Yeah! We would say the same if someone propose us to use this :)
1. We share the source code of Wallarm Node (nginx-based filter instance) with the companies after signing NDA. 2. Will run 3rd party audit of the code and share the report. 3. At some point, we'll open-source it.
Ivan (wlrm) will come up with the examples of attacks soon.