You build it.We protect it.

Abuse-resistant DDoS protection on a fast-flux edge, with real-time mitigation and 24/7 support.

02REQUEST FLOW

Every request, verdicted in microseconds.

Forge-proof layers sit in front of your origin, deciding every request at the edge before it ever reaches you.

INCOMING
Real visitor
Bot / scraper
DDoS / WAF probe
MINLAT GUARD
01TLS · JA4 fingerprint
02HTTP/2 wire fingerprint
03WAF custom rules
04Per-IP / ASN rate-limit
05PoW challenge
OUTBOUND
Origin
Cache
Dropped

Real-time edge filtering

Every request earns a microsecond-scale verdict before it touches your origin. JA4/JA3 TLS fingerprints, HTTP/2 wire format, header order, WASM proof-of-work, and WAF logic all run inside Rust hot paths.

L3 and L7 protection

Network-layer floods like SYN and UDP amplification are soaked up by anycast capacity. Application-layer abuse such as slow-loris, cache-busting, and HTTP flooding is neutralized by adaptive challenges before it reaches your code.

Anycast edge network

Distributed Rust nodes absorb floods at the source, and anycast routing pulls visitors to the nearest healthy POP. Attack volume gets diluted across the network instead of landing on your backend.

WAF rules and rate-limit

A Cloudflare-style engine lets you block, challenge, or allow on any mix of IP, ASN, country, JA4, path, method, headers, query, or body, with per-rule sliding-window limits. Built point-and-click in the dashboard, zero code.

Server-observed signals

Client-reported data is forgeable; the TLS handshake, JA4 fingerprint, HTTP/2 wire format, and header-arrival order are not. We rule on what a browser physically cannot fake.

Adaptive under attack

Thresholds tighten automatically as severity climbs. Per-ASN bursts trigger challenges, sustained floods escalate to under-attack mode, and replayed cookies are invalidated. The system grows harder under pressure, never slower.

Customizable caching and speed

Set cache level and query mode, browser and asset TTLs, immutable files, HTML page storage, bypass paths, and per-request rules where first match wins. Brotli and Gzip compression plus WebP optimization speed delivery, and hits are served straight from the edge.

Abuse-resistant hidden origin

DNS rotates A records in fast-flux style, turning the edge into a moving target. Your real server stays out of reach, so attackers can never lock onto a fixed IP.

0%
uptime
0B
req/day filtered
0ms
p50 latency

Pricing

Simple pricing that scales with you.

Pick a plan that fits today, then move up as your traffic or the attacks against it grow.

No credit card · Cancel anytime

Starter

$100/month

For a single site that needs real protection.

Get Started
  • 1 protected domain
  • Layer 3–7 protection
  • 5 custom WAF rules
  • 1 rate-limit rule
  • Point-and-click edge caching
  • Managed bot & flood blocking (JA3/JA4, ASN)
  • Support included
Most Popular

Pro

$250/month

For growing platforms under real traffic.

Get Started
  • 5 protected domains
  • Layer 3–7 protection
  • 20 custom WAF rules
  • 5 rate-limit rules
  • Point-and-click edge caching
  • Tor & WebSocket controls
  • Load balancer
  • Custom support

Enterprise

Custom

For high-traffic platforms and teams.

  • Unlimited domains
  • Unlimited WAF & rate-limit rules
  • Point-and-click edge caching
  • Managed bot & flood blocking (JA3/JA4, ASN)
  • Dedicated tuning & SLA
  • Priority 24/7 support

Ready to keep your site online?

Point your DNS and let Minlat Guard absorb the next attack, with no code changes and no Cloudflare lock-in.