Layer 3/4Soon

Protection below HTTP.

For everything that isn't a website.

A game server, a mail host or a VPN endpoint cannot sit behind an HTTP proxy — but it still needs the flood to stop somewhere. Traffic is routed to us over a GRE tunnel, scrubbed at our edge, and handed back to your machine clean. Your hardware stays exactly where it is, and its real address stays out of public routing.

Scroll for more

Pricing

Pick your clean capacity

Monthly, no setup fee, and no charge for the traffic an attack sends you. Setup is done with a human, not a form.

Filtered transit to hardware you already own.

Starter

One service, one box

Soon
€29/ mo
Clean capacity1 Gbit/s
Prefix/29 from us
ProtocolsTCP · UDP
TunnelGRE / IPIP
  • Always-on filtering
  • Origin IP stays hidden
  • Setup done with you
Talk to us
Best value

Pro

A small fleet

Soon
€79/ mo
Clean capacity5 Gbit/s
Prefix/28 from us
ProtocolsTCP · UDP
TunnelGRE / IPIP
  • Always-on filtering
  • Origin IP stays hidden
  • Setup done with you
  • Per-port policy
Talk to us

Business

Your own prefix

Soon
€149/ mo
Clean capacity10 Gbit/s
Prefix/24 or BYOIP
ProtocolsTCP · UDP
TunnelGRE / IPIP
  • Always-on filtering
  • Announce your own range
  • Setup done with you
  • Per-port policy
Talk to us
GRE / IPIPTunnel
TCP · UDPProtocols
Ours or BYOIPPrefix
Always-onMitigation

What you get

Built for non-HTTP traffic

Packet-level filtering for the services a reverse proxy cannot help — with your hardware left where it is.

Any protocol

TCP, UDP, ICMP and anything custom on top of them. The filter works on packets, so it does not need to understand your application.

Origin stays hidden

Traffic reaches your machine through the tunnel, so its real address never appears in public routing and cannot be attacked directly.

Keep your hardware

No migration. Your servers stay with whichever provider they are at now — only the route in front of them changes.

Bring your own IPs

Announce your own prefix through us, or use addresses from our range if you do not have any of your own.

Latency-aware

Filtering happens in the packet path, not by rerouting you through a distant scrubbing centre when an attack starts.

Setup with a human

Tunnels and routing are not self-serve guesswork. We configure it with you and confirm it works before you cut over.

Made for traffic that cannot be challenged.

A browser can solve a proof-of-work. A game client cannot, and neither can a mail server. Layer 3/4 protection therefore judges packets on shape, volume and source rather than asking anything to identify itself — so nothing legitimate is ever asked a question it cannot answer.

  • 01No challenges, no interruption to sessions
  • 02Volumetric floods dropped before your uplink
  • 03Per-port and per-protocol policy
  • 04Works for services with no HTTP layer at all

How a tunnel actually gets set up.

Nothing about this is self-serve guesswork. We agree the addressing, you configure one interface, and we verify traffic flows correctly before anything is cut over — so the switch happens when it already works, not in the hope that it will.

  • 01We assign protected addresses, or announce a prefix you already own
  • 02You add a GRE interface on your server — a handful of lines
  • 03We set MTU and MSS clamping with you so large packets do not break
  • 04We test the path together, then you move traffic across

What runs well behind it.

Anything that speaks TCP or UDP and cannot sit behind an HTTP proxy. The filter works on packet shape and volume, so it does not need to understand your protocol to defend it.

  • 01Game servers — Minecraft, FiveM, Rust, CS2, Source engine and similar
  • 02Voice and chat — TeamSpeak, Mumble, Discord-adjacent self-hosting
  • 03Mail servers, where reputation depends on staying reachable
  • 04VPN and tunnel endpoints, including WireGuard and OpenVPN
  • 05Custom binary protocols and anything else on an odd port

Questions

Questions about tunnels

Tell us what you need to protect.

Game server, mail, VPN or something unusual — we will tell you honestly whether we are the right fit.