TCPGUARD  //  NETWORK SECURITY OPERATIONS CENTER  ·  DXB ALL SCRUBBING CENTERS OPERATIONAL  ·  status.tcpguard.com
Mitigating L3–L7 since 2017

They flood.
We filter.
You stay online.

No single provider stops every kind of flood — anyone who says otherwise is selling you something. So we stacked the ones that actually work and tuned the rules by hand. Your origin stays hidden. Your site stays up.

Talk to an engineer →
2.5 Tbps+ capacity No null-routes 24/7 humans
SYN FloodUDP AmplificationDNS ReflectionHTTP/2 Rapid ResetSlowlorisACK FloodNTP / SSDP / Memcached AmpTLS RenegotiationLayer 7 Bot FloodsCarpet Bombing SYN FloodUDP AmplificationDNS ReflectionHTTP/2 Rapid ResetSlowlorisACK FloodNTP / SSDP / Memcached AmpTLS RenegotiationLayer 7 Bot FloodsCarpet Bombing
// INCIDENT RESPONSE

Site going down right now?

Skip the ticket queue. Tell us your domain and what you're seeing — we start pulling your traffic onto our edge and soaking up the flood immediately.

2.5Tbps+
Mitigation capacity
L3L7
Full-stack coverage
0ms
Null-route policy
2017
Operating since
// WHO'S BEHIND THE GLASS

A small team that has been doing this since 2017.

We are not a reseller dashboard with a support bot. TCPGuard is run by people who have spent years on the wrong end of a 600 Gbps flood at 3 in the morning — and learned exactly which knobs to turn.

We have opinions. We do not null-route you to make an attack "go away." We do not hide your origin behind a single CNAME and call it protection. We architect the stack around what you are actually defending, and we stay on the line until the graphs go flat.

If you have ever been told "just upgrade your plan" by a provider who clearly was not watching the traffic — you will understand why we built this.

TG — The TCPGuard NOCDubai · U.A.E · operating since 2017

// House rules

  • We pick up. Real engineers, not a queue.
  • No null-routes. No blackholes. We filter.
  • Your origin IP is sacred — it never leaks.
  • Rules are hand-tuned per target, not copy-pasted.
  • If we can't protect it well, we tell you straight.
// DEFENSE STACK

One provider can't cover everything. So we don't pretend to.

A layered defense built from carrier-grade networks and dedicated mitigation platforms — Voxility for Layer 3-4, Path for Layer 7, filtration tuned against Arbor PeakFlow telemetry, and custom ModSecurity rules to keep the naughty guys out.

Voxility
LAYER 3-4

Volumetric Mitigation — Voxility

Carrier-grade absorption of SYN floods, UDP amplification and reflection attacks across up to 100 Gbps ports. The flood never reaches your origin.

voxility.com ↗
Path.net
LAYER 7

Application Defense — Path

Dedicated Layer 7 filtering for HTTP/S floods and bot traffic. Real mitigation — no null-routing, no blackholes, no downtime windows.

path.net ↗
RoyaleHosting
EDGE FIREWALL

Advanced Firewall — RoyaleHosting

2.5 Tbps+ of upstream DDoS mitigation and managed firewall policy in front of your infrastructure, tuned per deployment.

royalehosting.net ↗
ModSecurity / OWASP CRS
WAF

Custom ModSecurity Rules

Hand-written WAF rules on top of the OWASP Core Rule Set to block exploit attempts and keep you operational around the clock.

owasp crs ↗
// PACKET PATH

Every packet earns its way to your origin.

Traffic lands on our scrubbing edge, gets inspected and filtered layer by layer, and only clean requests are proxied through to you.

tcpguard@edge — mitigation pipeline
# inbound traffic hits the scrubbing edge
edge ~$ ingest --proto any --port 0-65535
[L3-4] voxility  → SYN/UDP/reflection .......... SCRUBBED
[L7]   path     → http/s flood + bots ........... FILTERED
[WAF]  modsec  → owasp crs + custom rules ...... ENFORCED
[FW]   arbor   → peakflow telemetry ............ CLEAN
edge ~$ proxy --to origin --tls passthrough
# your origin only ever sees legitimate traffic.
// DEPLOYMENT

However you run, we sit in front of it.

Point your DNS at us, or let us host the whole thing. Either way the attack stops at our edge, not yours.

01 / PROXY

Reverse Proxy

Keep your existing host. Route traffic through our protected edge and hide your origin IP from the world.

02 / COMPUTE

Protected Virtual Machines

Spin up VMs that live behind our mitigation from day one — nothing exposed, nothing to leak.

03 / METAL

Dedicated Servers

Full bare-metal performance with carrier-grade DDoS protection baked into the network it lives on.

TCPGuard

Make a smarter security decision today.

Reverse proxy, virtual machine or dedicated server — tell us what you're defending and we'll architect the right stack for it.

GET IN TOUCH →
Accepted payment methods
tabby