Terabit-Scale DDoS Protection and Web Security
Security is our foundation. The moment you onboard, your origin IP is hidden from the public internet. Our in-house mitigation stack handles DDoS attacks, traffic hijacking and malicious requests in a single move.



Secure connections
Every customer gets free, fully automated SSL certificates. Once a domain is onboarded, the certificate is issued and deployed automatically — no manual steps and no extra charge.
All HTTPS connections run on the latest performance and security features, including TLS 1.3 with 0-RTT and an optimised HTTP/3 stack.
Content security features
Protect your content with expiring links that can be further restricted to specific IP addresses. Each resource gets a unique token and secret for generating signed URLs.
Origin Protection proxies sit between your origin and our edge caches, cutting both the load on your servers and the cost of egress traffic.
Allow or block individual IP addresses, countries or regions with straightforward allow and deny rules that take effect immediately.
Content theft stops being a problem. Lock assets to your own domains — hotlink protection only serves requests carrying a valid referrer header.
DDoS and CC attack mitigation
RockCloud runs on Anycast, so a single IP absorbs up to 3 Tbps of attack traffic. Combined with the Game Shield AI engine, malicious CC traffic is identified and dropped within three seconds, keeping your service online throughout.
- A network built for scale
We interconnect directly with 14 Tier-1 carriers and operate CN2 GIA private lines into mainland China. With roughly 15+ Tbps of capacity, mitigation never comes at the cost of delivery speed.
- Purpose-built mitigation
RockCloud built its DDoS mitigation stack on DPDK. Big-data analysis and machine learning work together to detect and block incoming attacks and malicious requests within seconds.
- No speed trade-off
Even while an attack is in progress, your content stays secure and fully reachable for real users. You never have to trade performance for protection.
Anti-DDoS CDN, protected servers and mitigation FAQ
A protected server concentrates mitigation at one machine, so capacity is capped by that facility and the real IP stays exposed. An anti-DDoS CDN scrubs traffic across distributed edges, spreading the attack over many nodes while hiding the origin. RockCloud provides the anti-DDoS CDN and Game Shield that sit in front of your own servers — whether your origin is a protected server or an ordinary instance, it gains distributed mitigation and nearby delivery. Web and API workloads usually go straight to the CDN; game workloads needing full TCP/UDP forwarding use Game Shield.
They are both included. DDoS mitigation handles volumetric floods (UDP, SYN, NTP and DNS amplification) and depends on scrubbing capacity. CC mitigation handles application-layer request floods that look much like real users, and depends on behavioural detection and human verification. One is a capacity problem, the other an accuracy problem, and both run on the same request path.
No. Our acceleration nodes sit in Hong Kong, Japan, Korea and Singapore, forming a filing-free CDN edge that avoids the mainland filing process, then connect back over CN2 so visitors in mainland China still get near-domestic speed. This is why cross-border, export-oriented and ecommerce sites commonly adopt this architecture.
A single IP absorbs up to 3 Tbps, with 7T+ of network-wide scrubbing capacity. Plans are billed by peak protection tier; if an attack exceeds your tier we first raise the scrubbing level to keep you online and then discuss next steps, rather than blackholing your IP outright. Tiers and overage handling can be confirmed before onboarding.
There is no interruption. Onboarding is a DNS change that takes effect within five minutes, with old and new paths running in parallel during cutover. When onboarding under attack, also rotate the origin IP and allow only our fetch nodes through the origin firewall — otherwise attackers can still reach the previously exposed address directly.
Still haven't found what you're looking for? Talk to our team.
Put terabit-scale DDoS protection in front of your service
