Detect. Route. Scrub.
Return clean.
Flowtriq Shield is managed cloud scrubbing that works alongside Flowtriq's detection engine. When an attack is detected, your traffic is routed through a secure tunnel, malicious packets are filtered out, and only clean traffic reaches your servers. No BGP expertise required. Setup in under 20 minutes.
How It Works
Four steps from attack to clean traffic
Detect
Flowtriq detects the DDoS attack in under 1 second using per-server packet analysis. The attack is classified and severity is measured before any action is taken.
Route
Traffic is automatically rerouted through your pre-configured GRE or WireGuard tunnel to Shield's scrubbing infrastructure. No manual intervention needed.
Scrub
Malicious traffic is filtered out using Flowtriq's attack classification data. The scrubbing layer knows exactly what to drop because detection already identified the attack family.
Return
Clean traffic is returned to your origin servers. When the attack subsides, Shield automatically deactivates and direct routing resumes. Zero latency during peacetime.
Why Shield
Scrubbing without the complexity
No BGP expertise required
Simple Mode handles everything. Configure a tunnel, activate Shield, and let Flowtriq manage the rest. No BGP sessions, no LOAs, no prefix announcements.
Setup in under 20 minutes
Point your tunnel, verify connectivity, activate. No week-long onboarding, no enterprise sales cycle, no hardware to rack.
No enterprise contract
Month-to-month. No annual commitment, no minimum spend, no lock-in. Cancel anytime if it does not fit your needs.
Works with any hosting provider
If your provider supports GRE or WireGuard tunnels, Shield works. OVH, Hetzner, Vultr, DigitalOcean, Linode, AWS, bare metal, colo.
GRE + WireGuard support
Choose the tunnel protocol that fits your infrastructure. GRE for legacy compatibility, WireGuard for encrypted transport with lower overhead.
Advanced Mode with BGP
For operators who want full control, Advanced Mode with BGP-based routing will be available after the initial launch. Start simple, upgrade when you are ready.
Waitlist
Get early access to Shield
Join the waitlist and we will notify you when Shield is ready. Early waitlist members get priority onboarding and launch pricing.
FAQ
Common questions about Shield
Shield is a managed cloud scrubbing service. Flowtriq detects the attack, routes your traffic through a GRE or WireGuard tunnel to our scrubbing infrastructure, filters out malicious traffic, and returns clean traffic to your origin. You do not need to manage any scrubbing infrastructure yourself.
No. Simple Mode requires zero BGP knowledge. You set up a GRE or WireGuard tunnel, point your traffic, and Shield handles the rest. For operators who want more control, Advanced Mode with BGP will be available after the initial launch.
Under 20 minutes in Simple Mode. You configure a tunnel endpoint, verify connectivity, and activate. No hardware to install, no enterprise contract to negotiate, no onboarding calls required.
GRE and WireGuard at launch. Both are standard protocols supported by virtually every hosting provider, firewall, and router on the market.
Yes. Shield works with any provider that supports outbound GRE or WireGuard tunnels. That includes OVH, Hetzner, Vultr, DigitalOcean, Linode, AWS, bare metal providers, and colocations.
During peacetime, your traffic routes directly to your servers. Shield activates on-demand when Flowtriq detects an attack. There is no always-on tunnel penalty and no added latency when you are not under attack.
No. Shield will be available month-to-month with no commitment. Cancel anytime.
We are targeting Q3-Q4 2026. Join the waitlist to get early access and be the first to know when it goes live.