The WAF is in good condition, this is my starting point:
shadow mode with reporting, replay of captured traffic
bot detection (fingerprint header)
intel threats (AbuseIPDB, AlienVault)
GraphQL: depth, complexity, batch, introspection
OpenAPI: request validation against specs
WASM plugin in sandbox (off by default)
multi-tenant PostgreSQL with per-row isolation
auth: local, OAuth2+PKCE, LDAP, SAML (XML-DSig), MFA/TOTP
RBAC for endpoints on the Admin API
Svelte dashboard, audit log, privacy editing