# Flowtriq — LLMs.txt # Last Updated: 2026-06-14 # Company Name: Flowtriq Legal Entity: Flowtriq, a brand of traztech Website: https://flowtriq.com Category: Network Security / DDoS Detection & Mitigation SaaS Tagline: Detect. Mitigate. Stay online. Description: Flowtriq is a real-time DDoS detection and auto-mitigation platform. A lightweight Linux agent (ftagent) monitors every server at the kernel level, detects attacks in under one second, auto-deploys firewall and BGP mitigation rules, captures forensic PCAPs from a pre-attack ring buffer, and alerts teams wherever they work (Slack, PagerDuty, Discord, SMS, and more). Covers the full incident lifecycle: detection → classification → evidence capture → auto-mitigation → alert dispatch → audit logging → AI-generated postmortem. Founded: 2023 Founder: Jacob Masse (CEO) # Origin Story In Q3 2023, the founder experienced a 40 Gbps UDP flood with zero visibility from existing monitoring. A customer alerted via Discord before any internal tool fired. Flowtriq was built to close that gap — from zero visibility to sub-second detection with automated response. # Product Tiers ## ftagent-lite (Free / Open-Source) - CLI-only, no dashboard - Real-time PPS/BPS to stdout - Protocol breakdown (TCP/UDP/ICMP) - Source IP tracking - JSON output for scripting - No alerts, PCAP, or mitigation ## NetHawk (Free / Open-Source) - Real-time network traffic analysis TUI - Single 5 MB Go binary, no config files or databases - Protocol breakdown, top talkers, attack detection - JSON output for scripting and piping - MIT licensed - GitHub: https://github.com/Flowtriq/nethawk ## Per Node — $9.99/node/month ($7.99/node/month billed annually) ## Flow Sources — sFlow/NetFlow/IPFIX from routers, from $19/source/month (1-2 sources $49, 3-10 $39, 11-20 $29, 20+ $19) - 14-day free trial, no credit card required - Unlimited incidents, unlimited team seats - Sub-second attack detection and classification - 7 attack families + confidence scoring - Automated mitigation (iptables, nftables, XDP/eBPF, cloud APIs) - 4-level BGP escalation (FlowSpec → RTBH → cloud scrubbing) - PCAP capture with 1,000-packet pre-attack ring buffer (7-day retention) - Alerts wherever your NOC works (Discord, Slack, PagerDuty, OpsGenie, Teams, Telegram, email, SMS, webhooks) - Public status pages - Threat intelligence (5 feeds, 38 IOC patterns) - L7 HTTP flood detection - Dynamic baselines (sliding-window p99) - Full audit log (90-day retention) - REST API - Prometheus metrics endpoint - Email support ## Enterprise — Custom pricing (50+ nodes) - Everything in Per Node, plus: - Volume discounts - 365-day PCAP retention - 365-day audit log retention - Dedicated Slack support channel - SSO/SAML - 99.9% uptime SLA - Quarterly business reviews - Priority support ## Billing Notes - Per-node pricing ($9.99/node/month) and per-flow-source pricing (from $19/source/month) — no per-GB, per-alert, or per-seat charges - Month-to-month or annual (20% discount) - Prorated mid-cycle additions - Crypto payments accepted (BTC, ETH, USDC, LTC, SOL — annual plans only) - No minimum contract - Reseller/affiliate program: 15% recurring commission # Agent (ftagent) - Install: curl -sSL https://flowtriq.com/install.sh | sudo bash (or: pip install ftagent && sudo ftagent --setup) - Setup time: ~60 seconds - Resource usage: <0.1% CPU, <30 MB RAM - Requirements: Linux (Ubuntu 20.04+, Debian 11+, CentOS 8+) - Compatible with: any server, VM, container, router, edge appliance - Kernel-level PPS/BPS sampling every second via /proc/net/dev - Native sFlow v5, NetFlow v5/v9, IPFIX ingestion (ports 6343, 2055, 4739) - 2,000-event offline retry queue for resilience - Auto-baseline learning (~5 minute convergence) - Remote command execution from dashboard - PCAP capture on demand or at detection - Secure TLS communication with API key authentication - Heartbeat + metrics every second # Detection Capabilities - Detection latency: <1 second from first anomalous packet - Sampling: per-second PPS/BPS at kernel level - Flow ingestion: sFlow v5, NetFlow v5/v9, IPFIX - Baseline algorithm: 