Security

Enterprise protection included on every plan

Always-on DDoS mitigation, a configurable firewall, SSH key injection, and full DNS control — the same security stack on a $16 VPS and a $2,000 dedicated server. No upsells, no activation tickets.

DDoS automatic Firewall included SSH keys at provision DNS editor in panel

Edge DDoS mitigation

Multi-layer scrubbing at the network edge filters volumetric floods and common L7 attacks before traffic hits your instance. Active by default on every server.

Stateful firewall

Define inbound and outbound rules by port, protocol, and source IP from the control panel. Sensible baselines applied at provision time.

SSH key authentication

Upload public keys to your account and inject them when servers are created. Disable password login for production hardening.

How protection works

Automatic mitigation — no manual activation

Unlike hosts that treat DDoS as a premium add-on, Super Lambda scrubs attack traffic upstream so your server keeps serving legitimate requests.

Multi-layer edge filtering

Incoming traffic passes through edge scrubbing that detects and drops abusive patterns. Your instance receives only clean traffic on its dedicated IPv4 and /64 IPv6 block.

  • Volumetric flood mitigation (UDP/TCP saturation)
  • Common application-layer attack filtering
  • No per-incident fees or activation delays
  • Same protection on VPS and dedicated servers
99.9%
Platform uptime SLA
Control panel

Firewall, DNS, and access in one place

Manage security alongside provisioning — no separate portals for DNS or firewall rules.

FirewallActive
SSH22Allow
HTTP80Allow
HTTPS443Allow
All otherDeny
DNS zoneexample.com
A@ → 203.0.113.10
AAAA@ → 2001:db8::1
MXmail.example.com
TXTv=spf1 include:…
SSH keys2 keys
laptoped25519Inject
ci-runnerrsa-4096Inject
Keys applied on next provision or reinstall
Datacenter & compliance

Physical security and data residency

Physical access
CCTV, biometric entry, 24/7 on-site staff
Network segmentation
Customer traffic isolated at the edge
Management plane
TLS 1.2+ for panel and API access
GDPR
EU data residency in German regions
IPMI / KVM
Out-of-band console on dedicated servers
Support access
Instance data accessed only when you request help
FAQ

Security questions

Is DDoS protection included on every plan?

Yes. Every VPS and dedicated server includes always-on multi-layer DDoS mitigation at no extra cost — no activation ticket required.

What types of attacks are mitigated?

Edge scrubbing handles common volumetric floods and application-layer patterns. Extremely large or novel attacks may be rate-limited to protect the broader network — we will contact you if sustained mitigation affects your service.

Can I configure firewall rules myself?

Yes. The control panel includes a stateful firewall. Define rules by port, protocol, and source IP. Defaults allow SSH and common web ports; tighten as needed.

How do SSH keys work?

Upload public keys to your account. Select which keys to inject when provisioning or reinstalling. Password authentication can be disabled for hardened setups.

Can I manage DNS records?

Yes. Full DNS zone editing for A, AAAA, MX, TXT, and CNAME records, plus configurable reverse DNS (PTR) on your primary IPv4.

Is there a fair-use limit on protected traffic?

DDoS mitigation is unlimited for legitimate server workloads. Sustained abusive traffic that threatens network stability may be throttled — aligned with our fair-use policy for outbound bandwidth.

Security included — pick your server

Every plan ships with the same DDoS stack, firewall, and DNS tools. Compare specs and deploy in under a minute.