DDoS Protection
Attacks stop at the edge.
Layer 3 to Layer 7, always on.
Mitigation is not a mode you switch on when something breaks — it runs on every request from the moment your traffic points at us. Volumetric floods are absorbed where they enter the network; application-layer attacks are scored request by request and dropped before they cost your origin a connection.
What you get
How the attack is stopped
Six layers of defence that run on every request, not a mode you switch on once something breaks.
Volumetric floods
SYN, UDP and amplification traffic is dropped in the kernel at the edge, upstream of anything that could saturate your uplink.
Application-layer scoring
Every HTTP request gets a risk score from its headers, TLS fingerprint, behaviour and network — not from a static blocklist.
Adaptive escalation
Protection tightens only while the origin is genuinely under strain, then relaxes. A flood we absorb cleanly never costs your visitors anything.
Distributed-attack radar
A suspicious pattern has to appear across many independent sources before it counts, so one unusual visitor is never treated as an attack.
Challenges, not blocks
Borderline traffic is asked to prove itself with a check the browser solves on its own. A false positive costs a second, not a customer.
Live visibility
Every drop, challenge and pass is logged with its reason as it happens, so you can see exactly what the attack looked like.
Priced flat, on purpose.
An attack is when you need your provider most, and when most pricing models turn against you. Ours does not move: mitigation is included on every plan, including the free one, and traffic during an attack is not billed differently from any other traffic.
- 01No per-GB or per-request attack fees
- 02Unmetered mitigation on every plan
- 03No emergency upgrade to a higher tier
- 04The bill after an attack looks like the one before it
Tuned against false positives.
Blocking a real customer is a worse outcome than passing a bot, so the system is built to avoid it. Detections have to be corroborated across many sources, trusted visitors keep their standing, and the harshest responses are reserved for the moment the origin is actually suffering.
- 01Corroboration required before a rule scores
- 02Self-solving checks — nothing to click
- 03Solving once clears every penalty on that visitor
- 04Your own API traffic is never interfered with
Questions
Before you ask
Further reading
The concepts behind this
Point your nameservers. We take the flood.
Most sites are protected in under five minutes, with no code changes.