Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive reduction. Use when deploying new apps behind a cloud WAF, when pentests reveal injection/XSS flaws, when facing bot or credential-stuffing traffic, or when compliance (e.g. PCI-DSS) mandates a WAF.