Under attack?
Protection for ISPs and carriers

Wholesale scrubbing that leaves your routing policy in your hands

When an attack crosses your network toward a downstream customer, you carry every packet of it and your own upstreams may blackhole you for it. Buying mitigation should not mean surrendering your routing - you keep your AS, your prefixes and your policy, and divert only what you choose to divert.

The operator's specific problem

You pay for traffic you did not want

Attack volume toward a downstream customer transits your core, fills your transit commits and is billed at 95th percentile like anything else.

Your upstream's mitigation is your outage

Carriers protect themselves first. A large enough attack toward your ranges gets null-routed upstream of you, and the decision is taken without you.

RTBH is a customer-losing tool

Blackholing the destination stops the flood and completes the attack. For a retail ISP this is a support call; for a wholesale one it is a contract.

Why this works as a carrier-to-carrier service

Announce from your AS or ours

Protected prefixes can stay in your announcements with traffic steered through us, or be announced by us during an event and returned afterwards. Both are BGP, both are reversible in a session.

FlowSpec instead of a null route

Rules that match a vector rather than a destination, so mitigation removes the attack and not the customer. Published communities for traffic engineering and per-prefix control of what is diverted.

Marked upstreams and per-path blame

Our border marks every packet with the upstream it arrived on, so when a destination exceeds its budget we can identify and block the path carrying the flood while the other paths keep the full budget. Your legitimate traffic over a clean upstream is untouched.

Operator tooling, not a dashboard

Public looking glass, published peering policy and BGP communities, PeeringDB and bgp.tools entries. You can verify the network before you buy it and inspect it while you use it.

Tier 2 European backbone · European DDoS protected network Built, filtered and operated inside the EU · human NOC 24/7, no AI agents
ISO 9001ISO 27001PCI-DSSGDPRNIS2

Carrier services beside the scrubbing

The mitigation is one layer. The same network sells the layers around it - and a stack bought from one operator has nobody in it to blame somebody else.

IP transit

Wholesale capacity with communities that work

Full table, documented large communities, RPKI validation enforced on every session and no oversubscription - an upstream that publishes what it does instead of asking you to trust it. The transit page →

DWDM

Backhaul and alien waves

Wavelengths between our metros for your own backbone spans - or bring your transponders and take just the channel. Latency per route is quoted from the measured fibre, not from a map. DWDM wavelengths →

Transport

Carry your customers across our core

Hand traffic to us in one metro, collect it in another: QinQ-transparent E-Line and E-LAN over the same EVPN-MPLS core that carries our own filtering, with protection stated per route. EVPN-MPLS transport →

Consulting

A second pair of eyes on the border

Route policy, RTBH and FlowSpec design, and equipment selection for the next upgrade - advice from an operator that runs its own border, not from a reseller with a quota. How an engagement runs →

How it is delivered

BGP session, full table or default, IPv4 and IPv6
GRE or physical handoff at a shared facility
FlowSpec rules included for precise incident response
Diversion on demand or always-on, per prefix

Protection for other sectors