ZERO-PROTECT DDoS Protection
German DDoS Protection · BSI-Qualified

Keep your sites and APIs online under attack

Multi-layer mitigation on our own German network (AS215197). GDPR-compliant, no foreign jurisdiction, no shared tenancy.

BSI. Bundesamt für Sicherheit in der Informationstechnik

Qualified by the Federal Office for Information Security

Zero Services GmbH was listed in 2026 as a BSI-qualified DDoS mitigation service provider under §3 BSIG. Tested and qualified to defend operators of critical infrastructure (KRITIS) by Germany's national cyber security authority. Read the full story →

0

Own Network & Datacenters

0

Metrics Monitored

0

Years Infrastructure Experience

0

Datacenters Worldwide

Ten Stages. One Pipeline.

Every request passes through a sequential chain. Volumetric attacks are dropped at the network edge. What reaches your origin is clean.

1

L3/L4 Volumetric Filtering

BGP Flowspec rules drop UDP floods, SYN floods, and amplification attacks at the network edge within seconds.

2

JA4 TLS Fingerprinting

Detects bot frameworks by TLS handshake signature, independent of IP rotation.

3

Access Rules

Customer-defined rules matching on geo, IP, ASN, JA4 fingerprint, or URL path. Plus self-learning reputation lists we maintain from our own edge data.

4

Connection Rate Limiting

TCP-level flood protection with zero CPU overhead. Slow-HTTP defense catches Slowloris and Slow POST.

5

HTTP Rate Limiting

Per-IP, per-path, per-fingerprint request rate control. Cluster-synchronized across all edge nodes.

6

JA4 / Path Rate Limiting

Granular rate limiting by TLS fingerprint and URL path for targeted bot mitigation.

7

Proof-of-Work Challenge

Argon2-based puzzles. Browsers solve them in milliseconds. Bot farms burn CPU.

8

Edge Cache

Per-service cache reduces origin load during attacks and improves TTFB.

9

Layer 7 WAF

Coraza WAF with OWASP CRS. Per-service containers. Tunable paranoia levels.

Your Origin

Clean traffic only.

Protect Your Infrastructure

DDoS Resiliency Score

Level 6 / 7

“Extreme”

Measured Against a Public, Vendor-Neutral Standard

Zero Services GmbH self-assesses at DRS 6. “Extreme” on the seven-level DDoS Resiliency Score by Red Button Ltd. That envelope covers cache-bypassing patterns, bot networks that rotate fingerprints, and direct-IP vectors. Read how we score ourselves →

Self-Service Portal

Configure, monitor, and respond, without tickets or waiting.

ACL

Visual ACL Rule Builder

Match on geo, ASN, IP, path, JA4 fingerprint. Block, rate-limit, challenge, or allow. Drag-and-drop priority.

Metrics

Live Metrics & Edge Status

RPS, bandwidth, response codes, threats blocked. Real-time health of all edge nodes at a glance.

SSL

SSL & Certificate Management

ACME automation (Let's Encrypt, Buypass, ZeroSSL, Google) or custom upload. Auto-renewal, zero downtime.

Emergency

Emergency Actions

Instant blocking and maintenance mode. Propagates to all edge nodes within seconds.

Audit

Audit Logging

Every change logged with timestamp, user, and diff. Full traceability for compliance.

Branding

White-Label Branding

Custom logo, colors, challenge pages, error pages. Full branding on Dedicated plan.

Built for Infrastructure Teams

A full edge platform on our own network (AS215197). German and European data residency. No third-party bottlenecks.

Architecture

Resilient Architecture

Multi-site anycast edge nodes with git-based config distribution. Edge nodes keep running if the control plane is down.

Health Checks

Health Checking & Load Balancing

Active health checks. Automatic failover. Traffic distributed across healthy backends.

Origin Shielding

Forward Proxy & Origin Shielding

Backhaul via CrossConnect, MPLS, or VPN. Origin never exposed to the public internet.

TCP & Transit

TCP, AnyConnect & IP-Transit

Protect TCP services and VPN endpoints. Standalone L3/L4 filtering available for IP-Transit customers.