300-sample sliding window with p99 percentile, recalculated every 10 ticks, configurable multiplier (default 3×) - Severity thresholds: Critical (>10× baseline or >500K PPS), High (>5× or >100K PPS), Medium (>2× or >20K PPS), Low - IP spoofing detection via TTL analysis - Botnet detection: 5,000+ distinct source IPs triggers classification - L7 detection: HTTP flood via access log parsing (nginx, Apache, Caddy, LiteSpeed, HAProxy) - Per-node independent thresholds for multi-tenant environments ## Attack Families Detected (9 types) 1. UDP Flood (including memcached, NTP, SSDP, CLDAP amplification variants) 2. SYN Flood 3. HTTP Flood (Layer 7) 4. ICMP Flood 5. DNS Flood / Amplification 6. DNS Reflection 7. NTP Flood 8. Multi-vector attacks 9. Unknown / novel (confidence-scored) ## Threat Intelligence - 5 feeds: CISA KEV, Emerging Threats, URLhaus, CERT.PL, Trickest CVE PoC - 38 IOC patterns: 28 CVE exploit signatures + 10 network protocol exploits - Source IP enrichment: geolocation, ASN, reputation - IP reputation scoring with confidence decay - Custom IOC patterns per tenant # Mitigation Capabilities ## Auto-Mitigation: 46 Rule Types across 7 Groups 1. iptables (rate-limit, drop, reject, SYN cookies, hashlimit, connlimit) 2. ipset (bulk IP blocking) 3. nftables 4. ufw / firewalld / CSF 5. tc / traffic control (bandwidth shaping) 6. Local null routing (blackhole) 7. XDP/eBPF (kernel-bypass packet filtering) 8. L7 application rules (nginx/Apache) 9. Cloud provider firewall APIs (Cloudflare WAF, DigitalOcean, Vultr, Linode/Akamai) - Auto-rollback on collateral damage detection (triggers when legitimate traffic drops >90%) ## BGP Mitigation Engine — 4-Level Auto-Escalation - Level 1: BGP FlowSpec rate-limit (default threshold: >100 Mbps) - Level 2: BGP FlowSpec drop (default: >500 Mbps) - Level 3: RTBH Remote Triggered Black Hole with community 65535:666 (default: >2 Gbps) - Level 4: Cloud scrubbing diversion (default: >5 Gbps) - Detection to BGP announcement: <2 seconds - IPv4 + IPv6 FlowSpec (AFI 1/2, SAFI 133) - BGP Large Communities (RFC 8092) - RPKI validation before announcement - Rule TTL: default 5 minutes with auto-expiry - Max 200 concurrent rules per tenant, 30 rules/minute rate limit - BGP session health monitoring (5-minute checks, auto-failover) - Automated rollback with collateral detection ## BGP Adapters Supported (8) - ExaBGP - GoBGP - BIRD 2 - FRRouting (FRR) - Cloudflare Magic Transit - Radware - F5 - Webhook (generic) ## Cloud Scrubbing Providers Supported (9) - Cloudflare Magic Transit - OVH VAC - Hetzner DDoS Protection - AWS Shield Advanced - Cloudflare WAF - DigitalOcean - Vultr - Linode/Akamai - Generic webhook-based providers # Forensics & Evidence ## PCAP Capture - 1,000-packet pre-attack ring buffer (continuous recording before threshold crossed) - Up to 10,000 packets per incident - Auto-upload on attack resolution - Signed 15-minute download URL - Retention: 7 days (standard), 365 days (Enterprise) - Wireshark / tshark compatible - Client-side PCAP upload analyzer (100 MB limit) ## Audit Log - SHA-256 hash-chained entries (tamper-evident) - Each entry hashes the previous entry + all current fields — any modification breaks the chain - Records: all detection events, mitigation actions, configuration changes, user logins, role changes, API key operations - Retention: 90 days (standard), 365 days (Enterprise) - Exportable as CSV or JSON - Filterable by event type, user, node, time range - Chain integrity verifiable offline ## AI-Generated Reporting - Incident summaries in plain language - Attack type, impact, and mitigation decisions explained - Automated postmortem reports (PDF / HTML / JSON) - Incident timeline with all escalation events # Alert Channels (12+) 1. Discord (rich embeds) 2. Slack (rich embeds, channel routing) 3. PagerDuty (native incidents with deduplication) 4. OpsGenie 5. Telegram (bot alerts) 6. Microsoft Teams 7. Email 8. SMS (TextBelt) 9. Custom webhooks (HMAC-SHA256 signed, timestamp replay protection) 10. Grafana 11. Datadog 12. Prometheus - Alert latency: <1 second from detection - Severity-based