Attacks stop before they reach your server
Traffic to your sites goes through a filter first: injections, bots, floods. What reaches you is what you were expecting — and you keep a record of everything that was stopped.
Compare the protections
Only looking for the padlock and the encryption? See SSL certificates
Essential
One site behind the firewall, with the managed rules kept up to date for you.
Choose Essential/year
Billed every year
- Sites protected
- 1
- DDoS protection
- Included
- Firewall rules
- Managed by us
- Rate limiting
- Not included
- Bot filtering
- Included
- Logs kept
- 7 days
- Support
- Standard
- Attacks are filtered before they reach your server
- Managed rules against injection, cross-site scripting and the known exploits of common CMS plugins
- DDoS filtering that absorbs the flood instead of passing it on
- Blocked requests are logged, so you see what was stopped and why
Business
Most popularSeveral sites, your own rules, and a cap on how fast anyone can hit your forms.
Choose Business/year
Billed every year
- Sites protected
- 5
- DDoS protection
- Included
- Firewall rules
- Managed + your own
- Rate limiting
- Included
- Bot filtering
- Included
- Logs kept
- 30 days
- Support
- Standard
- Attacks are filtered before they reach your server
- Managed rules against injection, cross-site scripting and the known exploits of common CMS plugins
- DDoS filtering that absorbs the flood instead of passing it on
- Blocked requests are logged, so you see what was stopped and why
Agency
Client sites under one account, with three months of logs to answer for what happened.
Choose Agency/year
Billed every year
- Sites protected
- 20
- DDoS protection
- Included
- Firewall rules
- Managed + your own
- Rate limiting
- Included
- Bot filtering
- Included
- Logs kept
- 90 days
- Support
- Priority
- Attacks are filtered before they reach your server
- Managed rules against injection, cross-site scripting and the known exploits of common CMS plugins
- DDoS filtering that absorbs the flood instead of passing it on
- Blocked requests are logged, so you see what was stopped and why
Switching the filter on
One addressing change, and the filter is in place.
- 01
You tell us which site to protect
The first domain to put behind the filter. The others are added from your client area.
- 02
You point the domain at the filter
A DNS change: we give you the exact values, and we make it for you if the domain is registered with us.
- 03
Traffic is filtered upstream
Hostile requests are stopped there. Legitimate visitors carry on to your server without noticing a thing.
- 04
You see what was blocked
Every stopped request is logged: the rule that caught it, where it came from, when. Useful the day someone asks you to account for it.
On every plan
The filtering is the product; none of this sits in a tier above it.
- Attacks are filtered before they reach your server
- Managed rules against injection, cross-site scripting and the known exploits of common CMS plugins
- DDoS filtering that absorbs the flood instead of passing it on
- Blocked requests are logged, so you see what was stopped and why
Questions about protection
What gets filtered, what changes on your side, and the limits.
Contact supportTraffic to your site passes through a filtering network before it reaches you. Requests carrying an SQL injection, a hostile script or the exploit of a known plugin flaw are rejected there; the rest carries on to your server. You install nothing, and your code is not touched.
Not on the site, but on its addressing: the domain has to point at the filter rather than straight at your server. If your domain is registered with us we take care of it; otherwise we give you the exact values to enter at your registrar.
It happens, mostly on admin interfaces and large uploads. The logs show you which rule caught it, and from the Business plan up you add your own rules to allow it through. Write to us if you would rather we did it.
The filtering absorbs ordinary floods without your server ever seeing them. We do not promise unlimited capacity: an exceptional attack can degrade the service while the rules adjust, and we would rather write that here than discover it together on the day.
Yes. The protection sits in front of the site whoever hosts it: us, a competitor, or your own server. Only the domain addressing has to go through the filter.
Start with a domain. Add the rest when you need it.
Create your account and bring your first project online.