Under attack?
Protection for data centres

DDoS protection that stops traffic before it reaches your facility uplink

A data centre's problem is not the attacked server - it is the shared path in front of it. Once an attack fills the uplink, every tenant behind that port is offline regardless of what protection they individually bought. Filtering has to happen upstream of the facility, not inside it.

Where the damage actually happens

The uplink saturates before any filter runs

On-premises appliances, tenant firewalls and even in-rack scrubbing are all downstream of the congested link. A 300 Gbps flood against one customer is decided at the port it arrives on, and nothing behind that port gets a vote.

Cross-tenant blast radius

Tenants who bought nothing and tenants who bought protection go dark together, and the facility takes the reputational cost for an attack aimed at one of them.

Blackholing as the only tool

Most upstream carriers offer RTBH and nothing else. It clears the link by completing the attack, and the tenant whose prefix was null-routed is the one who cancels.

Why upstream filtering fits a facility

Filtering at our edge, not yours

Attack traffic is absorbed at our points of presence and only clean traffic is carried onward, so the volumetric event never reaches the port it was meant to fill.

Per-tenant thresholds, one delivery

The facility takes one clean handoff while each tenant prefix keeps its own budgets and its own attack history - isolation without a separate circuit per customer.

Capacity that is per node, not shared

Every scrubbing location runs a cluster of at least ten Dell servers, each terminating 400 Gbps on ConnectX-8 adapters, each measured filtering 100 million packets per second. Load is shared by weighted ECMP and every node holds its proportional share of each budget, so adding one raises the ceiling without loosening a limit.

No null routes in the runbook

Mitigation never means withdrawing a tenant's prefix. The escalation path ends in a tighter filter, not in a customer being disconnected.

Tier 2 European backbone · European DDoS protected network Built, filtered and operated inside the EU · human NOC 24/7, no AI agents
ISO 9001ISO 27001PCI-DSSGDPRNIS2

What else a facility takes from us

The mitigation is one layer. The same network sells the layers around it - and a stack bought from one operator has nobody in it to blame somebody else.

IP transit

Transit at the meet-me room, ready to resell

Protected dual-stack transit delivered at the facility edge, 1G to 400G - for your own network, or packaged into what you offer tenants alongside power and cooling. The transit page →

DWDM

Lambdas into the building

Wavelengths from your facility onto our backbone: interconnect to a second site, capacity to an exchange in another metro, or backhaul for an anchor tenant - without running your own optical desk. DWDM wavelengths →

Consulting

Spine, edge, and the operations after

Equipment selection for the facility fabric, configuration against measured load rather than the datasheet, documentation, and a support contract for the network your team inherits. Consulting & build →

How it is delivered

Cross-connect at a shared point of presence
Protected IP transit delivered to the facility edge
Tunnelled delivery where the existing upstream stays in place
Per-tenant reporting the facility can pass through to its customers

Protection for other sectors