Detection, Mitigation & Response

Detect and mitigate DDoS attacks in under 1 second, respond automatically, and keep your users informed.

All features →
Docs
Documentation Quick Start API Reference Agent Setup Integrations 18
Learn
Free Tools 37 Free Certifications State of DDoS 2026 REPORT DDoS Protection Landscape Buyer's Guide PDF Hackathon Sponsorships
Company
About Us Become a Consultant 30% Partners White Label Managed Protection Contact Us System Status
Open Source
ftagent-lite MIT NetHawk MIT
Legal
Security Trust Center Terms & Privacy
Who Uses Flowtriq

From indie hosts to ISPs, see how teams like yours use Flowtriq to detect and stop DDoS attacks.

All use cases →
COMING Q3-Q4 2026

Detect. Route. Scrub.
Return clean.

Flowtriq Shield is managed cloud scrubbing that works alongside Flowtriq's detection engine. When an attack is detected, your traffic is routed through a secure tunnel, malicious packets are filtered out, and only clean traffic reaches your servers. No BGP expertise required. Setup in under 20 minutes.

How It Works

Four steps from attack to clean traffic

STEP 1

Detect

Flowtriq detects the DDoS attack in under 1 second using per-server packet analysis. The attack is classified and severity is measured before any action is taken.

STEP 2

Route

Traffic is automatically rerouted through your pre-configured GRE or WireGuard tunnel to Shield's scrubbing infrastructure. No manual intervention needed.

STEP 3

Scrub

Malicious traffic is filtered out using Flowtriq's attack classification data. The scrubbing layer knows exactly what to drop because detection already identified the attack family.

STEP 4

Return

Clean traffic is returned to your origin servers. When the attack subsides, Shield automatically deactivates and direct routing resumes. Zero latency during peacetime.

Why Shield

Scrubbing without the complexity

No BGP expertise required

Simple Mode handles everything. Configure a tunnel, activate Shield, and let Flowtriq manage the rest. No BGP sessions, no LOAs, no prefix announcements.

Setup in under 20 minutes

Point your tunnel, verify connectivity, activate. No week-long onboarding, no enterprise sales cycle, no hardware to rack.

No enterprise contract

Month-to-month. No annual commitment, no minimum spend, no lock-in. Cancel anytime if it does not fit your needs.

Works with any hosting provider

If your provider supports GRE or WireGuard tunnels, Shield works. OVH, Hetzner, Vultr, DigitalOcean, Linode, AWS, bare metal, colo.

GRE + WireGuard support

Choose the tunnel protocol that fits your infrastructure. GRE for legacy compatibility, WireGuard for encrypted transport with lower overhead.

Advanced Mode with BGP

For operators who want full control, Advanced Mode with BGP-based routing will be available after the initial launch. Start simple, upgrade when you are ready.

Waitlist

Get early access to Shield

Join the waitlist and we will notify you when Shield is ready. Early waitlist members get priority onboarding and launch pricing.

FAQ

Common questions about Shield

What is Flowtriq Shield?

Shield is a managed cloud scrubbing service. Flowtriq detects the attack, routes your traffic through a GRE or WireGuard tunnel to our scrubbing infrastructure, filters out malicious traffic, and returns clean traffic to your origin. You do not need to manage any scrubbing infrastructure yourself.

Do I need BGP expertise to use Shield?

No. Simple Mode requires zero BGP knowledge. You set up a GRE or WireGuard tunnel, point your traffic, and Shield handles the rest. For operators who want more control, Advanced Mode with BGP will be available after the initial launch.

How long does setup take?

Under 20 minutes in Simple Mode. You configure a tunnel endpoint, verify connectivity, and activate. No hardware to install, no enterprise contract to negotiate, no onboarding calls required.

Which tunnel protocols are supported?

GRE and WireGuard at launch. Both are standard protocols supported by virtually every hosting provider, firewall, and router on the market.

Does Shield work with any hosting provider?

Yes. Shield works with any provider that supports outbound GRE or WireGuard tunnels. That includes OVH, Hetzner, Vultr, DigitalOcean, Linode, AWS, bare metal providers, and colocations.

What happens to my traffic during peacetime?

During peacetime, your traffic routes directly to your servers. Shield activates on-demand when Flowtriq detects an attack. There is no always-on tunnel penalty and no added latency when you are not under attack.

Is there a long-term contract?

No. Shield will be available month-to-month with no commitment. Cancel anytime.

When does Shield launch?

We are targeting Q3-Q4 2026. Join the waitlist to get early access and be the first to know when it goes live.

Get Started

Ready to stop worrying about scrubbing infrastructure?

Join the Shield waitlist. Early members get priority onboarding and launch pricing.