Market Overview

Castlight Health Implements Signal Sciences


Innovative Capabilities of Network Learning Exchange and Power Rules
Surface 50 Percent More Attacks, Offer Time Savings While Ensuring HIPAA

Signal Sciences, the most trusted brand in web defense with patented
next-gen WAF and RASP technology, today announced that Castlight Health
has implemented Signal Sciences for its Digital Health Platform.
Leveraging Signal Sciences' newly released Network Learning Exchange and
Power Rules, Castlight has gained tighter control of its web security.

Supporting millions of users within large global enterprises to access
private health and wellness data, Castlight sought a replacement to its
incumbent web application firewall (WAF) to achieve greater insight into
attacks and better security coverage with improved performance without
any maintenance overhead.

Before implementing Signal Sciences, Castlight's security team had
invested significantly in its traditional appliance WAF. Yet, the
solution fell short in terms of performance, visibility, and attack
coverage. Due to the legacy architecture of common network-based WAFs,
Castlight had been required to provide SSL keys, which wasn't ideal.
Another challenge was that all traffic could not be inspected, without
slowing down application traffic. This potentially resulted in
unnecessary risk and exposure.

With a distributed team model of 20 people across Network, DevOps and
Security teams, Castlight deemed it was important to have a tool that
provided access to valuable insights to all teams and was easy to use.

Castlight Health knew it needed to implement a solution to protect its
newly acquired web applications. So, after a thorough review of a number
of solutions, the company selected Signal Sciences as an alternative.

Signal Sciences provided Castlight with a modern architecture and
innovative capabilities such as monthly snapshots of blocked attacks,
most attacked targets, and more, cutting the time spent on report
preparation for executives by half.

Smarter, out-of-the-box detections and Power Rules allowed Castlight
Health to recoup 10 hours per month in maintenance time, while detecting
and blocking 50% more attacks their old tool couldn't see. Castlight
Health was able to achieve these results, all the while maintaining
HIPAA compliance with Signal Sciences privacy redactions and controls.

In addition, the DevOps team especially appreciated Signal Sciences'
ease of installation, ease of use and the fact that it didn't require
maintenance post-install and didn't add any noticeable overhead.

"Signal Sciences started working right off the bat. Signal Sciences
installs in our web server, the exact spot in the tech stack where it
should sit, where it's easier to maintain and doesn't upset the network
team for requiring SSL keys or introducing another traffic hop," said
Andrew Van Wormer, Sr. Manager, Security Operations.

"The community model is huge," added Wormer. "Network Learning Exchange
is innovative in that it gives us additional insights that not a lot of
other companies are getting. It helps us show the business that we're
becoming more sophisticated in our ability to protect our platform."

About Castlight Health

Castlight is on a mission to make it as easy as humanly possible to
navigate healthcare and live happier, healthier, more productive lives.
Our health navigation platform connects with hundreds of health vendors,
benefits resources, and plan designs, giving rise to the world's first
comprehensive app for all health needs. We guide individuals - based on
their unique profile - to the best resources available to them, whether
they are healthy, chronically ill, or actively seeking medical care. In
doing so, we help companies regain control over rising healthcare costs
and get more value from their benefits investments. Castlight
revolutionized the healthcare sector with the introduction of
data-driven price transparency tools in 2008 and the first
consumer-grade wellbeing platform in 2012. Today, Castlight serves as
the health navigation platform for millions of people and is a trusted
partner to many of the largest employers in the world.

For more information visit
Follow us on Twitter
and LinkedIn
and Like us on Facebook.

Related Links:

Follow Signal Sciences:

About Signal Sciences:
Signal Sciences protects the web
presence of the world's leading brands. With its patented approach to
WAF and RASP, Signal Sciences helps companies defend their journey to
the cloud and DevOps with a practical and proven approach, built by one
of the first teams to experience the shift. Based in Culver City,
California, Signal Sciences customers include Under Armour, Etsy, Adobe,
Datadog, WeWork and more. For more information, please visit

View Comments and Join the Discussion!