Most DDoS tools are built to absorb volume. But the attacks that actually take sites down are quiet: bots posing as customers, slow drains, credential stuffing, fake checkouts, API floods that look perfectly ordinary. They look like traffic you want. Generic filters either miss them, or block your real customers trying to catch them.
Itnetic does one thing: surgical Layer-7 DDoS mitigation, plus a CDN on the same edge network. Change two DNS records, live in minutes. No hardware, no agents, no rules to tune, no professional-services invoice.
How it works
Our edge stacks defenses instead of betting on one signal:
Layered flood detection — page loads, cookieless traffic and API/asset floods are watched separately, so an attack that dodges one still trips another.
Learns your normal — a rolling per-domain baseline catches attacks that stay under every fixed threshold but are far above what your site normally does.
Challenges that cost bots, not customers — attackers burn real CPU to get through; a real browser passes in under a second and stays trusted.
Catches "solve once, then flood" — a bot that passes and then abuses it loses that trust instantly.
Behavioral fingerprinting — recognizes an attacker by how it browses, so rotating through thousands of IPs doesn't help.
ML bot scoring — trained on your own traffic, retrained continuously. Suspicious visitors get challenged, not blocked: a false positive costs one puzzle, never a customer.
Shield — if an attack starts while someone is browsing, their failed requests are recovered and replayed automatically. They see a spinner, not an error page.
Everything else at the edge
🌍 Global CDN + edge caching on the same network that filters your attacks
🔒 Free automatic SSL, HTTP/2, WebSockets
🛡️ Custom WAF rules and per-route rate limiting
🚦 Waiting room — cap concurrent visitors and queue the rest with live position and ETA, so a launch doesn't melt your origin
⚖️ Origin load balancing — up to 8 upstreams, weighted or IP-hash, with automatic failover
🪣 Private bucket origins — serve from a private S3-compatible bucket, no public bucket needed
🤖 Good-bot allowlist — Google and Bing aren't your attackers
📊 Live request logs + analytics — every request and block with its reason, plus origin response times, error rates and slowest endpoints
🗺️ Live traffic map by country and location
🔔 Attack alerts to Discord and email, with a chart of what hit you
🔑 Passkey login, team accounts, documented public REST API
🌐 Dashboard in English, Czech, German and French
Network: Warsaw 🇵🇱, Toronto 🇨🇦, Singapore 🇸🇬 — zero-downtime deploys, so shipping an update never costs you a request.
Pricing: Free forever tier (1 domain, 2 GB/mo). Hobby €10, Pro €29, Business €99, Enterprise €1,000. Every plan gets the full protection stack — no enterprise-only security. Plans differ on domains and bandwidth, not on whether you're allowed to be protected.
Built with