CPU time, and RAM size.
Learning capability of the device is quite weak.
For how long have I used the solution?
I have been using the solution for four years.
Buyer's Guide
Imperva Application Security Platform
March 2026
Learn what your peers think about Imperva Application Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,933 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable and has strong performance.
What do I think about the scalability of the solution?
The solution is scalable and is currently being met with high demand on the clients side.
How are customer service and support?
Support response time to a given problem could be much faster. This may be due to time zone limitations as well as the amount of time it takes the representative to understand the scope of the issue.
How was the initial setup?
Initial installation requires a lot of customizations that depend on the environment and use case of the client. For clients looking to maximize all policies, settings, and features provided, their setup could take up to one year.
Two engineers are required for deployment.
What's my experience with pricing, setup cost, and licensing?
Licensing can range from one to twenty thousand dollars annually. Additionally, some features, including software support, require an annual subscription as well.
What other advice do I have?
This is a good WAF solution that I would rate a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
GA Consultant Cyber Security at a tech services company with 51-200 employees
Suits large enterprises, supports different application sources, and provides tight control
Pros and Cons
- "Configuration for different application sources is most valuable. We can segregate the traffic that an application is carrying and identify the sizing in Imperva."
- "It should be more user-friendly. Like other web solutions, it would be helpful to be able to easily do policy configuration and identification inside the application. Understanding the in-depth configuration of a policy is somewhat difficult for an engineer, and they can improve that."
What is our primary use case?
We have an Akamai cloud-based solution for it. We have an in-house customer, and they have their own Akamai cloud for WAF. As a solution provider, we are working with their private Akamai WAF.
What is most valuable?
Configuration for different application sources is most valuable. We can segregate the traffic that an application is carrying and identify the sizing in Imperva.
It is quite proficient in terms of logs reports, and it provides tight control for policy configuration. So, there can't be any unwanted applications on the internal LAN site. It is quite restrictive, which is a plus point. The sizing of an application is quite easy to understand while we are configuring and deploying Imperva.
What needs improvement?
It should be more user-friendly. Like other web solutions, it would be helpful to be able to easily do policy configuration and identification inside the application. Understanding the in-depth configuration of a policy is somewhat difficult for an engineer, and they can improve that.
For how long have I used the solution?
I have about two to three years of experience with Imperva. I'm working as a GA consultant for cybersecurity and information security. I'm working on different security solutions such as WAF, IAM, DDoS, Azure firewall proxy, and antivirus. I work with different customers, and I also do the architecture review or assessment.
What do I think about the stability of the solution?
Its stability is quite good. It is not at all an issue.
It is also quite good performance-wise. We are confident about its performance.
What do I think about the scalability of the solution?
It is for large-scale enterprises where the traffic is huge, and there are many internet-facing applications, which is a plus point of Imperva.
We don't have the HA mode for the respective solution in Imperva, which has to be there when we have the DC and DR locations. We can activate only one solution at DC, but while we are conducting the drills between DC and DR, it is quite difficult to import all the configurations at the DR location in Imperva. It takes time.
How are customer service and support?
Their support is good. It is not an issue. Whenever we have any questions or concerns, we're getting an appropriate solution for our queries.
Some of the clients have had direct support from Imperva, and some of the clients had a third-party vendor. We also get support from a local Imperva employee. When I was working for a bank, there was good support from this person who was working with Imperva.
How was the initial setup?
The support for the setup is very good from the provider, but it can be difficult for an engineer to have an in-depth understanding of the configuration of a policy for an application.
What other advice do I have?
I would rate it an eight out of 10.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Imperva Application Security Platform
March 2026
Learn what your peers think about Imperva Application Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,933 professionals have used our research since 2012.
IT Solutions Senior Manager at a media company with 501-1,000 employees
Helpful support, good licensing model, and fits within our budget
Pros and Cons
- "It fits our requirements, as well as our budget."
- "Some maintenance must be performed by our IT team."
What is our primary use case?
We use this product as our Web Application Firewall. It provides web-based protection for us. Our requirements are not very complex.
What needs improvement?
Some maintenance must be performed by our IT team.
For how long have I used the solution?
We have been working with Imperva Incapsula for two years.
What do I think about the stability of the solution?
The stability is okay. We use it extensively, on a daily basis. The firewall operates 24 hours per day.
