Multi-layer mitigation on our own German network (AS215197). GDPR-compliant, no foreign jurisdiction, no shared tenancy.
Zero Services GmbH was listed in 2026 as a BSI-qualified DDoS mitigation service provider under §3 BSIG. Tested and qualified to defend operators of critical infrastructure (KRITIS) by Germany's national cyber security authority. Read the full story →
Own Network & Datacenters
Metrics Monitored
Years Infrastructure Experience
Datacenters Worldwide
Every request passes through a sequential chain. Volumetric attacks are dropped at the network edge. What reaches your origin is clean.
BGP Flowspec rules drop UDP floods, SYN floods, and amplification attacks at the network edge within seconds.
Detects bot frameworks by TLS handshake signature, independent of IP rotation.
Customer-defined rules matching on geo, IP, ASN, JA4 fingerprint, or URL path. Plus self-learning reputation lists we maintain from our own edge data.
TCP-level flood protection with zero CPU overhead. Slow-HTTP defense catches Slowloris and Slow POST.
Per-IP, per-path, per-fingerprint request rate control. Cluster-synchronized across all edge nodes.
Granular rate limiting by TLS fingerprint and URL path for targeted bot mitigation.
Argon2-based puzzles. Browsers solve them in milliseconds. Bot farms burn CPU.
Per-service cache reduces origin load during attacks and improves TTFB.
Coraza WAF with OWASP CRS. Per-service containers. Tunable paranoia levels.
Clean traffic only.
DDoS Resiliency Score
Level 6 / 7
“Extreme”
Zero Services GmbH self-assesses at DRS 6. “Extreme” on the seven-level DDoS Resiliency Score by Red Button Ltd. That envelope covers cache-bypassing patterns, bot networks that rotate fingerprints, and direct-IP vectors. Read how we score ourselves →
Configure, monitor, and respond, without tickets or waiting.
Match on geo, ASN, IP, path, JA4 fingerprint. Block, rate-limit, challenge, or allow. Drag-and-drop priority.
RPS, bandwidth, response codes, threats blocked. Real-time health of all edge nodes at a glance.
ACME automation (Let's Encrypt, Buypass, ZeroSSL, Google) or custom upload. Auto-renewal, zero downtime.
Instant blocking and maintenance mode. Propagates to all edge nodes within seconds.
Every change logged with timestamp, user, and diff. Full traceability for compliance.
Custom logo, colors, challenge pages, error pages. Full branding on Dedicated plan.
A full edge platform on our own network (AS215197). German and European data residency. No third-party bottlenecks.
Multi-site anycast edge nodes with git-based config distribution. Edge nodes keep running if the control plane is down.
Active health checks. Automatic failover. Traffic distributed across healthy backends.
Backhaul via CrossConnect, MPLS, or VPN. Origin never exposed to the public internet.
Protect TCP services and VPN endpoints. Standalone L3/L4 filtering available for IP-Transit customers.
The same team that runs the servers, the clusters, and the network also builds and operates ZERO-PROTECT. No hand-offs.
Per-service metrics for your own Grafana, alerting, and long-term retention.
BSI-qualified. German infrastructure. For organizations where downtime has real consequences.
Utilities, energy, telecom, government. BSI-qualified per §3 BSIG. German data residency in ISO/IEC 27001-certified datacenters. Audit logging for compliance.
Every minute of downtime is lost revenue. Edge caching, instant emergency actions, and transparent clean-traffic billing.
Strict compliance requirements. German contract partner. Full audit trail. Dedicated edge nodes for complete tenant isolation.
Yes. Shared is ordered online at €440 per month with no setup fee. You enter the FQDN to protect, pay, and the service is provisioned automatically. Switch your DNS to the edge and you are live within minutes. If you prefer a guided start, choose guided onboarding in the cart: we open a ticket with you, configure everything together and check your origin. It is billed by effort according to our Terms of Service.
Layer 3/4 mitigation via BGP Flowspec is applied at the network edge within seconds. Layer 7 protections (rate limiting, PoW challenges, WAF) are always-on. They don't need to "kick in" because they're already active on every request.
Instead of showing a CAPTCHA, we send the browser a small computational puzzle (Argon2-based). A real browser solves it in milliseconds. The user doesn't notice. A bot farm needs real CPU time per request, making large-scale L7 attacks economically unviable. Difficulty is adjustable per service.
JA4 creates a fingerprint from TLS handshake parameters. Cipher suites, extensions, supported versions. Bots using the same framework produce identical fingerprints even when rotating through thousands of IPs. We rate-limit by fingerprint, not just by IP.
Yes. You point your DNS records to the ZERO-PROTECT anycast IPs and the edge filters everything before it reaches your origin. Step by step in the onboarding guide.
All traffic processing happens on German and European infrastructure (AS215197). Zero Services GmbH is a German company. No CLOUD Act. No FISA 702. Your traffic data stays in Europe.
White-label branding (custom logo, colors, support URLs, challenge page text, error pages) is available on the Dedicated plan. Shared customers can customize challenge and error page text.
Yes. Zero Services GmbH is listed as a BSI-qualified DDoS mitigation provider pursuant to §3 BSIG. All traffic processing runs on German and European infrastructure (AS215197). The qualification is specifically designed for providers serving operators of critical infrastructure.
We measure ourselves against the DDoS Resiliency Score (a public, vendor-neutral standard) and currently self-assess at DRS 6 (Extreme: cache-bypass, fingerprint rotation, direct-IP). We don't quote vague Tbps numbers.
Yes. Customers with their own prefixes get standalone L3/L4 protection via BGP Flowspec, no DNS change and no reverse proxy. Details in the onboarding guide.
Describe your setup. We'll recommend the right plan, onboard you to the portal, and stay available whenever you need us.