Vercel's WAF blocks 87 billion attacks in Q4 2024
Vercel's platform security continues to operate as a multi-layered defense system, automatically mitigating threats before they reach customer applications. In the last quarter of 2024, the company's Web Application Firewall (WAF) blocked 87 billion attacks originating from 19 million unique IPs.
The security architecture combines two principal layers:
- Network-wide Layer 3 and Layer 4 protection via Vercel's firewall, which automatically mitigates DDoS threats and TCP-based attacks. This applies to every customer across all plan tiers.
- Comprehensive Layer 7 security via the WAF, which identifies and mitigates threats including SQL injection, cross-site scripting (XSS), and bot-driven attacks without degrading performance.
Geographic distribution of blocked traffic shows where attack volumes concentrate:
- 22 billion requests stopped in the US from 3.6 million unique IPs
- 16 billion requests mitigated in Germany
- 13 billion requests blocked in Singapore
These figures underscore the scale of modern cyber threats and the importance of proactive defense. By preventing attacks before they cause downtime, Vercel's WAF protects user experiences and reduces infrastructure strain while maintaining performance through automated detection and real-time mitigation.
Faster mitigation and clearer enforcement
Recent improvements focus on speed and clarity of threat response. DDoS protection is now 40x faster thanks to real-time stream processing that identifies and blocks malicious traffic earlier in the attack lifecycle. This approach also helps neutralize both high-volume and low-and-slow attacks before they reach applications, reducing associated costs.
For persistent threats, Vercel now returns a 403 Forbidden response instead of silently dropping traffic, making enforcement actions clearer to end-users.
Enhanced visibility and monitoring
Several updates expand the observability of security events across the platform.
- DDoS mitigation notifications: Admins can receive alerts when the Vercel Firewall detects and automatically mitigates an attack on a project, enabling teams to review attack logs and take further action.
- Project Overview previews: The Project Overview page now displays Firewall status along with other security data from the past 24 hours.
- Granular firewall data in Monitoring: The Monitoring or Observability Plus tab now supports filtering blocked requests by action, with additional details such as IP country and user agent.
Compliance and audit capabilities
Enterprise customers can now configure a real-time audit log stream to their existing Security Information and Event Management (SIEM) tools, including Datadog and Splunk. This integration supports established security operations workflows without requiring new tooling.
To assist customers with Payment Card Industry Data Security Standard (PCI DSS) requirements, Vercel has completed its Self-Assessment Questionnaire Attestation of Compliance (SAQ-D AOC) for Service Providers under PCI DSS v4.0, upgrading from version 3.2.1.



