DDoS Protection · Early Access

Your services stay online.
Through any attack.

Akarguard filters DDoS traffic at the edge before it reaches your server, and keeps the flood off your origin. Always-on, no hardware, and live with a single DNS change.

  • EU GDPR compliant
  • Continuous attack detection
  • Setup in minutes — DNS change only

No credit card requiredCancel anytimeSetup in minutes — DNS only

Filtering
In-kernel

Filtering

floods dropped at the firewall

Setup
DNS only

Setup

no hardware, no migration

Certificates
Free TLS

Certificates

issued and renewed for you

Security certifications:

EU GDPRCompliant
CCPACompliant
BCP38Compliant
OWASP L3–7Protected

Trusted by teams running production infrastructure

  • Sadenet
  • İkra Telekom
  • Yigit Tech
  • Sunucu Servisi
  • QuellStudios
  • Fua Music
  • Dungeon Rampage
  • Baso Network

Protection Features

Every attack vector. Neutralized.

Akarguard's multi-layered engine handles the full spectrum of DDoS attacks — so you never have to think about it.

Application-Layer (L7) Protection

Akarguard is a Layer 7 reverse proxy: it inspects every HTTP/HTTPS request and filters application-layer floods, bots and abuse — while hiding your origin IP so direct network floods can't find your server.

  • Application layer (L7)
  • Hidden origin IP
  • Bot & challenge filtering

Automatic Mitigation

Traffic analysis detects an attack and raises protection automatically, then restores your normal mode once it's over — no one has to be awake to flip a switch.

  • Automatic detection
  • Auto-raise & restore
  • No manual intervention

Reverse-Proxy Filtering

Traffic is routed through our protective edge via a simple DNS change. Clean requests reach your server; attack traffic never does.

  • DNS-based setup
  • No hardware needed
  • Origin IP stays hidden

Real-Time Dashboard

Full visibility into traffic patterns, blocked requests, and active mitigation events — all in a single, intuitive dashboard.

  • Live attack maps
  • Detailed analytics
  • API access

SSL/TLS Inspection

Decrypt, inspect, and re-encrypt traffic inline — stopping encrypted attack payloads without sacrificing user privacy.

  • TLS 1.3 support
  • HTTPS protection
  • Zero privacy compromise

Always-On & On-Demand

Deploy in always-on mode for constant protection, or on-demand for instant activation the moment an attack is detected.

  • Zero config setup
  • Instant activation
  • Seamless failover

How It Works

Attack to clean traffic. Milliseconds.

Traffic enters through our edge, bots are challenged, floods are dropped in-kernel, and only verified requests reach your server — with everything visible in your dashboard.

01

Point Your DNS

Add your domain in the dashboard, drop in the A record we give you, and every request now enters through the Akarguard edge instead of hitting your server directly. Your origin IP stays hidden.

02

Visitors Verified

The edge sits in front as a reverse proxy. Under load it serves a lightweight browser check (or a CAPTCHA) that real browsers clear in a few seconds — automated floods and headless bots never get past it.

03

Attackers Banned

Sources that keep flooding are dropped in the Linux kernel itself — ipset plus iptables, not a slow log parser. Repeat offenders are cut at the firewall in milliseconds, so the box stays fast even under a real attack.

04

Clean Traffic + Reports

Verified requests are forwarded straight to your origin. The dashboard shows live traffic and mitigation events as they happen, and emails you a PDF report once an attack is over.

By the numbers

Real numbers, measured live.

Not estimates. Every figure is counted on our own edge and updates hourly — see the open data.

86

Attacks mitigated

on our edge since Sep 2026

112.3k/s

Peak attack absorbed

highest filtered request rate

2,124,573

Malicious requests dropped

before reaching an origin

50s

Median attack length

detection to resolution

Now Available · v0.3.1

AkarPass is here.

A post-quantum, zero-knowledge password manager. Your vault is encrypted on your device before it leaves — the server never sees a single byte of plaintext.

Get Started Free

Zero-Knowledge Architecture

The server never sees it.

Your master password, encryption key, and vault contents never reach the server as plaintext. Only an encrypted blob is ever transmitted.

masterPassword → Argon2id → masterKey → ML-KEM-768 → DEKEncryptedVault

All key material is wiped from memory immediately after use.

Platform Support

Web App
Next.js 15
Desktop
Windows (Tauri)
Chrome Extension
Manifest V3

React Native mobile app coming soon • iOS & Android

Cryptographic Layers

01Argon2id KDF

Key derivation with 64 MiB of memory — the industry standard against brute-force.

02ML-KEM-768

NIST FIPS 203 post-quantum encryption — ready for quantum computers.

03AES-256-GCM

Authenticated symmetric encryption — military-grade data protection.

Open-source cryptography — nothing hidden.

Built on @noble/post-quantum and hash-wasm — audited, independent libraries. No home-grown crypto.

Post-Quantum
ML-KEM-768

Post-Quantum

NIST FIPS 203

Symmetric Cipher
AES-256-GCM

Symmetric Cipher

Authenticated

KDF
Argon2id

KDF

64 MiB memory

Plaintext
0 bytes

Plaintext

Never reaches server

Pricing

Simple, transparent pricing.

Clear fair-use limits, metered overage only past them. No hidden fees. Protection that scales with your business.

Starter

For a single site or game server that needs real protection without an enterprise contract.

€9/mo
  • 1 protected domain
  • Hidden origin IP — attackers can't hit your server directly
  • Layer 7 JavaScript / cookie challenge
  • Attack reports + email alerts
  • ~100 GB/mo fair-use traffic
  • Email support
Start free trial

14 days, no credit card

Most Popular

Pro

For growing SaaS and e-commerce that can't go down when an attack lands.

€29/mo
  • Up to 5 protected domains
  • Full Layer 7 (application-layer) protection + WAF
  • Automatic mitigation under attack
  • Extra alert recipients
  • ~1 TB/mo fair-use traffic
  • Priority ticket support
Start free trial

14 days, no credit card

Business

For agencies and multi-site operators — and hosts who want to resell.

€99/mo
  • Up to 15 protected domains
  • Everything in Pro, higher capacity
  • Uptime SLA (by agreement)
  • Guided onboarding
  • White-label / reseller option
  • ~5 TB/mo fair-use traffic
Talk to our team

Reseller pricing available

All plans include a 14-day free trial, automatic TLS certificates, and continuous attack monitoring. Questions? Talk to our team.

Security Blog

Stay ahead of the threat.

View all articles
Explainer

DDoS vs DoS: What's the Difference, and Why It Matters

A DoS attack comes from one source; a DDoS from thousands at once. Here's what actually separates them, why DDoS is far harder to stop, and how each is defended.

Akarguard Team

Security Engineering

Sep 15, 20256 min read
Explainer

How Much Does a DDoS Attack Cost Your Business?

Downtime, lost sales, emergency engineering, churn and reputation — a DDoS attack costs far more than the bandwidth. Here's how to estimate your real exposure.

Akarguard Team

Security Engineering

Aug 22, 20256 min read

Get the weekly threat digest

Attack reports, mitigation guides, and security news — every Friday.

Managed DDoS Protection

Stop attacks before
they start.

Point your DNS at Akarguard and attack traffic is filtered at our edge — before it ever reaches your origin.

  • 14-day free trial
  • No credit card required
  • Cancel anytime
  • EU GDPR & CCPA compliant

Get protected today

Start your free 14-day trial. No card needed.

Setup takes minutes. Just point your DNS at us.