Layer 3 — Layer 7 Protection

GuardX CDN / Proxy

Protection at every layer.

A self-developed reverse proxy with our own WAF engine, multiple protection modes, edge cache and on-the-fly image optimization — and, below the HTTP layer, GRE transit and protected hardware for everything that isn't a website. Built and operated end-to-end by GuardX.

Scroll to explore
In-houseWAF Engine
L3 – L7Coverage
MultipleProtection modes
NLLive location

How it works

Inspection at every layer

Every request passes through our stack of appliances. Bots, abuse and attacks are dropped before they reach your origin.

Internet
GuardX Edge
WAF
Edge Cache
Your Origin
Bots — stopped at the edgeAttacks — blocked at the WAFClean traffic — passed through

Platform

One proxy in front of everything you run.

DDoS MitigationLive
Volumetric and application-layer floods are detected and scrubbed at the edge — no rerouting, no downtime, no extra cost per attack.
WAF Engine
Managed rulesets against SQLi, XSS and the OWASP Top 10, plus custom rules on path, headers, geo, ASN or rate.
Edge Cache / CDN
Static assets cached close to your users on an Anycast network. Tiered caching keeps origin traffic low.
DNS Management
Authoritative DNS with instant propagation. Manage records in the panel or via API, proxy any record with one toggle.
TLS Everywhere
Free auto-renewing certificates, TLS 1.3, HSTS and full origin encryption by default.
Layer 3/4 & GRE TransitSoon
TCP/UDP scrubbing for game servers, mail and custom protocols — the same pipeline, below the HTTP layer. Route to us over GRE, or rent hardware that already sits behind the filter.

Use cases

Built for whatever you put behind it.

The same engine protects a checkout, a login endpoint and a game server — what changes is which layer does the work.

E-commerce & checkout

Layer 7

Keep carts and payment flows reachable during a flood. Bot scoring separates scrapers and card-testers from buyers, and the cache absorbs the traffic that never needed your origin.

  • Inventory scraping blocked
  • Card-testing rate limited
  • Checkout stays uncached and fast

SaaS & APIs

Layer 7

Machine traffic is the product, so nothing is challenged by default. Per-route rules and API-aware rate limits let you protect a login endpoint without touching the endpoints your customers automate against.

  • Per-route rules and limits
  • Credential-stuffing detection
  • API traffic never interfered with

Gaming & voice

Layer 3/4

UDP floods never reach the box. Traffic is routed to us over GRE, scrubbed, and handed back — your server IP stays out of public routing entirely.

  • UDP and TCP scrubbing
  • Origin IP hidden
  • Latency-aware filtering

Agencies & hosting

Layer 3 – 7

Bring a portfolio of client sites under one panel. Per-domain rules, per-domain analytics, and one bill that does not move when a client gets attacked.

  • Unlimited domains per account
  • Per-domain rules and analytics
  • Flat cost during attacks

Infrastructure

Servers that live behind the filter.

Rather than tunnelling to your own hardware, rent it from us — Ryzen compute and single-tenant machines that sit inside the protected network from the first packet.

Hardware is being racked. Leave your email and we will tell you the moment a batch goes live — no deposit, no queue tricks.

Network

Close to your users. Closer to the attack.

Anycast routing sends every request to the nearest PoP — attacks get scrubbed where they enter the network, not in front of your origin.

0Gbps scrubbing capacity
0 BRequests / month
0ms median edge latency
AMSNetherlandsLive
FRAFrankfurtPlanned
LONLondonPlanned
PARParisPlanned
WAWWarsawPlanned
NYCNew YorkPlanned

Getting started

Protected in three steps.

No agent to install, no library to import, no code to change.

1

Point your nameservers

~2 minutes

Add the domain, we import your existing records, then you swap the nameservers at your registrar. Nothing changes for visitors while you check the records.

2

Flip the proxy on

Automatic

Toggle any record to proxied. We issue the TLS certificate over DNS-01 and start terminating traffic at the edge — your origin keeps serving exactly as it did.

3

Tune what you need

Optional

Sensible protection is on from the first request. Add rules, rate limits or a stricter mode whenever you want them — every event in the log turns into a rule in one click.

Questions

The things people ask first.

Point your nameservers. We handle the rest.

Most sites are protected in under five minutes, with zero code changes.