Stop DDoS attacks instantly.
Secure your infrastructure with real Layer 7 protection.
Volumetric floods are the easy part. What actually takes sites down is Layer 7, HTTP floods, credential stuffing and API abuse arriving over valid TLS from convincing browsers. TOSHOST Shield inspects every request at the edge with TLS fingerprinting, a layered WAF, bot classification and adaptive challenge, in front of any application, with no code changes.
Mitigation
Automatic · seconds
Three layers, one edge
Every Shield plan covers all three. They are separated here because they fail in completely different ways, and only one of them is solved by raw capacity.
Website & API Protection
Layer 7 defence for anything that speaks HTTP, WordPress, WooCommerce, Laravel, headless APIs. WAF, bot management, challenge and rate limiting in front of your app, with no code changes.
See the Layer 7 stackNetwork & DNS Protection
Your origin IP never appears in DNS again. Traffic terminates on the TOSCDN edge, is inspected, then forwarded over a private path your attackers cannot reach directly.
How origin masking worksInfrastructure & Layer 3/4 Defence
Volumetric floods, SYN, UDP, amplification and reflection, are absorbed and filtered at the network edge, long before they can reach an application server or saturate your uplink.
See network capabilitiesSeven checks between an attacker and your application
A Layer 7 attack does not look like an attack. It arrives over a valid TLS session, requests a real URL and returns a 200. Capacity alone will never stop it, you have to inspect it. This is the exact order a request travels through the TOSCDN edge before your origin ever hears about it.
JA3 / JA4 fingerprinting
TLS handshakeBefore a single byte of HTTP is read, we fingerprint the TLS ClientHello, cipher list, extensions, curves and their exact order. That identifies the client library, not the user-agent string it claims. A headless attack toolkit cannot hide behind a copied Chrome header.
Spoofed user-agents · headless toolkits · botnet TLS stacks
Bot classification
Access phaseEvery request is scored into allow, block or pass. Verified search engines are allow-listed, but only if the IP genuinely belongs to Google, Bing or the rest, never on the user-agent alone. Known scanners, exploit kits and aggressive scrapers are blocked outright.
Vulnerability scanners · scrapers · fake Googlebot
ModSecurity + OWASP CRS
Rewrite phaseThe full OWASP Core Rule Set, roughly 840 rules, runs in front of your application, with per-domain exclusions so a false positive on one site never weakens the ruleset for everyone else.
Injection · protocol abuse · known CVE payloads
TOSCDN signature WAF
Access phaseA second, deliberately narrow ruleset built for zero false positives: JIT-compiled PCRE signatures for SQL injection, XSS, path traversal, remote code execution and probes for sensitive files. Every rule is auditable, no opaque bytecode.
SQLi · XSS · traversal · RCE · config-file probes
Edge Rules engine
Rewrite phaseYour own declarative when / then policy, evaluated at the edge, block a country from checkout, rate-limit one API path, challenge a header pattern. Rules run after the WAF by design, so a rule can terminate a request but can never smuggle one past your protection.
Business-logic abuse · targeted campaigns · API misuse
Adaptive rate limiting
Access phaseA sliding-window counter per source IP. Cross the soft limit and you get a challenge; cross the hard limit and you are temporarily blocked, with the block escalating each time the same source comes back.
HTTP floods · credential stuffing · brute force · scraping
Global Protect challenge
Under attackWhen an attack is detected the edge arms a JS challenge for every uncleared visitor, disarming itself automatically once the flood passes. Real browsers solve it invisibly and receive an HMAC-signed clearance cookie. Flood bots never do.
Layer 7 floods · botnets · request-per-second spikes
Your origin, and Always Online if it falls over
Only clean traffic reaches your server. If the origin goes down anyway, mid-attack or mid-deploy, cached URLs keep serving, your homepage is served from the last known-good snapshot, and everything else returns a branded notice instead of a raw 502. Your site keeps looking alive while you fix it.
Stages 1–4 and 6–7 are on every Shield plan. The Edge Rules engine and JA3/JA4 fingerprint blocking unlock on Shield Business.
Built to be switched on and forgotten
Mitigation that needs a human to notice an attack has already failed. Shield decides on its own, then tells you what it did.
Real-Time Detection & Mitigation
Attacks are classified and mitigated automatically in seconds, no ticket, no phone call, no waiting for an engineer to flip a switch.
Global Anycast Edge
A 120+ PoP anycast footprint across four continents absorbs attack traffic close to its source and serves real visitors from the node nearest to them.
Intelligent Layered WAF
OWASP Core Rule Set and our own signature engine run together, tuned per domain so protection gets stricter without getting noisier.
No Latency Penalty
Cacheable responses are served straight from the edge and skip inspection entirely, so protection routinely makes a site faster rather than slower.
Custom Edge Rule Engine
Write your own when / then policy, by path, country, header, method or ASN, and push it to every edge node without touching your application.
24/7 Security Operations
Real engineers watching real attack telemetry, with rule-efficacy reporting so you can see exactly what was blocked and why.
Enterprise protection, priced honestly
Every plan includes the full Layer 3/4 and Layer 7 stack. You are paying for scale, control and how fast a human answers, not for whether you are protected.
Shield Pro
Production sites and stores that cannot go down
$99.00 Save 17%
- Always-on L3 / L4 + Layer 7 mitigation
- Up to 5 protected hostnames
- ModSecurity + OWASP Core Rule Set
- TOSCDN signature WAF, SQLi, XSS, RCE, traversal
- Adaptive rate limiting + JS challenge
- Verified good-bot allow-list (SEO-safe)
- Global Protect under-attack mode
- Always Online origin failover
- Real-time attack analytics
- 24/7 ticket support
Shield Business
Multi-site platforms and APIs under constant pressure
$399.00 Save 17%
- Everything in Shield Pro
- Up to 25 protected hostnames
- JA3 / JA4 TLS fingerprint blocking
- Custom Edge Rules engine (when / then)
- Per-path and per-API rate-limit policies
- Bot classifier with operator labelling
- Custom CRS tuning + per-domain exclusions
- Attack log export & rule-efficacy reporting
- Priority support, 1-hour response
- 99.99% uptime SLA
Shield Enterprise
Dedicated capacity, named engineers, contractual SLA
$1,499.00 Save 17%
- Everything in Shield Business
- Unlimited protected hostnames
- Dedicated scrubbing capacity
- Custom mitigation playbooks per application
- Named security engineer + quarterly review
- 24/7 SOC escalation, 15-minute response
- Managed onboarding and migration
- Private edge capacity on request
- Contractual SLA with service credits
- Invoice / PO billing
Prices shown in USD. Protection applies to any origin, on our network or anyone else's. Need more than Shield Enterprise, or a custom on-ramp? Talk to us.
Questions, answered
Get behind the edge before the next attack
Onboarding is a DNS change. Protection is live in minutes, your application never changes, and real engineers are watching the telemetry 24/7.