Website protection
Your site is published through NetIO's filtering layer. You point your domain at a protected IP address we assign to you; we terminate the connection, inspect every request, and forward only legitimate traffic to your origin server — which stays hidden behind us.
How it works
- We assign a protected IP address from NetIO address space and provision your domains in the control panel.
- You repoint DNS — an A/AAAA record, or a CNAME, to the address we gave you. Nothing changes on your server.
- Every request is inspected at the application layer: HTTP floods, slow-rate attacks, scrapers, credential stuffing and OWASP-class exploits are blocked or challenged.
- Clean requests reach your origin over the connection we keep open to it. Your origin address is never exposed to the public Internet.
What is included
- Protected IPv4 and IPv6 addresses assigned to your account from NetIO address space
- HTTP and HTTPS flood mitigation, including slow-rate and low-and-slow attacks
- Web application firewall covering OWASP-class threats — injection, XSS, path traversal, file inclusion
- Bot mitigation — challenge-response, JavaScript validation, TLS and HTTP fingerprinting
- Managed TLS certificates, or bring your own
- Origin cloaking, access rules, rate limits, geo and ASN filtering
- Traffic and attack analytics in the control panel, plus a documented REST API
- Multiple origins with health checks and failover