ZERO-PROTECT¶
An anycast reverse proxy in front of your origin. Traffic hits our edge on AS215197, passes the mitigation pipeline, and only clean requests reach your servers. Qualified by the BSI under §3 BSIG.
| Modes | HTTPS reverse proxy (ports 443 and 80), TCP services, UDP ports; standalone L3/L4 for IP-transit customers |
| Addressing | one anycast IPv4 and IPv6 per service, pool DE or EU; edge hostname for CNAMEs |
| Scope | Shared: 1 FQDN plus up to 20 aliases; Dedicated: edge nodes reserved, own IP range or BYOIP |
| Pipeline | Flowspec and XDP at L3/L4, connection limits, JA4 fingerprinting, protection rules, rate limits, slow-HTTP detection, proof-of-work, edge cache, WAF (Coraza, OWASP CRS), see Pipeline |
| TLS | ACME (Let's Encrypt, ZeroSSL, Buypass, Google) or own certificate, HTTPS redirect, HSTS |
| Config propagation | about 30 seconds from portal to all edges; emergency actions within seconds |