ddos protection · measured, not claimed

Floods stop at the edge. Your box never hears them.

Every figure on this page is read from our own edge, not from a datasheet. Volumetric floods are scrubbed on the network before they reach your uplink, and whatever survives that is filtered request by request.

2768.42
Gbps absorbed
112,994,771
Requests blocked
last 30 days, at the edge

the console

This is the screen you get.

Not a mockup of a product we are planning. Three tabs on every instance, from the first hour, on every plan.

console.evorxa.com/instances/…

DDoS protection

Mitigation across every protected address and endpoint.

Traffic during mitigation

DroppedServed

Requests blocked

112,994,771

Attacks mitigated

163

Peak absorbed

374

Gbps

Average peak

16.98

Gbps

Median to clear

55s

Attack vectors
VectorAttacksShare
UDP Flood13135.6%
ACK Flood5916%
SYN Flood4813%
RST Flood215.7%
FIN Flood205.4%
ICMP Flood205.4%
NTP Amp195.2%
Handshake184.9%
DNS Amp143.8%
DNS Flood71.9%
SYN ACK Flood41.1%
DNS Amplification41.1%

The tiles and the vector table are live platform figures. The traffic curves are an example: shape belongs to one instance during one attack, and there is nothing to average across customers.

Absorbed on the network

Volumetric floods meet multi-Tbps of scrub capacity on the ScaleBit network, before anything reaches an uplink you share. There is nothing to switch on and nothing to size.

Filtered per request

Whatever survives scrubbing is judged at the edge. Drop a country, a network, an address range, a protocol or a port, and it stops there rather than on your box.

On from the first hour

Shield ships with every plan. No separate SKU, no add-on to remember, and no traffic surcharge on the day somebody points a botnet at you.

the path a request takes

Everything arrives at the edge. Only what should reach you leaves it.

Floods and legitimate requests hit the same address. The edge separates them there, so your uplink only ever carries the traffic you wanted.

dropped
passed
dropped
evorxa edge
your server

inbound → evorxa edge → your server

stage by stage

Three stops, and only one of them is yours.

The same journey without the geography: everything lands on the edge, the edge decides, and one clean stream continues to your server.

dropped
passed
dropped
inbound
evorxa edge
your server

inbound → evorxa edge → your server

01 · ddos protection

Absorbed before it reached an uplink.

Floods are scrubbed on the network, and whatever survives that is filtered per request at the edge. These are the platform's own figures.

2768.42Gbps

163 attacks scrubbed against protected addresses. Your server keeps serving; it never hears the flood.

The headline adds up every recorded attack's own peak rate. It is a sum of crests, not an integral of traffic over time.

One address, every service behind it.

Protection belongs to the address, not to a protocol. Anything listening on a protected IP inherits it.

Websites and APIs

Request floods are filtered before they reach your origin. Rules read the path, the method and the source, so a bad country or a scraping ASN stops at the edge while real visitors carry on.

TCP and UDP services

Game servers, databases, VPN endpoints, anything on a port. Mitigation is not limited to HTTP, so a UDP amplification flood is handled the same way an HTTP one is.

The whole box

Rules apply to the address, so every service behind it inherits them at once. Drop a range for SSH and it is dropped for everything else too.

Visible while it happens

Every attack is recorded with its vector, its peak and how long it ran, in your console as it is mitigated rather than in a monthly report.

Already carrying production traffic.

  • AutoComputer Trading
  • Cointo
  • Cranl
  • Eduvera
  • Envkit
  • Stockship

03 · plans

Shield ships with every plan. No separate SKU, no traffic surcharge on the day someone points a botnet at you. Pick a size; the edge is already in front of it.

Clear plans. Choose what you need.

Compare resources and choose a plan for your game server, business apps or next project. Switch billing cycles to see prepaid discounts.

Every tier: NVMe storage · Shield protection · AI agent access, with usage billed separately

Standard VMs

General-purpose VMs with unmetered bandwidth.

Cores
4–10
shared cores
Storage
100–400 GB
NVMe
Uplink
Up to 2 Gbps
  • Tinyvm.tiny.8gb
    $11.99/mo
    Cores
    4
    Memory
    8 GB
    Storage
    100 GB
    Uplink
    1 Gbps
    Provision →
  • Largevm.large.10gb
    $14.99/mo
    Cores
    4
    Memory
    10 GB
    Storage
    150 GB
    Uplink
    1 Gbps
    Provision →
  • XLargevm.xlarge.16gb
    $22.99/mo
    Cores
    6
    Memory
    16 GB
    Storage
    200 GB
    Uplink
    2 Gbps
    Provision →
  • 2XLarge3 leftvm.2xlarge.20gb
    $29.99/mo
    Cores
    8
    Memory
    20 GB
    Storage
    300 GB
    Uplink
    2 Gbps
    Provision →
  • 3XLarge3 leftvm.3xlarge.32gb
    $44.99/mo
    Cores
    10
    Memory
    32 GB
    Storage
    400 GB
    Uplink
    2 Gbps
    Provision →

Prices in USD · prepaid for the selected billing cycle

questions

Before you point a record at us.

Is DDoS protection an add-on?

No. Shield ships with every plan, on from the first hour. There is no separate SKU to buy, no add-on to remember to enable, and no traffic surcharge on the day somebody points a botnet at you.

How large an attack can you actually absorb?

Volumetric floods meet multi-Tbps of scrub capacity on the ScaleBit network, before anything reaches an uplink you share. Every figure on this page is read from that edge rather than a datasheet, including the largest attack we have absorbed so far.

Does this only cover websites?

No. Protection belongs to the address, not to a protocol, so anything listening on a protected IP inherits it: game servers, databases, VPN endpoints, anything on a port. A UDP amplification flood is handled the same way an HTTP one is.

What do I have to configure?

Nothing to switch on and nothing to size. Scrubbing, edge filtering and the rule editor are active from the moment the instance exists. You only touch the firewall if you want to narrow who can reach it.

How quickly do firewall rules take effect?

Seconds. Drop a country, a network, an address range, a protocol or a port and it stops at the edge rather than on your box. Rules apply to the address, so every service behind it inherits them at once.

Am I billed for attack traffic?

No. Traffic that never reaches your server is not your traffic. An attack day costs the same as a quiet one, which is the whole reason mitigation belongs on the network rather than on the box you are paying for.

Put your next server behind the same edge.

Scrubbing, edge filtering and the rule editor are on from the first hour, on every tier.

Scrubbing on from the first hourNo traffic surcharge on an attack dayRules push in secondsFiltered per request at the edgeEvery figure read from our own edge