Protection sized to your risk.
You pay only for the legitimate requests we forward to your origin. Attacks are never metered, so the worst week of your year does not become the largest invoice of your year.
Four tiers, one billing rule.
Layer 7 is not an upgrade. Every plan gets the same WAF, the same proof-of-work challenges and the same ruleset, because the node runs one pipeline for everyone. What changes is how much legitimate traffic you send, how many applications sit behind it, how fast we answer, and whether we also carry your network traffic at L3 and L4.
Annual billing is 10 months for 12. Two months free.
Starter
For small sites and apps that want peace of mind.
- Full Layer 7 protection, no tiering
- WAF ruleset, maintained by us
- Proof-of-work challenges
- 1 application or domain
- Basic traffic analytics
- Email support
- Availability SLA
Business
For growing platforms with real traffic to protect.
- Everything in Starter, plus:
- Up to 5 applications or domains
- Higher rate and concurrency ceilings
- Attack reports
- Real-time alerts
- Priority support
- L3 / L4 network protection on request
Pro
FeaturedFor production applications that cannot afford downtime.
- Everything in Business, plus:
- L3 / L4 volumetric protection included
- Managed WAF tuned by our team
- Up to 25 applications or domains
- Origin protection
- 24/7 monitoring and support
- Highest availability SLA
Scale
For critical infrastructure at large scale.
- Everything in Pro, plus:
- Dedicated GRE / IPsec tunnels
- Unlimited applications or domains
- Dedicated account engineer
- Emergency onboarding
- Custom integrations (SIEM, API)
- SLA and penalties negotiated in writing
All plans include the global network and always-on protection. Prices are USD and exclude VAT.
Which of these is you?
Request quotas are hard to place against your own site, so answer three questions instead and we will point at the nearest plan. It escalates rather than averages: the highest plan any one answer implies is the one you see.
A starting point, not a quote. Three questions, then the nearest plan. The plan you actually sign for comes out of the free assessment, where we look at what you send rather than what you estimate.
Roughly how much traffic does it get?
A rough shape is enough. We are looking for an order of magnitude, not a figure from your analytics.
How many applications or domains?
Count each hostname you would put behind us, including staging and API subdomains if they are exposed.
Do you need protection for anything that is not web traffic?
TCP or UDP services, game or voice servers, or your own IP space carried over GRE, IPsec or BGP. Layer 7 is on every plan already, so answer no if all you serve is HTTP.
Answer any one of the questions and a plan appears here. You can change an answer at any time and the recommendation follows it.
Attacks are not metered.
DDoS floods, blocked probes and bots stopped at the challenge never consume quota. The only thing counted is a request the node actually forwards to your origin, because that is the only request your application had to serve.
The traffic you fear most is the traffic you are not billed for. That is the opposite of how per-request CDN and WAF billing normally behaves, where an attack is precisely the event that generates the invoice.
One billable row. The rest is what you are paying us to stop.
What to know before you sign.
What happens if I am attacked beyond my plan's capacity?
Nothing. Attacks are never metered. The quota counts only the legitimate requests we forward to your origin, so floods, blocked probes and challenged bots cost you nothing, however long the attack lasts. You are billed for real traffic, not for being a target.
Which plans include L3 and L4 protection?
Every plan is fully protected at Layer 7 already: the WAF, the ruleset and proof of work are not upgrades and are never withheld. L3 and L4 refers to something different, carrying your network traffic rather than your web traffic, which means TCP and UDP services or your own address space over GRE, IPsec or BGP. That is included from Pro upwards and comes with dedicated tunnels on Scale. On Business it is available, but it is a conversation rather than a checkbox, because it is provisioning work we do with you.
How long does onboarding take?
Same day for most web applications: you point a DNS record at us and traffic starts flowing through the network. TCP/UDP services and tunnel setups take 1 to 3 business days, because we configure them with you.
I am already under attack. Can you take me on now?
Yes. We run emergency onboarding, including for people who are not customers yet. We take the traffic, apply mitigation, get you back online, and move you onto a permanent plan afterwards.
Do you sign an SLA?
Yes. Every plan comes with a written SLA covering availability and mitigation time. Pro and Scale add contractual penalties if we miss what we committed to.
Will proof of work slow my visitors down?
No. A real browser solves the challenge in a moment, with nothing to click and nothing to read. Difficulty only rises for clients that already look suspicious, and a solved challenge carries a clearance, so the same visitor is not asked again.
Not sure which plan fits?
Tell us what you run and what has been hitting it. We will size a plan against your real traffic and tell you if a smaller one is enough.