Skip to content
Security & compliance

The subscriber edge that defends itself

DDoS detection and mitigation live where subscriber context lives: on the BNG. And the same platform carries your lawful-compliance duties, from NAT records to legal-request workflows, without a single extra box.

DDoS protection

Four detection layers. One quiet NOC.

Each engine runs independently: disabling one never blinds another. Confirmation windows keep false positives out; sub-second fast-signal keeps reaction times in.

Signatures

SYN, UDP and ICMP floods, reflection/amplification patterns and port scans, classified per subscriber with per-class thresholds.

Volumetric

Absolute pps and bps ceilings catch brute-force floods immediately, independent of shape or signature.

Fanout / entropy

Destination-spread analysis spots scanners and carpet-bomb behavior that stays under volumetric radar.

Adaptive baseline

Per-subscriber history learns what normal looks like, so a quiet CPE turning into a cannon stands out instantly.

Illustrations mirror the shipping console. Identifiers are fictional.

SYN floodUDP floodICMP floodReflection / amplificationCarpet bombPort scanMixed
One production day, measured

11K+

incidents triaged automatically, 24h

98

concurrent mitigations, no operator action

156M+

NTP amplification packets dropped, 100% eff.

< 5s

fast-signal reaction window

Rounded figures from a single 24-hour window on the production reference cluster (FTTH ISP, Delhi). Mitigation defaults to targeted rate limits with one-click clear.

Lawful compliance

Compliance as a workflow, not a project

IPDR, NAT records, legal requests and scoped access are product features. Your regulator asks; the console answers.

Deterministic CGNAT logging

Port-block allocation makes every public IP and port range attributable. NAT sessions log continuously and export as IPDR.

IPDR search that answers

Given a public IP, NAT port, TCP flags, destination or username plus a time range, the console resolves the subscriber in seconds. Excel exports are unlimited.

Legal-request workflow

Requests from authorities are tracked as first-class objects: who asked, what was searched, what was exported, when.

A scoped LEA role

Law enforcement gets its own read-only role, limited to lawful lookup workflows. No shared admin passwords, ever.

Tamper-evident audit log

Every login, config change, lookup and mitigation lands in the audit trail with actor, source IP and full detail.

Least-privilege by default

Admin, operator, partner and LEA roles separate duties. Partners see only their own VLANs; API tokens are scoped and stored hashed.

IPDR / Legal

From "who had this IP and port?" to a name, in seconds

The question every authority asks is the query the console is built around. Search billions of flow records by public NAT IP and port, private IP, destination, TCP flags or username, export the evidence to Excel, and log the whole lookup in the legal-request workflow.

  • Search by NAT IP + port + timestamp, the lawful triple
  • Unlimited Excel exports with every matching record
  • Requests tracked end to end, with a full audit trail
  • LEA role: scoped, read-only, no shared credentials
FAQ

Security and compliance, answered

Detection uses four independent layers (signatures, volumetric thresholds, fanout/entropy and adaptive per-subscriber baselines) with confirmation windows before action, and mitigation defaults to targeted rate limits rather than blackholing. Every threshold is tunable live, per network or per BNG, whitelists are first-class, and every action lands in the audit trail with one-click clear.

Bring your worst attack to the demo

We will replay attack patterns against a live cluster and walk your compliance workflow end to end, with your regulator's questions in mind.

Runs on your hardware · One plan, every feature · Migrate in slices