DDoS Mitigation Standby

Your domain sits behind an edge network that filters attack traffic, with the thresholds, the under-attack settings and the escalation contacts agreed in advance instead of invented while the site is down. Standby is the honest word for it: the filtering is always on, and we are at the end of an agreed escalation path — not watching your traffic graph around the clock.

What you get

  • One domain moved behind edge filtering, with the origin locked to the edge as far as your hosting allows
  • Thresholds and an under-attack configuration agreed before anything happens, so the response is a switch rather than a decision
  • A named escalation path: who we call, who you call, and in what order, written down on both sides
  • Traffic reporting during and after an attack — what arrived, what was dropped, what reached you
  • A short note afterwards on which of the attack-time settings are worth keeping

What this does not cover

  • A guarantee that your site stays up. The capacity that absorbs a flood belongs to the upstream network, not to us; we configure it, tune it and escalate into it
  • Services that are not behind the edge: SSH, mail, databases, and anything reached by raw IP address
  • Application-layer abuse — scraping, credential stuffing, a slow stream of plausible-looking requests — which is Managed WAF Ruleset
  • Bandwidth or request charges your hosting or CDN provider bills you during an attack
  • Noticing on your behalf. The filtering is automatic; being told that something is wrong is Uptime and Alert Monitoring

Who it fits

A site that has been hit before, or one that cannot be offline during a launch or a campaign. If what you are actually seeing is bots, scrapers and login attempts rather than a flood, Managed WAF Ruleset is closer to the problem and costs less.