Yes — always-on, included by default, on every tier.
We run up to ~1.2 Tbps of inline scrubbing capacity in front of every port. Filtering begins within about 10 seconds of an attack starting — no manual null-routes, no opt-in, no extra line item on the invoice.
We filter at L3 (volumetric: UDP/ICMP/amplification), L4 (protocol: SYN/ACK/RST floods), and L7 (application: HTTP/HTTPS floods) — plus pre-built filters for game protocols (Source Engine, Minecraft, FiveM) that don't false-positive on legitimate players.
Real example: we've absorbed 240+ Gbit/s SYN floods against IPTV panels mid-derby and 847 Gbit/s against a 100G customer — legit traffic unaffected in both cases.
See also: DDoS protection · Choosing a port speed with DDoS headroom