Terabit-Scale DDoS Protection and Web Security

Security is our foundation. The moment you onboard, your origin IP is hidden from the public internet. Our in-house mitigation stack handles DDoS attacks, traffic hijacking and malicious requests in a single move.

Translucent globe marked with the locations of RockCloud scrubbing nodes worldwideClose-up of neatly routed network patch cables inside a data centre rackRows of server racks with status indicators lit inside a data centre hall
SSL Labs server test report showing an overall rating of A+ for a domain served by RockCloud

Secure connections

Every customer gets free, fully automated SSL certificates. Once a domain is onboarded, the certificate is issued and deployed automatically — no manual steps and no extra charge.

All HTTPS connections run on the latest performance and security features, including TLS 1.3 with 0-RTT and an optimised HTTP/3 stack.

Content security features

Secure tokens and signed URLs

Protect your content with expiring links that can be further restricted to specific IP addresses. Each resource gets a unique token and secret for generating signed URLs.

Origin protection

Origin Protection proxies sit between your origin and our edge caches, cutting both the load on your servers and the cost of egress traffic.

IP and geo allow/block lists

Allow or block individual IP addresses, countries or regions with straightforward allow and deny rules that take effect immediately.

Hotlink protection

Content theft stops being a problem. Lock assets to your own domains — hotlink protection only serves requests carrying a valid referrer header.

DDoS and CC attack mitigation

RockCloud runs on Anycast, so a single IP absorbs up to 3 Tbps of attack traffic. Combined with the Game Shield AI engine, malicious CC traffic is identified and dropped within three seconds, keeping your service online throughout.

UDP floodsNTP amplificationDNS amplificationCC attacksSYN floods
  • A network built for scale

    We interconnect directly with 14 Tier-1 carriers and operate CN2 GIA private lines into mainland China. With roughly 15+ Tbps of capacity, mitigation never comes at the cost of delivery speed.

  • Purpose-built mitigation

    RockCloud built its DDoS mitigation stack on DPDK. Big-data analysis and machine learning work together to detect and block incoming attacks and malicious requests within seconds.

  • No speed trade-off

    Even while an attack is in progress, your content stays secure and fully reachable for real users. You never have to trade performance for protection.

Anti-DDoS CDN, protected servers and mitigation FAQ

A protected server concentrates mitigation at one machine, so capacity is capped by that facility and the real IP stays exposed. An anti-DDoS CDN scrubs traffic across distributed edges, spreading the attack over many nodes while hiding the origin. RockCloud provides the anti-DDoS CDN and Game Shield that sit in front of your own servers — whether your origin is a protected server or an ordinary instance, it gains distributed mitigation and nearby delivery. Web and API workloads usually go straight to the CDN; game workloads needing full TCP/UDP forwarding use Game Shield.

They are both included. DDoS mitigation handles volumetric floods (UDP, SYN, NTP and DNS amplification) and depends on scrubbing capacity. CC mitigation handles application-layer request floods that look much like real users, and depends on behavioural detection and human verification. One is a capacity problem, the other an accuracy problem, and both run on the same request path.

No. Our acceleration nodes sit in Hong Kong, Japan, Korea and Singapore, forming a filing-free CDN edge that avoids the mainland filing process, then connect back over CN2 so visitors in mainland China still get near-domestic speed. This is why cross-border, export-oriented and ecommerce sites commonly adopt this architecture.

A single IP absorbs up to 3 Tbps, with 7T+ of network-wide scrubbing capacity. Plans are billed by peak protection tier; if an attack exceeds your tier we first raise the scrubbing level to keep you online and then discuss next steps, rather than blackholing your IP outright. Tiers and overage handling can be confirmed before onboarding.

There is no interruption. Onboarding is a DNS change that takes effect within five minutes, with old and new paths running in parallel during cutover. When onboarding under attack, also rotate the origin IP and allow only our fetch nodes through the origin firewall — otherwise attackers can still reach the previously exposed address directly.

Still haven't found what you're looking for? Talk to our team.

Put terabit-scale DDoS protection in front of your service