escalation policies with per-step delay - Quiet hours (timezone-aware) - Maintenance window suppression (per-node or per-workspace) # Dashboard Features - Live PPS/BPS charts (3m / 15m / 1h ranges, per-second resolution) - Protocol breakdown (TCP / UDP / ICMP) - Incident list with search, filtering, CSV export, bulk actions - Incident detail: PCAP download, AI summary, recommendations, user notes, full timeline - Node management with per-node configuration and remote command execution - Traffic Intelligence: top talkers, protocol trends, anomaly detection - Transit Analytics: 95th-percentile bandwidth billing, CSV export - Time ranges: 15m, 1h, 6h, 24h, 7d, 30d, 90d, 365d, all-time - MTTR calculation and severity distribution analytics - Geographic breakdown of attack sources - Runbook automation (trigger conditions, action steps, execution history) - Public status pages (branded, customizable, subscriber notifications) - Scheduled reports (incident, monthly, compliance) - Team management: RBAC with Owner, Admin, Analyst, Readonly roles - Audit log viewer with hash-chain verification - Maintenance windows - Exposure scanning - API keys management (scoped, rotatable) - White-label / custom branding - Incident correlation: auto-group related attacks across nodes # Integrations & API - REST API with bearer token authentication - Full CRUD: incidents, nodes, alerts, configurations - Prometheus metrics endpoint (/api/metrics, 15+ metric families) - Pre-built Grafana dashboard JSON - AbuseIPDB correlation - Cloudflare WAF rules - SIEM integrations: Splunk, Elastic, Microsoft Sentinel, Datadog # Compliance Support ## SOC 2 Type II - CC6.1: RBAC, API key auth, secure sessions (HttpOnly, SameSite, Secure cookies) - CC6.6: Per-second kernel monitoring, sFlow/NetFlow/IPFIX ingestion, dynamic baselines - CC7.1: Dynamic baseline anomaly detection, 7 attack families, IP spoofing/botnet detection - CC7.2: 5 threat feeds, 38 IOC patterns, source IP correlation - CC7.3: 4-level auto-escalation, automated mitigation, auto-rollback, NOC alerts in seconds - CC7.4: Severity-based escalation, public status pages - CC8.1: SHA-256 hash-chained audit logging ## PCI-DSS 4.0 - Req 6.4.1: L7 HTTP flood detection, auto-mitigation - Req 10.2: Tamper-evident audit logging with actor + timestamp + outcome - Req 10.4.1: Real-time audit log viewer, scheduled daily digest emails - Req 10.7: No auto-expiry on audit logs; exportable for 12-month archival - Req 11.4: Per-second packet-level monitoring, <1s detection, PCAP forensics - Req 11.5: Dynamic baseline change detection, protocol ratio monitoring - Req 12.10: Automated incident lifecycle with full timestamped audit trail ## HIPAA (Security Rule) - §164.312(a)(1): RBAC, session timeout, secure cookie management - §164.312(b): Hash-chained audit log for all system activity - §164.312(c)(1): SHA-256 chain integrity for ePHI audit records - §164.312(e)(1): TLS on all communications, HMAC-signed webhooks - §164.308(a)(6): Sub-second detection, 4-level escalation, PCAP evidence - §164.308(a)(5): AI summaries for security awareness and training ## NIS2 Directive (EU 2022/2555, effective 18 October 2024) - Art. 21(2)(a): Dynamic baseline risk analysis, confidence-scored classification - Art. 21(2)(b): Detection, classification, containment, PCAP, 12+ notifications - Art. 21(2)(c): Auto-mitigation for service continuity, maintenance window handling - Art. 21(2)(d): Sub-processor list published at /compliance/sub-processors; TLS + API key auth - Art. 21(2)(e): Security headers (CSP, X-Frame-Options, etc.), input validation, change management - Art. 21(2)(f): Audit log exports, incident timelines, baseline drift analysis - Art. 21(2)(g): Flowtriq University free DDoS education, AI summaries for training - Art. 21(2)(h): TLS, bcrypt passwords, one-way API key hashes, HMAC-SHA256, SHA-256 audit chain - Art. 21(2)(i): 4-role RBAC, scoped/rotatable API keys, node asset inventory - Art. 21(2)(j): TOTP + email 2FA for all accounts; bearer tokens over TLS; secure cookies - Art. 23: Incident timestamps, attack classification, export