Hosting & infrastructure

What DDoS protection do you provide?

1.5+ Tbps mitigation capacity included on all services (L3/L4). Layer-7 attacks need WAF activation — free request on managed services, paid add-on otherwise.

Default protection (included on every service)

Every PhotonSpark service sits behind upstream DDoS mitigation with 1.5+ Tbps of scrubbing capacity, via our partner AS199414. This absorbs automatically:

  • Layer 3 attacks (raw packet floods, amplification, reflection).
  • Layer 4 attacks (SYN floods, UDP floods, connection exhaustion).

These mitigate transparently. You will not see alerts unless mitigation drops your traffic, which happens only with very large or unusually-shaped attacks.

Layer 7 (HTTP/HTTPS) protection

Application-layer attacks (HTTP floods, slow-loris, credential stuffing, scrapers) are not in the default — those need a tuned WAF.

To enable WAF:

  • Managed services — open a ticket; we configure within 4 business hours, no extra charge.
  • Self-managed services — configure yourself (we recommend Cloudflare or BunkerWeb), or we configure as a paid add-on.

During an active attack

  1. Open a Sev-1 ticket with "active DDoS" in the subject.
  2. Hop on Discord and ping @PhotonSpark Ops.
  3. Send us the target (domain, IP, path) and a sample of malicious traffic if you have it.

Our SOC engages within 15 minutes for active attacks. Most absorb without intervention; if we need to act, we will.

Limits

  • Attacks above 1.5 Tbps may be rate-limited or partially blackholed. Rare (zero in the last 18 months) but possible.
  • Repeated targeted attacks may require a paid always-on WAF if your application is a high-value target.

High-risk launches

Launching something likely to attract attention (NFT drop, big PR, controversial content)? Tell us 48 hours in advance. We pre-position scrubbing capacity and tune the WAF before traffic arrives.