What do I think about the scalability of the solution?
We have approximately 500 employees that are protected with this product.
How are customer service and support?
We have not had any problems with their technical support.
Which solution did I use previously and why did I switch?
We did not use another Web Application Firewall before Imperva.
How was the initial setup?
Incapsula is not a difficult product to deploy.
What about the implementation team?
The vendor assisted us with the deployment.
We have an IT support team that is responsible for maintenance.
What's my experience with pricing, setup cost, and licensing?
We have a yearly contract and I am happy with the pricing. Imperva charges us based on bandwidth, which is better than other vendors that charge us according to data transfer. In these cases, our costs are quite high.
Outside of our package, there are no additional fees.
What other advice do I have?
Overall, I am really happy with this solution. This includes the features and capabilities, as well as the cost. It fits our requirements, as well as our budget.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Architect at a security firm with 51-200 employees
Features that outperform it's competitors, easy to scale, reliable, and responsive support
Pros and Cons
- "It's very pretty easy to onboard the URL."
- "It would be beneficial to include vulnerability management in the solution, similar to what they have for their on-premise solution."
What is our primary use case?
We offer implementation services for our customers.
Most customers use Imperva Incapsula to protect themselves from WAF attacks. If they need an application load balancing, whether it is on a single data center or if they have a B2B extension. Also, if they need protection from the bots. Imperva has all of those functionalities.
What is most valuable?
It's very pretty easy to onboard the URL. One of the unique features included with Imperva is its advanced bot protection. In addition the base licensing modules with most of the features.
In terms of features, Imperva is quite good; it outperforms its competitors.
What needs improvement?
Pricing could be more competitive.
It would be beneficial to include vulnerability management in the solution, similar to what they have for their on-premise solution.
For how long have I used the solution?
I have been working with Imperva Incapsula for more than three years.
I have been using the latest update.
What do I think about the stability of the solution?
The stability is quite good. It has an uptime of 99%. None of our customers have complained about its uptime and its availability.
What do I think about the scalability of the solution?
The majority of our customers are enterprise businesses, with some SMB, but it depends on their budget, as well as their needs, and whether it is for security or compliance purposes.
Imperva is quite expensive for organizations that use it for compliance purposes. Other WAP solutions, such as Fortinet or Barracuda, which are slightly less expensive than Imperva, will be considered.
Imperva Incapsula is easy to scale.
How are customer service and support?
I believe that Technical support is 24/7. They are also very quick to respond via email.
Which solution did I use previously and why did I switch?
We work with all of the Imperva solutions from the database, monitoring tools, and the web applications firewall.
How was the initial setup?
The initial setup Is quite simple and straightforward. We only have seven steps to follow. It's a very simple and straightforward process.
If the customer agrees to a DNS sense, it will take no more than 10 to 15 minutes.
Imperva is responsible for maintenance.
What's my experience with pricing, setup cost, and licensing?
Incapsula is a SaaS (software-as-a-service) provider. Anyone can do the applications, but you must subscribe to the service.
Pricing is a challenge for most of our customers.
What other advice do I have?
I cannot provide a comparison because I have not worked with any other vendors.
I would recommend this solution to others because it is pretty simple to implement, and you don't need a dedicated WAP technician to maintain this solution.
Anyone in the organization can easily implement it, and it can be maintained with a little application knowledge. On the application side, you do not need to be a subject matter expert it is not necessary.
I would rate Imperva Incapsula a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Support Manager at Sefisa
Reports are easy to configure with good graphics; tech support is knowledgeable
Pros and Cons
- "There are quite a few useful Imperva Incapsula features. For example, one of them is the reports. The graphics are very good and it's easy to configure. The whole process is very fast and reliable too. They have good tech support as well."
- "Users would benefit from better documentation. There is official documentation, but sometimes we need more detail. We have some use cases that are not so run of the mill. It would be great if there was a knowledge base that we could go to for more answers."
What is our primary use case?
Our customers have a number of use cases for Imperva Incapsula. Some use it to protect their APIs and others for its DDoS features.
What is most valuable?
There are quite a few useful Imperva Incapsula features. For example, one of them is the reports. The graphics are very good and it's easy to configure. The whole process is very fast and reliable too. They have good tech support as well.