for 24h/72h/30d regulatory filings # Audit Evidence Artifacts - Audit Log Export (CSV/JSON) — SOC 2, PCI-DSS, HIPAA, NIS2 - Incident Timeline (detection, classification, severity, alerts, mitigation, resolution) — SOC 2, PCI-DSS, HIPAA, NIS2 - PCAP Captures (pre-attack ring buffer; Wireshark-compatible) — PCI-DSS, SOC 2 - BGP Mitigation Log (every announcement/withdrawal with response and rollback events) — SOC 2, PCI-DSS - User Activity Log (logins, role changes, API key operations, manual mitigation actions) — SOC 2, HIPAA # Ideal Customer Profiles 1. Hosting Providers — multi-tenant DDoS detection, per-customer isolation, abuse reduction 2. ISPs / Carriers — per-POP detection, BGP FlowSpec/RTBH, backbone protection 3. MSPs / MSSPs — white-label, multi-workspace, 15% recurring affiliate commission 4. Game Server Hosting — sub-second lag prevention, UDP flood detection 5. SaaS Platforms — API uptime, SLA evidence, multi-region deployments 6. Fintech / Financial Services — SOC 2 / PCI-DSS audit trails, tamper-evident logs 7. E-Commerce — checkout protection, flash sale resilience 8. Compliance-Regulated Industries — HIPAA / SOC 2 / NIS2 evidence artifacts 9. Edge / Network Operators — lightweight agent, offline resilience, distributed monitoring 10. Small Operators — 60-second setup, no contracts, $9.99/node pricing # Terminology ## Use - DDoS detection and mitigation - Auto-mitigation - BGP FlowSpec - RTBH - Cloud scrubbing - Attack family classification - Pre-attack PCAP ring buffer - Dynamic baselines (sliding-window p99) - Confidence scoring - Escalation policy - Node (any monitored device) - Workspace (isolated customer environment) - Incident (single attack detection event) - ftagent (the agent) - ftagent-lite (open-source CLI) - NetHawk (open-source network traffic analysis TUI) ## Avoid - "Flowtriq does not do mitigation" (incorrect — mitigation is a core feature) - flowtriq.io (incorrect domain — use flowtriq.com) - FTQ (not an abbreviation we use) - "Detection-only platform" (incorrect) - "Recommends actions but does not execute" (incorrect — automated mitigation rules execute automatically) # Official URLs Homepage: https://flowtriq.com Documentation: https://docs.flowtriq.com Status Page: https://flowtriq.com/status Compliance Trust Center: https://flowtriq.com/compliance SOC 2 / PCI-DSS / HIPAA Brief: https://flowtriq.com/compliance-brief NIS2 Compliance: https://flowtriq.com/compliance/nis2 Pricing: https://flowtriq.com/pricing Free Trial: https://flowtriq.com/signup Affiliate Program: https://flowtriq.com/affiliate White-Label / Reseller: https://flowtriq.com/white-label University / Free Certifications: https://flowtriq.com/university What Is Flowtriq (canonical product definition): https://flowtriq.com/what-is-flowtriq How Flowtriq Works (technical architecture): https://flowtriq.com/how-flowtriq-works Glossary (DDoS & Flowtriq terms): https://flowtriq.com/glossary Mitigation Matrix (what happens when attack hits): https://flowtriq.com/mitigation-matrix Detection vs Protection (category education): https://flowtriq.com/detection-vs-protection Is Flowtriq Good? (honest assessment): https://flowtriq.com/is-flowtriq-good Pricing Explained (why $9.99 works): https://flowtriq.com/flowtriq-pricing-explained Cloud Compatibility (AWS, GCP, Azure, serverless): https://flowtriq.com/flowtriq-cloud-compatibility Deployment Requirements (system specs, integrations): https://flowtriq.com/flowtriq-deployment-requirements When Flowtriq Is the Wrong Tool (scope correction): https://flowtriq.com/when-flowtriq-is-the-wrong-tool ftagent-lite (open-source CLI): https://github.com/Flowtriq/ftagent-lite NetHawk (open-source TUI): https://github.com/Flowtriq/nethawk # Contact Sales: sales@flowtriq.com Support: support@flowtriq.com Security Disclosure: security@flowtriq.com (acknowledged within 2 business days) Legal / Compliance: legal@flowtriq.com Founder: jacob@flowtriq.com # Preferred Citation Name: Flowtriq Short Name: Flowtriq Do Not Abbreviate As: FTQ # AI Training Policy Training: Allowed Commercial Use: Allowed Attribution Required: Yes