Always-on, never diverted
Filtering is in the forwarding path at all times, so the route does not change when an attack starts. The latency you measure on a quiet evening is the latency during a flood - there is no diversion event and no BGP convergence to wait out.
Protocol profiles that are measured, not guessed
Source engine, RakNet and FiveM traffic are recognised from their bytes. Our incident captures identify these payloads by signature independently of port, which is how a flood on port 27015 is separated from players on port 27015.
Per-destination budgets that survive a carpet
Attacks against game hosting increasingly spread across an entire allocation. Prefix-level and host-level budgets are evaluated together, so a flood aimed at 256 servers at once is caught by the aggregate.
Optional reverse proxy for the web side
Launcher, store, forum and panel sit behind the Layer 7 service with automatic certificates and challenges only when a session looks wrong, while the game ports stay on pure network filtering where latency matters.