Layer 3 — Layer 7 Protection
GuardX CDN / Proxy
Protection at every layer.
A self-developed reverse proxy with our own WAF engine, multiple protection modes, edge cache and on-the-fly image optimization — and, below the HTTP layer, GRE transit and protected hardware for everything that isn't a website. Built and operated end-to-end by GuardX.
How it works
Inspection at every layer
Every request passes through our stack of appliances. Bots, abuse and attacks are dropped before they reach your origin.
Use cases
Built for whatever you put behind it.
The same engine protects a checkout, a login endpoint and a game server — what changes is which layer does the work.
E-commerce & checkout
Layer 7Keep carts and payment flows reachable during a flood. Bot scoring separates scrapers and card-testers from buyers, and the cache absorbs the traffic that never needed your origin.
- Inventory scraping blocked
- Card-testing rate limited
- Checkout stays uncached and fast
SaaS & APIs
Layer 7Machine traffic is the product, so nothing is challenged by default. Per-route rules and API-aware rate limits let you protect a login endpoint without touching the endpoints your customers automate against.
- Per-route rules and limits
- Credential-stuffing detection
- API traffic never interfered with
Gaming & voice
Layer 3/4UDP floods never reach the box. Traffic is routed to us over GRE, scrubbed, and handed back — your server IP stays out of public routing entirely.
- UDP and TCP scrubbing
- Origin IP hidden
- Latency-aware filtering
Agencies & hosting
Layer 3 – 7Bring a portfolio of client sites under one panel. Per-domain rules, per-domain analytics, and one bill that does not move when a client gets attacked.
- Unlimited domains per account
- Per-domain rules and analytics
- Flat cost during attacks
Infrastructure
Servers that live behind the filter.
Rather than tunnelling to your own hardware, rent it from us — Ryzen compute and single-tenant machines that sit inside the protected network from the first packet.
Hardware is being racked. Leave your email and we will tell you the moment a batch goes live — no deposit, no queue tricks.
Network
Close to your users. Closer to the attack.
Anycast routing sends every request to the nearest PoP — attacks get scrubbed where they enter the network, not in front of your origin.
Getting started
Protected in three steps.
No agent to install, no library to import, no code to change.
Point your nameservers
~2 minutesAdd the domain, we import your existing records, then you swap the nameservers at your registrar. Nothing changes for visitors while you check the records.
Flip the proxy on
AutomaticToggle any record to proxied. We issue the TLS certificate over DNS-01 and start terminating traffic at the edge — your origin keeps serving exactly as it did.
Tune what you need
OptionalSensible protection is on from the first request. Add rules, rate limits or a stricter mode whenever you want them — every event in the log turns into a rule in one click.
Learning centre
Understand it before you buy it.
Plain-English explanations of attacks, defences and the networking underneath — written to be useful whether or not you ever become a customer.
Questions
The things people ask first.
Point your nameservers. We handle the rest.
Most sites are protected in under five minutes, with zero code changes.