DDoS protectionAlways on, at the edge, and never an invoice.

1.2 Tbit/s of filtering in the path at every region, included on a $2.79 instance and on a full rack alike. The number matters less than the billing model: an attack here costs you nothing, which is the only arrangement under which being attacked is not also a punishment.

capacity1.2 Tbit/s

How it works

No per-attack fee · No metered scrubbing · No protected-IP tier

The part everyone else charges for

Mitigation is sold three ways in this industry, and two of them turn an attack on you into revenue for your host.

Why it is not a product here

Being attacked should not also be expensive.

Metered scrubbing means the worse the attack, the larger the bill — at exactly the moment you can least act on it. A per-attack fee means someone else decides what your week costs. A protected-IP tier means the unprotected one exists, and you found out which you were on during the outage. We took all three off the table and priced the filtering into the product, because a customer being attacked already has a problem.

Every plan includes it
  • No per-attack fee Absorbing one costs you the same as a quiet Tuesday: nothing.
  • No metered scrubbing Filtered volume is never counted, so an attack cannot arrive as an invoice.
  • No protected-IP tier Every address on the estate is behind the same filtering. There is no cheap seat.

How it works

In the path, not in a datasheet.

Mitigation that has to be triggered has already let the first minute through, and the first minute is the one that takes you off the internet. Everything below runs continuously, whether or not anything is happening.

Always on
No detection delay Traffic is inspected in the path at all times rather than swung into a scrubbing centre once an alarm fires. There is no first minute during which the attack lands and nothing happens.
Where it happens
At the edge, before you Filtering runs on the border routers of the region your server sits in. Attack traffic is dropped where it arrives instead of being carried across our backbone to be dropped near your port.
What it costs
Nothing, on every plan Included on a $2.79 instance and on a full rack alike. There is no per-attack fee, no overage on scrubbed volume, and no "protected IP" upsell.
Layer 3 and 4
Automatic, no thresholds you set Volumetric floods, amplification, spoofed SYN, fragmented and malformed traffic. Signatures update continuously; you are not asked to tune anything.
Layer 7
On request, per service HTTP floods and slow-request attacks need to know what your application looks like. An engineer sets it up with you rather than guessing, and it is still not billed by volume.
What we will not do
Null-route you and call it mitigation Blackholing a customer stops the attack for everyone else and ends the service for the customer. It is the last resort here, it is never silent, and it has never been the first response.

What it filters

  • L3/4 UDP and ICMP floods Raw volume aimed at filling the port.
  • L3/4 Amplification / reflection DNS, NTP, memcached, SSDP, CLDAP and the rest of the family.
  • L4 SYN and ACK floods State-table exhaustion, spoofed or otherwise.
  • L3/4 Fragmented and malformed Traffic designed to cost more to parse than to send.
  • L7 DNS query floods Against a resolver or an authoritative server you run.
  • L7 HTTP floods GET and POST storms from residential and datacentre ranges.
  • L7 Slowloris and friends Connection exhaustion by holding requests open.
  • L7 Game-protocol attacks Source-engine, FiveM and similar query abuse.

Layer 3 and 4 filtering is automatic and needs nothing from you. Layer 7 has to understand what your application looks like, so an engineer configures it with you rather than guessing — and it is still not billed by volume when it runs.

At the edge of all eight

Filtering runs on the border routers of the region your server is in. Attack traffic is dropped where it lands, not carried across a backbone first.

  • Reykjavík2 × 100 Gbit
  • Bucharest4 × 100 Gbit
  • Sofia2 × 100 Gbit
  • Chișinău2 × 40 Gbit
  • Zurich2 × 100 Gbit
  • Amsterdam6 × 100 Gbit
  • Panama City2 × 40 Gbit
  • Singapore2 × 100 Gbit

Before the first attack.

Is it really included on the cheapest plan?

Yes, identically. A $2.79 instance sits behind the same filtering as a full rack, because the filtering happens on the border router rather than on your service. There is no version of this estate where some addresses are protected and others are not.

What happens during an attack?

Usually nothing you notice: the traffic is dropped at the edge and your port never sees it. Where an attack is large enough to be worth telling you about, we tell you — with what it was, what it peaked at and what we did — rather than leaving you to infer it from a graph.

Will you null-route me?

Only as a genuine last resort, never silently, and never as a first response. Blackholing a customer solves the problem for everybody except the customer, which is why hosts who sell mitigation by the gigabyte reach for it so quickly. If it ever comes to that here, an engineer is talking to you before it happens.

Do you handle layer-7 attacks?

On request, per service. Application-layer filtering needs to know what a normal request to your application looks like, so it is set up with you rather than switched on blindly — a generic rule set that breaks your API is not protection. It is not billed by volume either.

Does mitigation add latency?

The filtering is in-path and line-rate, so the added latency is not something you can measure against an unfiltered path. What does add latency is the alternative — swinging traffic into a remote scrubbing centre and back — which is precisely why this runs at the edge instead.

Can I see the attack traffic?

We can tell you what was dropped, when and at what rate, and an engineer will walk you through it. What we do not keep is a flow record detailed enough to reconstruct who talked to whom, because that is a record we would then be asked for by somebody else.