Edge Protection

Edge Protection: your Cloudflare set up properly, then kept that way

Cloudflare can do a great deal, and almost nobody configures it past the defaults. We set the firewall, bot protection, rate limiting, caching and SSL to suit how your site is actually used, then compare the live settings against that every morning.

With Cascadia you get

Drift caught the next morning
Set once, checked daily
Configured for your site, not a template
Cloudflare specialists, not a helpdesk
Nothing switched on that you did not ask for
Your account stays yours

Why teams start here

Drift caught the next morning

Nine settings are compared every day against what we set, so a change made yesterday reaches you the morning after rather than during an incident. When it was not you who changed it, we put it back.

Set once, checked daily

Settings drift. Someone turns on development mode to test something and forgets, a rule gets disabled during an incident, a TLS minimum stays where it was set in 2019. The daily comparison is what catches it.

Configured for your site, not a template

We configure for your site rather than applying a template, because a shop, a booking site and a brochure site need different rules. What we set is recorded, so you can see exactly what protects you.

What you get

Everything Edge Protection covers

All of these come with Edge Protection, set up and looked after by our team.

Firewall

  • Firewall rules written for your site
  • Rules for wp-login and xmlrpc
  • Country and ASN blocking where it helps
  • Known bad traffic dropped at the edge
  • Exceptions for the tools you actually use

Bots and abuse

  • Bot protection configured, not left default
  • Rate limiting on the paths that get hammered
  • Scrapers and vulnerability scanners blocked
  • Form spam reduced at the edge
  • Good bots let through

Speed

  • Caching tuned to how the site is built
  • Browser cache set sensibly
  • Always Online for when the origin fails
  • HTTPS enforced, and TLS kept current
  • Development mode never left on by accident

Watching

  • Nine settings compared daily against what we set
  • Told the morning after anything changes
  • 90 days of history, day by day
  • Bot and rate limiting rules checked daily with the rest
  • Put back by us when it was not you

What sets it apart

  • Drift caught the next morning
  • Set once, checked daily
  • Configured for your site, not a template
  • Cloudflare specialists, not a helpdesk
  • Nothing switched on that you did not ask for
  • Your account stays yours

Want your edge configured properly?

Tell us what you sell and we will start with the questions your buyers ask.

Get startedSee the comparisons

What a default setup gives you, and what it misses

Cloudflare’s defaults are safe rather than right. The useful part is further in: rules that match how your site is used, caching that does not break logged-in pages, and somebody checking it still says that tomorrow.

Cloudflare left on defaultsEdge Protection
FirewallGeneric rules, or none at allRules written for how your site is actually used
CachingAggressive until something breaksCaching tuned to how the site is actually built
BotsAll allowed or all blockedRules reviewed as your site changes
TLSWhatever it was set to years agoTLS and SSL kept current, and checked daily
DriftFound during the next incidentCaught the next morning, and put back when it was not you
UpkeepSet once, never revisitedReviewed as your site and its traffic change

What clients say about working with Cascadia

“I’ve always dreaded website management, but Cascadia has done an incredible job with my WordPress site, making it one less thing for me to worry about.”
Alex R.
Cascadia client
“I’ve worked with Cascadia for several years now. They are always ready to help in any way I ask and can implement my ideas with ease. A company that values their clients!”
Liz D.
Cascadia client
“Cascadia has been great to work with! We recently needed some updates, and Cascadia was quick to get them completed! We highly recommend Cascadia Web Services.”
Naomi T.
Cascadia client
“Cascadia is very responsive and we’re happy with them as our primary IT vendor.”
Royle J.
Cascadia client
“They do great work, been using for years. Prompt responses to requests.”
Brian M.
Cascadia client

Want your edge configured properly?

Talk to us

Who Edge Protection fits best

Sites that need more than a default template

A shop, a booking site and a brochure site all need different rules, so we set the firewall, bot protection, rate limiting, caching and SSL for how your site is actually used. What we set is recorded, so you can see exactly what protects you.

Sites running edge settings nobody has reviewed

A misconfigured edge is invisible until it is not: a rule that blocks your own checkout, a cache that serves a logged-in page to everyone, a TLS setting that quietly fails a card payment.

Agencies reporting this for their clients

You can sell the outcome without hiring for it. We run the technical and content work under your brand, deliver reporting you can pass straight to a client, and stay out of the relationship.

Ready to hand off your edge settings?

We watch your Cloudflare settings so you do not have to, and tell you when something moves.

How it works

1. We read your current settings

We start by reading your current settings and telling you what is wrong with them. Most sites have at least one thing that matters: TLS 1.0 still allowed, development mode left on, caching set so aggressively that logged-in users see the wrong page.

2. We set them the way your site needs

Rules are written for how your site is actually used, then applied at the edge rather than inside WordPress. Anything that could block real traffic, such as a country rule or an aggressive rate limit, is explained to you before it goes on.

3. You get the picture every month

After that it runs itself. Every morning the live settings are compared with what we set, and anything that moved becomes a ticket naming the setting and its previous value.
Ask us

Answers to common Edge Protection questions

Weighing us against another option? Our comparisons take the main ones in turn.
What does Edge Protection cover?
The firewall rules, bot protection, rate limiting, caching and SSL on your Cloudflare account, set for how your site is actually used rather than left on the defaults. Nine settings are then compared against what we set every morning, so a change you did not make is something you hear about from us.
Turning it on gives you the defaults, which are safe rather than right. The work is deciding which rules suit your traffic, writing them, and then noticing the morning after one of them changes. Almost nobody configures Cloudflare past the defaults, and almost nobody goes back to check it.
Yes. Cloudflare’s free plan covers most of what a small business needs, and this service is about configuring it properly rather than buying more of it. Where a paid feature genuinely helps, we will say so and why.
We need access to your Cloudflare account, which is usually an invitation you can withdraw at any time. Nothing is installed on your website and no access to the site itself is needed.
Setup starts within two business days, and the first full picture arrives within a week.
Yes. Every setting we change is recorded, and the daily snapshots are kept for 90 days, so you can see what something was, when it changed, and whether it was us.
Cloudflare’s own defaults are a reasonable starting point and nothing more. The work is deciding which rules suit your traffic, then noticing when one of them changes.
That is the risk we plan around. Anything that could block real traffic, such as a country rule or an aggressive rate limit, is explained to you before it goes on, and exceptions are written for the tools you actually use. Good bots are let through rather than caught in the same net.
You hear about it the next morning. The live settings are compared with what we set every day, and anything that moved becomes a ticket naming the setting and the value it had before. If the change was not yours, we put it back.
Access to your Cloudflare account, and a note of anything that must not be touched. That is all.
That is the usual failure of caching turned up until something gives, and tuning is what avoids it. Caching is set to how the site is built, browser cache is set sensibly, and Always Online covers the origin failing rather than serving a logged-in page to everyone.
A small site is where the edge is most often left exactly as it came, and a misconfigured edge stays invisible until it is not: a rule that blocks your own checkout, a cache that serves the wrong page, a TLS setting that quietly fails a card payment. Nothing is installed anywhere, so there is no overhead in running it on a small site.
HTTPS is enforced and the TLS minimum is kept current rather than left where somebody set it years ago. SSL mode is set correctly and checked daily, which matters because a TLS setting that is quietly wrong tends to show up as a failed card payment rather than as an error anyone sees.
No. It runs as a standalone monthly service on whatever hosting you already use, and the work happens in your own Cloudflare account rather than on your website. It is also part of Domain Pro, if you would rather have DNS, the edge and your domains on one invoice.
Ask Us Anything
We’d love to hear from you!
Contact Form