Websites and APIs
Request floods are filtered before they reach your origin. Rules read the path, the method and the source, so a bad country or a scraping ASN stops at the edge while real visitors carry on.
ddos protection · measured, not claimed
Every figure on this page is read from our own edge, not from a datasheet. Volumetric floods are scrubbed on the network before they reach your uplink, and whatever survives that is filtered request by request.
the console
Not a mockup of a product we are planning. Three tabs on every instance, from the first hour, on every plan.
DDoS protection
Mitigation across every protected address and endpoint.
Traffic during mitigation
Requests blocked
112,994,771
Attacks mitigated
163
Peak absorbed
374
Gbps
Average peak
16.98
Gbps
Median to clear
55s
| Vector | Attacks | Share |
|---|---|---|
| UDP Flood | 131 | 35.6% |
| ACK Flood | 59 | 16% |
| SYN Flood | 48 | 13% |
| RST Flood | 21 | 5.7% |
| FIN Flood | 20 | 5.4% |
| ICMP Flood | 20 | 5.4% |
| NTP Amp | 19 | 5.2% |
| Handshake | 18 | 4.9% |
| DNS Amp | 14 | 3.8% |
| DNS Flood | 7 | 1.9% |
| SYN ACK Flood | 4 | 1.1% |
| DNS Amplification | 4 | 1.1% |
The tiles and the vector table are live platform figures. The traffic curves are an example: shape belongs to one instance during one attack, and there is nothing to average across customers.
Firewall rules
The rule editor, as it looks on your instance.
Default policy
Block-list drops only what you name and is the default. Allow-list drops everything you do not name, for boxes that should only ever hear from a handful of places.
Rules
Add rule| Priority | Action | Protocol | Port | Source | Enabled |
|---|---|---|---|---|---|
| 10 | deny | any | any | country: CN, RU | on |
| 20 | deny | any | any | asn: AS14618 | on |
| 30 | allow | tcp | 22 | ip: 198.51.100.7/32 | on |
| 40 | allow | tcp | 80-443 | any | on |
| 50 | deny | udp | any | any | on |
Rules belong to individual instances, so these rows are examples. The analytics above are live platform figures.
WAF
Application firewall in front of each hostname.
Firewall protection
Managed rules for the OWASP top ten, on by default.
Under-attack mode
Challenge every visitor. For when you are already being hit.
WAF apps
Add app| App | Hostname | Template | Rules | Status |
|---|---|---|---|---|
| api-gateway | api.example.com | HTTPS | 12 | active |
| storefront | shop.example.com | HTTPS | 8 | active |
| admin | admin.example.com | HTTPS | 21 | provisioning |
WAF apps belong to individual instances, so these rows are examples. The blocked-request count above is a live platform figure.
Volumetric floods meet multi-Tbps of scrub capacity on the ScaleBit network, before anything reaches an uplink you share. There is nothing to switch on and nothing to size.
Whatever survives scrubbing is judged at the edge. Drop a country, a network, an address range, a protocol or a port, and it stops there rather than on your box.
Shield ships with every plan. No separate SKU, no add-on to remember, and no traffic surcharge on the day somebody points a botnet at you.
the path a request takes
Floods and legitimate requests hit the same address. The edge separates them there, so your uplink only ever carries the traffic you wanted.
inbound → evorxa edge → your server
stage by stage
The same journey without the geography: everything lands on the edge, the edge decides, and one clean stream continues to your server.
inbound → evorxa edge → your server
01 · ddos protection
Floods are scrubbed on the network, and whatever survives that is filtered per request at the edge. These are the platform's own figures.
2768.42Gbps
163 attacks scrubbed against protected addresses. Your server keeps serving; it never hears the flood.
The headline adds up every recorded attack's own peak rate. It is a sum of crests, not an integral of traffic over time.
Protection belongs to the address, not to a protocol. Anything listening on a protected IP inherits it.
Request floods are filtered before they reach your origin. Rules read the path, the method and the source, so a bad country or a scraping ASN stops at the edge while real visitors carry on.
Game servers, databases, VPN endpoints, anything on a port. Mitigation is not limited to HTTP, so a UDP amplification flood is handled the same way an HTTP one is.
Rules apply to the address, so every service behind it inherits them at once. Drop a range for SSH and it is dropped for everything else too.
Every attack is recorded with its vector, its peak and how long it ran, in your console as it is mitigated rather than in a monthly report.
Already carrying production traffic.



03 · plans
Shield ships with every plan. No separate SKU, no traffic surcharge on the day someone points a botnet at you. Pick a size; the edge is already in front of it.
Compare resources and choose a plan for your game server, business apps or next project. Switch billing cycles to see prepaid discounts.
Every tier: NVMe storage · Shield protection · AI agent access, with usage billed separately
General-purpose VMs with unmetered bandwidth.
vm.tiny.8gbvm.large.10gbvm.xlarge.16gbvm.2xlarge.20gbvm.3xlarge.32gbPrices in USD · prepaid for the selected billing cycle
questions
No. Shield ships with every plan, on from the first hour. There is no separate SKU to buy, no add-on to remember to enable, and no traffic surcharge on the day somebody points a botnet at you.
Volumetric floods meet multi-Tbps of scrub capacity on the ScaleBit network, before anything reaches an uplink you share. Every figure on this page is read from that edge rather than a datasheet, including the largest attack we have absorbed so far.
No. Protection belongs to the address, not to a protocol, so anything listening on a protected IP inherits it: game servers, databases, VPN endpoints, anything on a port. A UDP amplification flood is handled the same way an HTTP one is.
Nothing to switch on and nothing to size. Scrubbing, edge filtering and the rule editor are active from the moment the instance exists. You only touch the firewall if you want to narrow who can reach it.
Seconds. Drop a country, a network, an address range, a protocol or a port and it stops at the edge rather than on your box. Rules apply to the address, so every service behind it inherits them at once.
No. Traffic that never reaches your server is not your traffic. An attack day costs the same as a quiet one, which is the whole reason mitigation belongs on the network rather than on the box you are paying for.
Scrubbing, edge filtering and the rule editor are on from the first hour, on every tier.