What needs improvement?
Users would benefit from better documentation. There is official documentation, but sometimes we need more detail. We have some use cases that are not so run of the mill. It would be great if there was a knowledge base that we could go to for more answers.
The price could also be more reasonable. The price should at the very least be adjusted for different parts of the world. For example, here in Latin America, our budgets are very different than those for projects in the United States or Europe. It would be really positive if we could get the product at a more affordable price as we are customers with lower budgets without sacrificing features or capabilities of the solution.
For how long have I used the solution?
I have been using Imperva Incapsula for about three years. It's a solutions I recommend to my customers.
What do I think about the stability of the solution?
This is a very stable solution.
How are customer service and support?
I like their support. The times we have asked for their help, they have been very accurate at giving answers.
How was the initial setup?
The initial setup is easy. It can take maybe half an hour due to the propagation of the DNS name on the server. However, setting up one Imperva website is very easy. You just have to wait for the DNS to refresh on the other DNS server and that's it.
What other advice do I have?
I would encourage people to implement Imperva Incapsula. I think it is a very mature, easy to use, and reliable solution.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Director at IT Big Bang
Easy to use and enables us to put everything in code
Pros and Cons
- "Simplifies putting everything in code."
- "A limited tool if you're looking to customize."
What is our primary use case?
The company uses this solution to protect us from any potential attacks. We are customers of Imperva and I'm the company director.
What is most valuable?
Imperva makes it easier for us to put everything in code; we use Terraform to deploy our infrastructure.
What needs improvement?
This is a very limited tool if you're looking to customize. It would be helpful if Imperva would provide additional resources for Terraform that can easily be deployed. There are some cases where we're currently unable to use Terraform.
For how long have I used the solution?
I've been using this solution for six months.
What do I think about the stability of the solution?
The solution is stable although sometimes content delivery seems to be affected because it's in the cloud.
What do I think about the scalability of the solution?
Scalability is fine and we haven't had any issues with resource consumption.
How are customer service and technical support?
Technical support is quite proactive in sharing information.
How was the initial setup?
The initial setup is relatively straightforward.
What other advice do I have?
I rate this solution eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Team Lead Senior Technical Engineer at a tech services company with 51-200 employees
Simple to maintain, easy to configure, and easy to scale
Pros and Cons
- "It has fewer false positives"
- "The support for the on-premises version needs improvement."
What is our primary use case?
I am a distributor for Imperva. We provide solutions for our customers.
This solution is mainly used to protect websites. When it is deployed on the cloud it is used for traffic redirection and URL redirection functionality.
It is also used for dual location blocking and security for the policies that are being applied.
What is most valuable?
Imperva is a good solution.
It has fewer false positives. It is very simple to maintain the device. It is also simple to configure. You don't need to have any HTTP knowledge or understand the HTTP programming languages when it comes to configuring the device.
What needs improvement?
The visibility of the actual traffic needs to be improved.
We are only monitoring the traffic if there are any issues and the alerts are being triggered.
We don't log the real-time traffic. We only log the real-time attacks and not the normal traffic that is passing through the device.
The main concern for our customers is to improve the visibility of the actual traffic. Customers feel that is the one feature that will greatly improve Imperva.
They would like to have the complete network traffic passing through the device. Currently, we are only being alerted for the attack that has passed through the device instead of the genuine traffic.
We would like to see logs of the genuine traffic that passes through the device. It can be optional to enable it for certain customers and certain applications but should be included.
The support for the on-premises version needs improvement.
For how long have I used the solution?
We have been distributing Imperva for the last 10 years.
We are currently dealing with the latest version.
We provide both on-premises and cloud deployment, it depends on the customer's requirement.
What do I think about the stability of the solution?
Once it is configured it is stable. There are no issues with the stability of the Imperva Web Application Firewall.
What do I think about the scalability of the solution?
It is easy to scale. The scalability is fine. You can add gateways and scale, which is a good feature in Imperva.
This device is suitable for everyone.
How are customer service and technical support?
There are two different support teams. The cloud support is very good, but the on-premises support is lacking. The response time could be much better.
How was the initial setup?
The initial setup is easy if you know how to deploy Imperva. Once we do the base installation, the deployment is simple.
Once in six months, there are some patch upgrades required. If there are specific requirements we need to upgrade.
