Under attack?
Tier 2 European backbone · DDoS protected

Most scrubbing providers rent the network their filter runs on.
We built both.

Our own DWDM lambdas between European points of presence, our own routers, switches and servers on top of them, and our own XDP/eBPF filter in the driver of every scrubbing node. One in-house team runs the whole of it, from the lambda to the packet - so there is no hand-off between the people who carry your traffic and the people who clean it.

1000Mpackets per second filtered per scrubbing location - ten servers at 100M each, in a redundant cluster
4000Gof filtering capacity per scrubbing location - ten servers at 400G each, PCIe Gen6 on ConnectX-8
<1sfrom first attack packet to enforced rule
10European locations - six scrubbing clusters, four edge nodes
Made in EuropeNetwork, filtering software and operations built and run inside the EU. No third-country dependency in the data path.
Human NOC, around the clockEvery message reaches an engineer. No chatbot, no AI agent, no model triaging your ticket before a person sees it.
Certified and auditedISO 9001, ISO 27001 and PCI-DSS, with the European security and reporting obligations that apply to network operators.
01 - What we own

Four layers, one owner

Every layer below is ours to change. When a new attack vector appears we write the filter for it - we do not open a support case with an appliance vendor and wait for a firmware release.

Optical
DWDM lambdas

Dedicated wavelengths between European sites.

ours
Transport
EVPN-MPLS

One control plane for bridging and routing between PoPs.

ours
Routing
Our AS, Tier 1 blend, IX and private peering

Per-upstream marking, so a flood can be traced to the path it entered on.

ours
Filtering
XDP/eBPF in the NIC driver

Per-vector counters, per-destination budgets, signature latches - reloadable without dropping a packet.

ours
Application
Layer 7 engine

A separate service, because a packet-level filter cannot judge a valid request.

ours
02 - Coverage

Fifty-one attack vectors, each with its own counter

Volumetric floods, amplification and reflection across every reflector class, carpet bombing spread over a whole prefix, TCP handshake abuse, protocol-specific game floods - and a separate Layer 7 engine for the attacks a packet filter cannot see.

Your traffic is never blackholed. We drop the attack, not the destination - a prefix under mitigation stays announced and stays reachable throughout.

Every vector we stop, and how each layer decides →

03 - Solutions

Who runs behind the wall

The filter is the same for everyone. What changes is the thresholds, and we set them against your traffic rather than against an industry default.

Hosting ProvidersPer-customer thresholds inside one prefix - and no null routes, ever. Data CentresFiltered upstream of the facility uplink, before the port fills. ISPs & CarriersWholesale scrubbing; your AS, your prefixes, your policy. Government & InstitutionsEU-operated end to end, evidence fit for a regulator. Game Servers & StudiosUDP filtering that tells players from floods, byte by byte. E-commerce & RetailReachable on Black Friday, with a WAF in front of checkout. Financial ServicesAlways-on, latency unchanged, DORA-shaped records. VoIP & TelecomNo diversion and no jitter event - the call survives the attack. iGaming & BettingCapacity that is real at kick-off, enforced in under a second. SaaS & Critical AppsOne tenant under attack is nobody else's outage. Hosting ProvidersPer-customer thresholds inside one prefix - and no null routes, ever. Data CentresFiltered upstream of the facility uplink, before the port fills. ISPs & CarriersWholesale scrubbing; your AS, your prefixes, your policy. Government & InstitutionsEU-operated end to end, evidence fit for a regulator. Game Servers & StudiosUDP filtering that tells players from floods, byte by byte. E-commerce & RetailReachable on Black Friday, with a WAF in front of checkout. Financial ServicesAlways-on, latency unchanged, DORA-shaped records. VoIP & TelecomNo diversion and no jitter event - the call survives the attack. iGaming & BettingCapacity that is real at kick-off, enforced in under a second. SaaS & Critical AppsOne tenant under attack is nobody else's outage.
04 - Support

You will be talking to a person

Support is engineers on the network, around the clock - nothing automated answers before a human does, and the person who replies can change a rule while you are still typing. Why we run it this way →

05 - Network

A Tier 2 European backbone, ten sites, all of it ours

Juniper at the edge, Dell clusters doing the filtering, our own DWDM lambdas between sites and EVPN-MPLS underneath the lot. Ten Tier 1 upstreams and twenty exchanges, with 100G and 400G handoff at every location.

