DDoS Protection

Attacks stop at the edge.

Layer 3 to Layer 7, always on.

Mitigation is not a mode you switch on when something breaks — it runs on every request from the moment your traffic points at us. Volumetric floods are absorbed where they enter the network; application-layer attacks are scored request by request and dropped before they cost your origin a connection.

Scroll for more
L3 – L7Coverage
Always-onMitigation
NoneAttack surcharge
AutomaticReaction

What you get

How the attack is stopped

Six layers of defence that run on every request, not a mode you switch on once something breaks.

Volumetric floods

SYN, UDP and amplification traffic is dropped in the kernel at the edge, upstream of anything that could saturate your uplink.

Application-layer scoring

Every HTTP request gets a risk score from its headers, TLS fingerprint, behaviour and network — not from a static blocklist.

Adaptive escalation

Protection tightens only while the origin is genuinely under strain, then relaxes. A flood we absorb cleanly never costs your visitors anything.

Distributed-attack radar

A suspicious pattern has to appear across many independent sources before it counts, so one unusual visitor is never treated as an attack.

Challenges, not blocks

Borderline traffic is asked to prove itself with a check the browser solves on its own. A false positive costs a second, not a customer.

Live visibility

Every drop, challenge and pass is logged with its reason as it happens, so you can see exactly what the attack looked like.

Priced flat, on purpose.

An attack is when you need your provider most, and when most pricing models turn against you. Ours does not move: mitigation is included on every plan, including the free one, and traffic during an attack is not billed differently from any other traffic.

  • 01No per-GB or per-request attack fees
  • 02Unmetered mitigation on every plan
  • 03No emergency upgrade to a higher tier
  • 04The bill after an attack looks like the one before it

Tuned against false positives.

Blocking a real customer is a worse outcome than passing a bot, so the system is built to avoid it. Detections have to be corroborated across many sources, trusted visitors keep their standing, and the harshest responses are reserved for the moment the origin is actually suffering.

  • 01Corroboration required before a rule scores
  • 02Self-solving checks — nothing to click
  • 03Solving once clears every penalty on that visitor
  • 04Your own API traffic is never interfered with

Questions

Before you ask

Point your nameservers. We take the flood.

Most sites are protected in under five minutes, with no code changes.