Skip to content
DEFLECTO
Always on, no reconfiguration under attack

Hostile traffic, deflected.
Your infrastructure, always online.

DEFLECTO is a Layer 7 web application firewall and reverse proxy that absorbs network-layer floods in front of it. Hostile requests are dropped, challenged or starved at the edge. What reaches your origin is the traffic you actually wanted.

Scope
L3 / L4 / L7
Deflection
Sub-second, automatic
Metered
Legitimate requests only

Deployed in front of

  • FinTech
  • iGaming
  • E-commerce
  • SaaS
  • Media
  • Public sector
The problem

Downtime is not a server problem. It is a customer problem.

An outage costs you customers, credibility, and an engineering team stuck firefighting instead of shipping. Modern floods are cheap to rent by the hour and hard to stop with a classic firewall, because most of them look like ordinary traffic right up until they do not.

  • Volumetric saturation

    The uplink fills with junk before a single packet reaches your application. The server is perfectly healthy and completely unreachable at the same time.

  • L7 floods that mimic real users

    Well formed HTTP requests, plausible headers, real TLS handshakes. Any rule blunt enough to block them blocks your customers with them.

  • Low and slow exhaustion

    A handful of connections held open, requests fed a byte at a time, until worker pools and connection tables are gone. The bandwidth graph stays flat throughout.

  • Extortion

    The first burst is a demonstration. The message that follows names a price for the second one not happening.

Proof of work

A challenge costs a visitor a moment. It costs a flood its entire business case.

When a client looks suspicious, DEFLECTO does not guess and block it. It hands the client a computational puzzle and waits for the answer. A browser solves it in about the time the page takes to appear, and nobody is asked to identify a bicycle.

An attacker has to solve the same puzzle, once per request, on every machine in the botnet. That is the whole idea. A flood is only viable while requests are free to send, so making each one pay for itself breaks the arithmetic that funds the attack. The traffic does not have to be identified as hostile, it only has to become uneconomic.

Real visitor
A moment of CPU in the background while the page loads. No CAPTCHA, nothing to read, nothing to click, nothing to fail.
Attacker
The same cost, paid again for every request in the flood, on hardware they are renting by the hour.
Under load
Difficulty tracks pressure. Quiet traffic is waved through, a surge is made progressively more expensive to sustain.

No CAPTCHA. Nothing for a human to solve.

Capabilities

One platform. Every vector, covered.

From the network edge to the application layer, DEFLECTO refuses attacks across the whole spectrum without slowing down the traffic you want.

L3, L4 and L7 from one layer

Volumetric, protocol and application filtering in a single pipeline. SYN and UDP floods and HTTP requests that imitate real users are handled in the same place, not by three products you have to reconcile.

Absorption near the client

Traffic enters a globally distributed network, so hostile volume is soaked up close to where it is generated instead of arriving intact at your uplink.

Managed WAF

OWASP rule coverage, per-route rate limiting and signatures that are updated continuously. Maintaining the ruleset is our job, not a chore we hand back to you.

Monitoring, 24/7

The network is watched around the clock. An anomaly reaches an engineer, not a ticket queue that opens again on Monday morning.

Sub-second deflection

Mitigation engages automatically. There is no console to log into, no rule to switch on and no phone call to place while the site is down.

Full visibility

Real-time reporting on what was allowed, what was challenged and what was dropped, with the evidence behind each decision kept alongside it.

How it works

We detect. We deflect. We deliver.

Three steps that run continuously and automatically, in milliseconds, without anyone pressing a button.

We detect

Every request is inspected at the edge. Patterns, signatures and behaviour are evaluated in milliseconds, long before the request is anywhere near your application.

We deflect

Hostile volume is absorbed and filtered. Suspicious clients are handed a challenge. Only the requests that earn their way through continue to your origin.

We deliver

Real users carry on without noticing that anything happened, and you get a report describing exactly what did.

Billing

Attacks are never metered.

Plans are quoted in legitimate requests forwarded to your origin, and that is the only thing a quota counts. Floods, refused probes and challenged bots are handled for free. Under ordinary per-request billing the invoice arrives precisely because you were attacked, and charging you for somebody else's botnet is not a business we want to be in.

What counts against a monthly quota
TrafficQuota
Legitimate requests forwarded to your originCounted
Volumetric floods absorbed at the edgeFree
Requests refused by the WAFFree
Clients handed a proof-of-work challengeFree
Service level

Commitments in writing, with penalties attached.

We do not sell best effort. The contract names an availability figure and a mitigation time, and it names what we owe you if we miss either one.

  • Availability committed in the contract, not implied in a brochure
  • Automatic mitigation within a stated time, measured from the first hostile packet
  • Emergency support 24/7/365, staffed by engineers who can change the configuration
  • Zero-downtime onboarding, cut over when you are ready and not before
  • Service credits when we miss a commitment we made
Next step

Already under attack, or making sure you never are.

Both are good reasons to talk. We will look at your exposure, tell you plainly what we would do about it, and if you are in the middle of an incident we can onboard you the same day.