Protection live before the advisory drops
Drupal Steward is a virtual patch from the Drupal Security Team. The moment a critical vulnerability is identified, protection is already live on your site — giving your team the time to patch on your schedule, not the attackers.
Every critical advisory is a race. Steward starts before the gun.
When a critical Drupal vulnerability is disclosed, everyone learns about it at once — your team, the internet, and the attackers writing exploits. From that moment, your sites are exposed until your team has tested, staged, and deployed the patch. That window can run hours, days, or weeks depending on your release cycle.
Steward is a web application firewall: a network layer that sits in front of your site and blocks the specific traffic that would exploit a vulnerability. The Drupal Security Team writes the protection rule during the same coordinated disclosure process that produces the public advisory. The rule is live the moment the advisory is. Think of it as a virtual patch — your sites are protected from T+0, while your team applies the real patch on its own schedule.

Three steps. Then it just runs.
-
Image
The Security Team writes the rule.
The same engineers who maintain Drupal core write the WAF rule that blocks the vulnerability — before the advisory becomes public. -
Image
The rule deploys instantly.
The moment the advisory goes public, protection is live across Steward's global edge network. Every subscribed site, simultaneously protected. -
Image
Your team patches when ready.
No fire drill. No after-hours emergency deploy. Apply the patch through your normal change management — the protection holds in the meantime.
-
Community Tier
Routed through our WAF
From $15/month · No risk to start, cancel anytime- For one site, or a small portfolio
- DNS-level setup in 30 minutes
- Pricing scales with sites and traffic
- Free Let's Encrypt SSL included
-
Platform & Enterprise
Deployed in your own WAF
Custom pricing · WAF rules direct · Advance notice- For platforms, agencies, and large deployments
- WAF rules shared directly with your team
- Advance notice of every public advisory
- Dedicated SLA on notice and fixes
Built by the Drupal Security Team.
The engineers who maintain Drupal core and write its security advisories also write Steward's protection rules. That's why protection can be live the moment a critical advisory is public.
Steward isn't a substitute for patching — it protects against the highly critical, mass-exploitable class of vulnerabilities that can be blocked at the request layer, not every issue and not zero-days.
Estimate your pricing
Stop racing critical Drupal advisories.
Set up in about 30 minutes. Your team patches on your schedule from there. Trusted by Acquia, Pantheon, and Ironstar.
No risk to start · Cancel anytime · 24/7 edge protection