Team

One Team. Fixed Contacts.

The same team that runs the servers, the clusters, and the network also builds and operates ZERO-PROTECT. No hand-offs.

Metrics Export

Prometheus Metrics Export

Per-service metrics for your own Grafana, alerting, and long-term retention.

Built for Industries That Cannot Go Offline

BSI-qualified. German infrastructure. For organizations where downtime has real consequences.

KRITIS

Critical Infrastructure (KRITIS)

Utilities, energy, telecom, government. BSI-qualified per §3 BSIG. German data residency in ISO/IEC 27001-certified datacenters. Audit logging for compliance.

E-Commerce

E-Commerce & High-Traffic Services

Every minute of downtime is lost revenue. Edge caching, instant emergency actions, and transparent clean-traffic billing.

Finance

Finance & Insurance

Strict compliance requirements. German contract partner. Full audit trail. Dedicated edge nodes for complete tenant isolation.

Shared or Dedicated Edge

Edge nodes are the servers between the internet and your origin. They terminate TLS, run the entire protection pipeline, and forward only clean traffic to your infrastructure. Both models run the full pipeline. Shared is ordered online and live within minutes. Dedicated adds reserved capacity and custom configuration.

Dedicated

Your own edge nodes, exclusively for you. Guaranteed capacity and custom configuration.

from €3,390 /month

€2,000 setup. 12-month term, billed monthly.

  • Edge nodes reserved entirely for your traffic
  • 20 TB clean traffic per month included, then €20 per TB
  • Multiple FQDNs
  • Dedicated IP range (min. /24 IPv4 + /48 IPv6) or BYOIP
  • White-labeling and custom challenge and error pages
  • Free location choice in Germany and the Netherlands
  • Provisioned within 5 to 10 business days

All prices exclude VAT.

Frequently Asked Questions

Yes. Shared is ordered online at €440 per month with no setup fee. You enter the FQDN to protect, pay, and the service is provisioned automatically. Switch your DNS to the edge and you are live within minutes. If you prefer a guided start, choose guided onboarding in the cart: we open a ticket with you, configure everything together and check your origin. It is billed by effort according to our Terms of Service.

Layer 3/4 mitigation via BGP Flowspec is applied at the network edge within seconds. Layer 7 protections (rate limiting, PoW challenges, WAF) are always-on. They don't need to "kick in" because they're already active on every request.

Instead of showing a CAPTCHA, we send the browser a small computational puzzle (Argon2-based). A real browser solves it in milliseconds. The user doesn't notice. A bot farm needs real CPU time per request, making large-scale L7 attacks economically unviable. Difficulty is adjustable per service.

JA4 creates a fingerprint from TLS handshake parameters. Cipher suites, extensions, supported versions. Bots using the same framework produce identical fingerprints even when rotating through thousands of IPs. We rate-limit by fingerprint, not just by IP.

Yes. You point your DNS records to the ZERO-PROTECT anycast IPs and the edge filters everything before it reaches your origin. Step by step in the onboarding guide.

All traffic processing happens on German and European infrastructure (AS215197). Zero Services GmbH is a German company. No CLOUD Act. No FISA 702. Your traffic data stays in Europe.

White-label branding (custom logo, colors, support URLs, challenge page text, error pages) is available on the Dedicated plan. Shared customers can customize challenge and error page text.

Yes. Zero Services GmbH is listed as a BSI-qualified DDoS mitigation provider pursuant to §3 BSIG. All traffic processing runs on German and European infrastructure (AS215197). The qualification is specifically designed for providers serving operators of critical infrastructure.

We measure ourselves against the DDoS Resiliency Score (a public, vendor-neutral standard) and currently self-assess at DRS 6 (Extreme: cache-bypass, fingerprint rotation, direct-IP). We don't quote vague Tbps numbers.

Yes. Customers with their own prefixes get standalone L3/L4 protection via BGP Flowspec, no DNS change and no reverse proxy. Details in the onboarding guide.

Ready to Protect Your Infrastructure?

Describe your setup. We'll recommend the right plan, onboard you to the portal, and stay available whenever you need us.