What about the implementation team?
We were able to complete the installation and deployment ourselves.
What's my experience with pricing, setup cost, and licensing?
When it comes to the cost, there are different sets of customers. Some are SMB and veteran customers who go with the cloud version of Imperva, which is a managed service. The next-level customers and enterprise will select the on-premises version along with the cloud. They prefer the hybrid environment.
There are a couple of different licensing models. One is with respect to the Cloud and is based on the number of applications you have to protect. The on-premises model is based on the throughput that is required to be inspected.
Which other solutions did I evaluate?
I know that FortiGate is a niche product and wanted to evaluate Impera and FortiGate for the differences.
What other advice do I have?
You should understand the customer's website, what their website is. They need to configure the ciphers properly. Many engineers are not able to complete the project because they don't understand the customer's environment.
Before doing an implementation, understand the customer's environment. The ciphers need to be configured properly. Some Imperva engineers are not able to complete the projects because they understand the customer's environment.
Know the ciphers being used and match the ciphers. You must ensure the same ciphers are being matched in the backend load balances. If the backend load or cipher is changed the same should be replicated in Imperva as well. Once this is complete it should be good.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Distributor
Technical Account Manager at a tech services company with 201-500 employees
Easy to deploy with good cost savings and great scaling potential
Pros and Cons
- "The solution is stable."
- "I loved the approach of the cloud. The cloud has a lot of new features, like advanced web protection and DDoS protection. If those could also be on-boarded onto the on-prem versions, that would be ideal. They need to pay attention to both deployment options and not just favor one."
What is most valuable?
The product is very good.
It's so easy to do the deployment. The installation is very straightforward. You can't even compare it to others on the market. It's that easy.
The features on offer are very nice.
The solution is stable.
The licensing setup makes the product easy to scale.
The pricing is very good.
What needs improvement?
I loved the approach of the cloud. The cloud has a lot of new features, like advanced web protection and DDoS protection. If those could also be on-boarded onto the on-prem versions, that would be ideal. They need to pay attention to both deployment options and not just favor one.
For how long have I used the solution?
I've been using the solution for the last five years. I've used it for quite a while now.
What do I think about the stability of the solution?
The stability of the product is good. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We typically deal with medium-sized organizations.
The licensing model makes the solution very simple to scale. If a company wants to expand, it's not a problem.
How are customer service and technical support?
We need an improvement in the support. We need a lot of turnarounds. Whenever is a ticket open, it's something that has become a concern.
Which solution did I use previously and why did I switch?
I'm not currently working with any other solution. I just use this product.
Previously, I did work with F5 and Fortinet. However, Imperva is superior to both of these products.
How was the initial setup?
The initial setup is easy and the solution is very simple to deploy.
What's my experience with pricing, setup cost, and licensing?
The solution is very affordable and the cloud is making it even easier in terms of cost savings.
What other advice do I have?
We are resellers and we are based in Kenya. We're actually doing the whole suite. I'm working with Database Security and I'm also doing the Web Application Firewall, both of which are on-prem and on the cloud. I'm also doing the DRA.
It's the best in breed in terms of a solution you can put in place.
I'd rate the solution at an nine out of ten. We're quite happy with its overall capabilities.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Imperva Application Security Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Distributed Denial-of-Service (DDoS) Protection CDN Web Application Firewall (WAF) Bot Management API SecurityPopular Comparisons
Prisma Cloud by Palo Alto Networks
Cloudflare One
Fortinet FortiWeb
Azure Front Door
F5 Advanced WAF
Microsoft Azure Application Gateway
Cloudflare Web Application Firewall
Akamai App and API Protector
Buyer's Guide
Download our free Imperva Application Security Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- F5 vs. Imperva WAF?
- Imperva WAF vs. Barracuda: Which One is Better?
- Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
- Can Imperva Bot Management protect against advanced bot threats, such as credential stuffing and content scraping?
- Can Imperva Bot Management protect against API attacks? Are APIs more susceptible to bot attacks?
- What is a zero-trust cybersecurity model and what would some of its key aspects be?
- We are looking at managed DNS providers and want to know what others are using
- Prolexic vs. Arbor Networks: How do they compare?
- How does a WAF help to protect against DDoS attacks?
- Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?












