1.6 Tbit/s of always-on mitigation.
Inline scrubbing at every PoP. No re-routing, no GRE tunnels, no manual triggers. Filtering starts before your stack even notices the anomaly.
Every layer. Every vector.
UDP / ICMP / amplification
Memcached, NTP, DNS, CLDAP reflection. Filtered at the edge before reaching our backbone.
SYN / ACK / RST floods
Stateful inspection at line rate. Cookie-based SYN protection, connection limits per /32.
HTTP / HTTPS floods
JS challenge, rate-limit per fingerprint, optional CAPTCHA. Bring your own WAF rules or use ours.
Authoritative DNS protection
If you run nameservers on us, we filter DNS-specific attacks: NXDOMAIN, water-torture, random subdomain.
Game-server protocols
Source Engine, Minecraft, FiveM, custom UDP. Pre-built filters per protocol — no false positives on legit clients.
Your filter rules
ACL, BPF, FlowSpec — push your own rules to our edge in real time. API access for automation.
What our scrubbers actually saw.
Where you can get it.
Already under attack?
Spin up a protected server in under 30 minutes. Or migrate IPs to our scrubbing in real time.