Every day, online shop fronts face millions of automated requests — bots probing weak spots, credential stuffers testing stolen passwords, scrapers harvesting product data and attackers waiting for peak traffic moments to strike. These threats do not pause during your busiest season. They escalate.
For most merchants, the question is no longer if they will face a sophisticated attack, but when — and whether they will have the right protection in place when it happens. Revenue lost to downtime, customer trust eroded by account breaches and conversion rates decimated by inventory-hoarding bots are all real, measurable business impacts.
That is why Adobe is introducing Advanced Security for Adobe Commerce— a comprehensive security offering purpose-built for the demands of modern commerce.
What is Advanced Security for Adobe Commerce?
Advanced Security is an add-on offering for Adobe Commerce on cloud infrastructure that extends your shop front protection with three powerful capabilities delivered at the network edge, powered by Fastly:
Bot management. Identifies and stops malicious bots in real time while ensuring legitimate bots, like search engine crawlers, continue to work normally. Includes dedicated controls for AI crawlers and content fetchers that target shop front data.
Layer 7 DDoS protection. Absorbs application-layer distributed denial-of-service attacks before they reach your servers. While Adobe Commerce already includes Layer 3 and 4 network protection, Layer 7 attacks — which target the application directly — require this additional defence.
Advanced rate limiting. Provides granular controls that protect specific URLs and API endpoints from high-volume abuse. Goes beyond basic rate limiting to address specific attack patterns — reducing infrastructure strain and controlling cloud costs.
The business threats Advanced Security is designed to stop.
Advanced Security addresses the attack patterns that cause direct, measurable business harm:
Credential stuffing and account takeover
Bots use lists of stolen username-and-password combinations to break into customer accounts at scale. A successful account takeover damages customer trust, creates fraud liability and is often invisible until the damage is done. Advanced Security's Bot Management identifies and blocks this automated activity at the edge — before it reaches your log in infrastructure.
Card testing fraud
Attackers use bots to systematically test stolen payment card numbers against your checkout process. Each test costs you in payment processor fees and a successful card often leads to a fraudulent order. Bot Management detects and stops this pattern before it drains your margins.
Inventory hoarding
Bots hold high-demand products in baskets to prevent legitimate customers from purchasing them — driving frustration, lost sales and brand damage during your most important selling moments. Advanced Rate Limiting and Bot Management work together to identify and neutralise this behaviour.
Content and pricing scraping
Competitors use bots to extract your product catalogue, pricing strategies and content. This erodes your competitive advantage and can distort your SEO performance. Bot Management blocks unauthorised scraping while allowing legitimate search engine indexing to continue.
Layer 7 DDoS attacks during peak traffic
Distributed application-layer attacks are designed to overwhelm your shop front at the worst possible moment — flash sales, product launches and holiday events. Unlike network-layer DDoS attacks that are already covered, Layer 7 attacks mimic legitimate traffic and can bypass conventional defences. Advanced Security absorbs these attacks at the edge, keeping your shop front available when it matters most.
AI crawler abuse
A growing category of automated traffic comes from AI systems that scrape your content to train large language models — without consent. Advanced Security gives you configurable controls to identify, challenge or block these crawlers, protecting the content and data that your business depends on.
Built into your existing commerce infrastructure.
One of the most significant advantages of Advanced Security is that it runs on the same Fastly edge platform already powering your Adobe Commerce shop front. There is no new infrastructure to deploy, no third-party integrations to manage and no fragmented security coverage across different providers.
This means:
- Faster activation. Advanced Security is enabled on your existing Fastly service, not a separate layer that needs to be deployed and integrated.
- Consistent coverage. Security policies are applied uniformly across your shop front, eliminating gaps that can come from mixing multiple vendors.
- Simpler operations. A single Adobe-supported solution reduces the operational overhead of managing multiple security tools and vendor relationships.
- Preserved performance. Edge-based protection means threats are intercepted without adding latency to your customers' shopping experience.
How Advanced Security complements your existing protections.
Adobe Commerce on cloud infrastructure already includes a robust security foundation:
- A Web Application Firewall (WAF) that blocks SQL injection, cross-site scripting and OWASP Top Ten threats
- Layer 3 and 4 DDoS protection enabled automatically via Fastly CDN
- SSL/TLS certificates for encrypted traffic
- Origin cloaking to prevent direct access to your servers
- VCL-based security snippets for IP blocking and request filtering
Advanced Security does not replace these — it extends them. Think of it as adding a sophisticated, AI-powered outer perimeter to your existing security architecture. Where your WAF handles code-level threats and your network protection handles volumetric floods, Advanced Security addresses the sophisticated, application-layer attacks and automated abuse that have become the defining threat pattern for commerce today.
Dynamic challenges and deception technology.
Beyond the core three capabilities, Advanced Security includes two additional defensive mechanisms worth understanding:
Dynamic challenges. When suspicious traffic is detected, Advanced Security automatically assigns the optimal challenge to that traffic using techniques like Private Access Tokens (PAT) to verify legitimacy without disrupting the experience for real shoppers. The goal is to stop attackers without creating friction for customers.
Deception technology. For account takeover attempts, Advanced Security can respond with false information, disrupting the attacker's ability to operate while protecting your real customer data. This turns a defensive posture into an active deterrent.
Is Advanced Security right for your business?
Advanced Security is particularly well-suited for merchants who:
- Have experienced or are concerned about bot-driven attacks such as credential stuffing, content scraping or inventory manipulation.
- Need Layer 7 DDoS protection to complement existing network-layer coverage.
- Have specific URLs or API endpoints that are targeted by high-volume, distributed traffic that cannot be controlled through IP blocking alone.
- Want to manage AI crawlers and content fetchers accessing their shop front.
- Need to consolidate from multiple third-party security providers to a single, Adobe-supported solution.
If your current challenges involve single identifiable IP addresses, SQL injection or XSS threats or code-level vulnerabilities, your existing Adobe Commerce protections are designed for those scenarios. Advanced Security addresses the distributed, application-layer threats that have become the dominant attack surface for commerce businesses.
Getting started.
Advanced Security is available for Adobe Commerce on cloud infrastructure (PaaS) projects as an add-on at an additional cost. Activation is straightforward:
- Contact your Adobe account team or Adobe sales representative to discuss Advanced Security for your project.
- After purchasing, submit an Adobe Commerce Support ticket requesting enablement — including your project ID and the environments to protect.
- Adobe activates Advanced Security on your Fastly service and configures initial protection policies, typically within a few working days.
- You receive confirmation when protection is active across your environment.
Configuration changes currently require a support ticket, with self-service controls through the Admin UI planned for a future release.
Recommended for you
https://business.adobe.com/fragments/resources/cards/thank-you-collections/commerce