Stop attacks at the edge.
Stay online. Always.
Reflexx is a European edge network that detects and absorbs DDoS attacks in under a second. Always-on L3–L7 protection for websites, APIs, game servers and entire networks, with your data kept inside the EU.
Trusted by 4,200+ teams across Europe
Every layer protected.
One network to run it all.
From volumetric floods to low-and-slow application attacks, Reflexx filters hostile traffic at the edge closest to its source, so only clean requests reach your infrastructure.
Always-on DDoS mitigation
Every packet is inspected inline at wire speed. Attacks are fingerprinted and dropped in under a second, with no rerouting, no scrubbing delay and no manual action.
Time to mitigate
Median detection-to-drop time across all attacks last quarter.
Web Application Firewall
Managed OWASP rules, virtual patching for new CVEs and custom rules deployed worldwide in seconds.
Bot management
Behavioural fingerprinting stops scraping and credential stuffing, no CAPTCHAs for real users.
API shield
Schema validation, per-key rate limits and anomaly detection for REST and GraphQL.
Game & UDP protection
Stateful filtering tuned for game servers, VoIP and real-time apps, adding under 2 ms of latency.
Network protection over BGP
Protect whole /24 prefixes. We announce your IP space, filter it and hand clean traffic back over GRE or a direct interconnect.
Built in Europe,
for Europe.
Every point of presence runs on our own hardware in carrier-neutral data centres. Traffic is inspected and logged only within the EU. No data ever leaves the Union.
Onboard in minutes.
Automate everything.
Point your DNS at Reflexx or announce your prefixes, and protection is live. Everything in the dashboard is available through our API and Terraform provider.
- ✓No hardware, no code changes, no downtime
- ✓Real-time attack analytics, webhooks and SIEM export
- ✓Terraform provider, REST API and CLI
- ✓Automatic TLS certificates and origin shielding
# Protect a new zone $ curl -X POST https://api.reflexx.cc/v2/zones \ -H "Authorization: Bearer $REFLEXX_TOKEN" \ -d '{ "name": "shop.example.com", "origin": "203.0.113.24", "profile": "l7-adaptive", "waf": true }' { "id": "zn_8f2c1a", "status": "active", "pops": 38 }
You never pay for attack traffic.
Unmetered mitigation on every plan. Prices exclude VAT. Save 15% with yearly billing.
Starter
For websites and side projects.
- Unmetered L3/L4/L7 protection
- Managed WAF rules
- 3 protected domains
- Email support
Business
For stores, SaaS and APIs.
- Everything in Starter
- Bot management & API shield
- 25 protected domains
- 100% uptime SLA
- 24/7 chat and phone support
Enterprise
For networks, hosters and studios.
- Network protection over BGP
- Dedicated filtering capacity
- Private interconnect (PNI)
- Named security engineer
Under attack right now?
Our engineers in Amsterdam onboard emergency customers around the clock, usually within 15 minutes.