Enterprise protection included on every plan
Always-on DDoS mitigation, a configurable firewall, SSH key injection, and full DNS control — the same security stack on a $16 VPS and a $2,000 dedicated server. No upsells, no activation tickets.
Edge DDoS mitigation
Multi-layer scrubbing at the network edge filters volumetric floods and common L7 attacks before traffic hits your instance. Active by default on every server.
Stateful firewall
Define inbound and outbound rules by port, protocol, and source IP from the control panel. Sensible baselines applied at provision time.
SSH key authentication
Upload public keys to your account and inject them when servers are created. Disable password login for production hardening.
Automatic mitigation — no manual activation
Unlike hosts that treat DDoS as a premium add-on, Super Lambda scrubs attack traffic upstream so your server keeps serving legitimate requests.
Multi-layer edge filtering
Incoming traffic passes through edge scrubbing that detects and drops abusive patterns. Your instance receives only clean traffic on its dedicated IPv4 and /64 IPv6 block.
- Volumetric flood mitigation (UDP/TCP saturation)
- Common application-layer attack filtering
- No per-incident fees or activation delays
- Same protection on VPS and dedicated servers
Firewall, DNS, and access in one place
Manage security alongside provisioning — no separate portals for DNS or firewall rules.
Physical security and data residency
- Physical access
- CCTV, biometric entry, 24/7 on-site staff
- Network segmentation
- Customer traffic isolated at the edge
- Management plane
- TLS 1.2+ for panel and API access
- GDPR
- EU data residency in German regions
- IPMI / KVM
- Out-of-band console on dedicated servers
- Support access
- Instance data accessed only when you request help
Security questions
Is DDoS protection included on every plan?
Yes. Every VPS and dedicated server includes always-on multi-layer DDoS mitigation at no extra cost — no activation ticket required.
What types of attacks are mitigated?
Edge scrubbing handles common volumetric floods and application-layer patterns. Extremely large or novel attacks may be rate-limited to protect the broader network — we will contact you if sustained mitigation affects your service.
Can I configure firewall rules myself?
Yes. The control panel includes a stateful firewall. Define rules by port, protocol, and source IP. Defaults allow SSH and common web ports; tighten as needed.
How do SSH keys work?
Upload public keys to your account. Select which keys to inject when provisioning or reinstalling. Password authentication can be disabled for hardened setups.
Can I manage DNS records?
Yes. Full DNS zone editing for A, AAAA, MX, TXT, and CNAME records, plus configurable reverse DNS (PTR) on your primary IPv4.
Is there a fair-use limit on protected traffic?
DDoS mitigation is unlimited for legitimate server workloads. Sustained abusive traffic that threatens network stability may be throttled — aligned with our fair-use policy for outbound bandwidth.
Security included — pick your server
Every plan ships with the same DDoS stack, firewall, and DNS tools. Compare specs and deploy in under a minute.