5 TbpsTier 1 transit capacity
15 TbpsInternet exchange and private peering capacity
50 TbpsBackbone capacity between points of presence

The map and the ten locations →  ·  The platform →  ·  Upstreams & peering →

06 - Services

What we sell, and where each of them is explained

Every service below runs on the same network, with the same filter in front of it and the same engineers behind it. The detail lives on its own page rather than all of it here.

Mitigation

DDoS protection

L3 and L4 filtering in the NIC driver at line rate, plus a separate Layer 7 WAF for what a packet filter cannot judge. Fifty-one vectors with their own counters and thresholds.

Connectivity

IP transit

Dual stack, 1G to 400G, full or partial table, documented BGP communities - and no oversubscription on any port at any hour.

Optical

DWDM wavelengths

Dedicated 10G, 100G and 400G channels between European sites on our own line system, with latency quoted from the fibre rather than from a map.

Layer 2

EVPN-MPLS transport

Transparent Ethernet between sites - E-Line, E-LAN and E-Tree - with tags and MTU intact and sub-50 ms protection where the route is diverse.

Network

The network itself

Ten points of presence, the Juniper and Dell platform underneath them, ten Tier 1 upstreams and twenty exchanges.

Engineering

Consulting & build

Architecture, hardware selection and full border and edge builds - from people who have rebuilt their own data plane six times since 2009.

07 - Engineering services

We also help you build your own

Six times we have designed a filtering data plane, chosen the hardware under it and rebuilt the border around it - on our own network, under real attack. DDoS architecture, router and switch selection, and full border and edge builds. What the engagements look like →

08 - Company

Six data planes since 2009

Each one was thrown away and rebuilt because the traffic outgrew it, not because a vendor released something. Every generation was ours to write, and the one running today can be replaced while packets are flowing.

Why each one was replaced, and what it cost to find out →

Connected with

The blend behind every port

5 Tbps of transit, 15 Tbps of peering and 50 Tbps of backbone between our points of presence.

10Tier 1 upstreams
20internet exchanges
100+direct PNI ports
1000+peering sessions
GTTNTTCogentTata CommunicationsOrangeHurricane ElectricSparkleArelionLumenRETNGoogleMetaAWSMicrosoftAppleNetflixCloudflareAkamaiFastlyCDN77AMS-IXDE-CIXLINXGNM-IXBIX.BGFRYS-IXSPEED-IXGigaNetInterLANGlobal-IXGTTNTTCogentTata CommunicationsOrangeHurricane ElectricSparkleArelionLumenRETNGoogleMetaAWSMicrosoftAppleNetflixCloudflareAkamaiFastlyCDN77AMS-IXDE-CIXLINXGNM-IXBIX.BGFRYS-IXSPEED-IXGigaNetInterLANGlobal-IX
NINE-IXPiter-IXERA-IXLSIXpeering.czSIX.SKGR-IXEquinix IXInterIXTurkIXByteDanceOVHcloudHetznerLeasewebDigitalOceanJuniper NetworksDell TechnologiesNVIDIA NetworkingCiscoMellanoxGTTNTTCogentTata CommunicationsOrangeHurricane ElectricSparkleArelionLumenRETNNINE-IXPiter-IXERA-IXLSIXpeering.czSIX.SKGR-IXEquinix IXInterIXTurkIXByteDanceOVHcloudHetznerLeasewebDigitalOceanJuniper NetworksDell TechnologiesNVIDIA NetworkingCiscoMellanoxGTTNTTCogentTata CommunicationsOrangeHurricane ElectricSparkleArelionLumenRETN