Client Area →
Powered by the TOSCDN edge

Stop DDoS attacks instantly.

Secure your infrastructure with real Layer 7 protection.

Volumetric floods are the easy part. What actually takes sites down is Layer 7, HTTP floods, credential stuffing and API abuse arriving over valid TLS from convincing browsers. TOSHOST Shield inspects every request at the edge with TLS fingerprinting, a layered WAF, bot classification and adaptive challenge, in front of any application, with no code changes.

Multi-Tbps capacity Always-on, no rerouting L3 / L4 / L7 in one pass Transparent reverse proxy

Mitigation

Automatic · seconds

Layers
L3 / L4 / L7
Capacity
Multi-Tbps
Mode
Always-on
Edge PoPs
120+
Onboarding
DNS / Proxy
Protection solutions

Three layers, one edge

Every Shield plan covers all three. They are separated here because they fail in completely different ways, and only one of them is solved by raw capacity.

Website & API Protection

Layer 7 defence for anything that speaks HTTP, WordPress, WooCommerce, Laravel, headless APIs. WAF, bot management, challenge and rate limiting in front of your app, with no code changes.

See the Layer 7 stack

Network & DNS Protection

Your origin IP never appears in DNS again. Traffic terminates on the TOSCDN edge, is inspected, then forwarded over a private path your attackers cannot reach directly.

How origin masking works

Infrastructure & Layer 3/4 Defence

Volumetric floods, SYN, UDP, amplification and reflection, are absorbed and filtered at the network edge, long before they can reach an application server or saturate your uplink.

See network capabilities
The Layer 7 stack

Seven checks between an attacker and your application

A Layer 7 attack does not look like an attack. It arrives over a valid TLS session, requests a real URL and returns a 200. Capacity alone will never stop it, you have to inspect it. This is the exact order a request travels through the TOSCDN edge before your origin ever hears about it.

1

JA3 / JA4 fingerprinting

TLS handshake

Before a single byte of HTTP is read, we fingerprint the TLS ClientHello, cipher list, extensions, curves and their exact order. That identifies the client library, not the user-agent string it claims. A headless attack toolkit cannot hide behind a copied Chrome header.

Spoofed user-agents · headless toolkits · botnet TLS stacks

2

Bot classification

Access phase

Every request is scored into allow, block or pass. Verified search engines are allow-listed, but only if the IP genuinely belongs to Google, Bing or the rest, never on the user-agent alone. Known scanners, exploit kits and aggressive scrapers are blocked outright.

Vulnerability scanners · scrapers · fake Googlebot

3

ModSecurity + OWASP CRS

Rewrite phase

The full OWASP Core Rule Set, roughly 840 rules, runs in front of your application, with per-domain exclusions so a false positive on one site never weakens the ruleset for everyone else.

Injection · protocol abuse · known CVE payloads

4

TOSCDN signature WAF

Access phase

A second, deliberately narrow ruleset built for zero false positives: JIT-compiled PCRE signatures for SQL injection, XSS, path traversal, remote code execution and probes for sensitive files. Every rule is auditable, no opaque bytecode.

SQLi · XSS · traversal · RCE · config-file probes

5

Edge Rules engine

Rewrite phase

Your own declarative when / then policy, evaluated at the edge, block a country from checkout, rate-limit one API path, challenge a header pattern. Rules run after the WAF by design, so a rule can terminate a request but can never smuggle one past your protection.

Business-logic abuse · targeted campaigns · API misuse

6

Adaptive rate limiting

Access phase

A sliding-window counter per source IP. Cross the soft limit and you get a challenge; cross the hard limit and you are temporarily blocked, with the block escalating each time the same source comes back.

HTTP floods · credential stuffing · brute force · scraping

7

Global Protect challenge

Under attack

When an attack is detected the edge arms a JS challenge for every uncleared visitor, disarming itself automatically once the flood passes. Real browsers solve it invisibly and receive an HMAC-signed clearance cookie. Flood bots never do.

Layer 7 floods · botnets · request-per-second spikes

Your origin, and Always Online if it falls over

Only clean traffic reaches your server. If the origin goes down anyway, mid-attack or mid-deploy, cached URLs keep serving, your homepage is served from the last known-good snapshot, and everything else returns a branded notice instead of a raw 502. Your site keeps looking alive while you fix it.

Stages 1–4 and 6–7 are on every Shield plan. The Edge Rules engine and JA3/JA4 fingerprint blocking unlock on Shield Business.

Features & benefits

Built to be switched on and forgotten

Mitigation that needs a human to notice an attack has already failed. Shield decides on its own, then tells you what it did.

Real-Time Detection & Mitigation

Attacks are classified and mitigated automatically in seconds, no ticket, no phone call, no waiting for an engineer to flip a switch.

Global Anycast Edge

A 120+ PoP anycast footprint across four continents absorbs attack traffic close to its source and serves real visitors from the node nearest to them.

Intelligent Layered WAF

OWASP Core Rule Set and our own signature engine run together, tuned per domain so protection gets stricter without getting noisier.

No Latency Penalty

Cacheable responses are served straight from the edge and skip inspection entirely, so protection routinely makes a site faster rather than slower.

Custom Edge Rule Engine

Write your own when / then policy, by path, country, header, method or ASN, and push it to every edge node without touching your application.

24/7 Security Operations

Real engineers watching real attack telemetry, with rule-efficacy reporting so you can see exactly what was blocked and why.

Pricing

Enterprise protection, priced honestly

Every plan includes the full Layer 3/4 and Layer 7 stack. You are paying for scale, control and how fast a human answers, not for whether you are protected.

Save 17% with yearly billing

Shield Pro

Production sites and stores that cannot go down

$ 82.50 /mo

$99.00 Save 17%

Get Shield Pro
  • Always-on L3 / L4 + Layer 7 mitigation
  • Up to 5 protected hostnames
  • ModSecurity + OWASP Core Rule Set
  • TOSCDN signature WAF, SQLi, XSS, RCE, traversal
  • Adaptive rate limiting + JS challenge
  • Verified good-bot allow-list (SEO-safe)
  • Global Protect under-attack mode
  • Always Online origin failover
  • Real-time attack analytics
  • 24/7 ticket support
Most Popular

Shield Business

Multi-site platforms and APIs under constant pressure

$ 332.50 /mo

$399.00 Save 17%

Get Shield Business
  • Everything in Shield Pro
  • Up to 25 protected hostnames
  • JA3 / JA4 TLS fingerprint blocking
  • Custom Edge Rules engine (when / then)
  • Per-path and per-API rate-limit policies
  • Bot classifier with operator labelling
  • Custom CRS tuning + per-domain exclusions
  • Attack log export & rule-efficacy reporting
  • Priority support, 1-hour response
  • 99.99% uptime SLA
Dedicated

Shield Enterprise

Dedicated capacity, named engineers, contractual SLA

$ 1,249.17 /mo

$1,499.00 Save 17%

Get Shield Enterprise or talk to our security team →
  • Everything in Shield Business
  • Unlimited protected hostnames
  • Dedicated scrubbing capacity
  • Custom mitigation playbooks per application
  • Named security engineer + quarterly review
  • 24/7 SOC escalation, 15-minute response
  • Managed onboarding and migration
  • Private edge capacity on request
  • Contractual SLA with service credits
  • Invoice / PO billing

Prices shown in USD. Protection applies to any origin, on our network or anyone else's. Need more than Shield Enterprise, or a custom on-ramp? Talk to us.

FAQ

Questions, answered

Get behind the edge before the next attack

Onboarding is a DNS change. Protection is live in minutes, your application never changes, and real engineers are watching the telemetry 24/7.