Terabit
Always onEvery service, every packet

For when enterprise-grade isn't enough.

Always on and never guessing. Every packet is checked against what your service expects, so there is no attack to detect first. A single game server gets the same protection as a whole network.

Edge capacity
500+ Tbps
Stateful, in-house
13+ Tbps
Anycast PoPs
13+

The protection overview: passed and dropped traffic over time, totals, and the top attack sources.

We don't guess what's bad.
We know what's good.

Detection has to spot an attack before it can stop one, so every new attack gets through at least once. We work the other way round: traffic that doesn't match what your service expects is dropped, whether we've seen it before or not.

The firewall for a protected IP address: allow and deny rules by source, port and protocol, and the order traffic is filtered in.

1

Filters that know the protocol

Game and service traffic is checked for how it should behave, not matched against a list of known attacks.

2

Layers in front of your rules

Threat intelligence, geo rules and IP rules run in order. Your firewall is the last step, not the only one.

3

Yours to see and change

Every rule and every drop shows in your panel, with packet captures when you need to look closer.

Always on

An attack starts. Nothing changes.

There's no threshold to trip, no scrubbing mode to switch on and no reroute mid-attack. Your traffic takes the same filtered path on a quiet night as it does in the middle of a flood.

Detect, then reactIllustrationPlayers dropped
Attack beginsMitigation engagedDetection window
PassDropReal players
Terabit, always onIllustrationNo change
Attack begins
PassDropReal players

Above enterprise-grade

Everyone says enterprise-grade. Here's what we say instead.

The label promises a lot and pins down very little. These are the lines we'd cross out of a typical enterprise pitch.

Attacks detected in secondsNothing to detect. Filtering starts at the first packet.
On-demand scrubbingAlways on, for every service, every hour of the day.
Escalate to the upstream vendorOur own engineers patch a leak, usually in minutes.
Generic layer 7 rulesetsFiltering that adapts to any game and any protocol, including yours.
A premium protection tierOne stack. A game server gets what a network gets.
Contact us for pricingPublished prices, charged on what you use.

One network. Two ways in.

Host with us and protection comes built in. Run your own network and put it behind ours.

The account dashboard: attacks mitigated, peak attack sizes, the upcoming bill, active services and recent attacks.

Game servers and dedicated servers

Included on every server.

No add-on and no lighter consumer version. Every attack and its peak shows on your dashboard as it happens.

  • Game-aware filtering on every port you open
  • Firewall rules and webhooks you control
  • Traffic reports with packet captures
Remote MitigationB2B remote mitigation for operators who want global anycast routing and clean traffic delivery via GRE or direct tunnel.$950/Gbps/mo
On-Premise / WhitelabelB2B on-premise and whitelabel deployment with zero added latency and full branding control.$1,250/mo

Hosts, operators and platforms

Put your own network behind ours.

The filtering that protects our own customers, delivered to your network or deployed inside it.

  • Self-serve onboarding from the portal
  • Your traffic stays on your hardware with on-premise
  • Full API access and a dedicated engineer
Dropped every dayAn attack doesn't need a name for us to drop it. These are the ones customers ask about.Plus the ones nobody has named yet.
Stage 1 · EdgeVolumetric absorption500+ Tbpsupstream capacity
Volumetric
  • TCP floodsSYN, ACK, RST, PSH and mixed-flag packets
  • UDP floodsHigh-rate datagrams with random ports and payloads
  • ICMP floodsEcho request floods and oversized pings
  • Tunnel protocol floodsESP and GTP packet floods
  • Botnet floodsMixed vectors sent from compromised hosts
Reflection & amplification
  • TCP amplificationSpoofed SYNs reflected back as SYN-ACK floods
  • Common UDP amplificationDNS · NTP · Memcached · SSDP / UPnP · LDAP · SNMP · Chargen · TFTP
  • QUIC reflectionSpoofed Initial packets that trigger large handshake replies
Stage 2 · In-houseStateful validation13+ Tbpsacross 13+ PoPs
Exhaustion
  • Malformed packetsTruncated headers and bad checksums
  • Invalid TCP flagsImpossible or reserved flag combinations
  • IP fragmentationTeardrop and overlapping fragments
  • Bogon sourcesPackets from reserved and unroutable addresses
  • Invalid portsPackets to port 0 and reserved ports
Game protocols
  • Arma ReforgerRplNet handshake floods and malformed packets
  • Squad and Source titlesA2S query floods: INFO, PLAYER, GETSUM
  • RustConnection floods and game-state abuse
  • MinecraftHandshake and bot-driven floods
  • GTA V / FiveMConnection exhaustion and state attacks
  • Your gameApp-specific floods against any other title

Not an exhaustive list. Traffic that doesn't match what your service expects is dropped whether or not it appears here.

Straight answers.

Anything else, ask a mitigation engineer. You won't get a chatbot.

We don't have to. Detection has to recognise an attack before it can stop it, so anything new gets through the first time. We check every packet against what your protocol and service expect, and drop anything that doesn't match, whether we've seen it before or not.

Send us the attack that got past everyone else.

Tell us what hit you and what you run, and we'll show you how we'd filter it.

Want to see it first? Watch live mitigation or try the demo.

  • Remote mitigation live from the portal
  • On-premise and whitelabel for your own network
  • Mitigation engineers on call 24/7