Gateway Sentry

Next-Generation DDoS Mitigation

Intelligent protection that learns and adapts in real time. Stop sophisticated DDoS attacks before they reach your infrastructure.

24PoPs
points of presence
5sites
anycast locations
2.1+Tbps
mitigation capacity
<1second
time to mitigate

The Attack Hits. Your Site Doesn't Notice

Floods die at the edge in under a second. Your origin keeps serving like nothing happened.

Next Door to the Whole World

One VM, every location. The edge answers nearby while your machine moves freely behind one permanent address.

Protection That Scales With Your Player Count

More players brings more attacks. Usage-based mitigation absorbs both without a config change.

Products

Four Products. One Platform

Pick the product that fits your infrastructure. Every one runs on the same protected edge.

Our Network

Our Edge, End to End

No resold scrubbing, no third-party cloud in the path. These are properties of the network itself, and each one is checkable.

Own datapath
eBPF/XDP filtering we wrote ourselves. No vendor in the loop.
Anycast + unicast
Anycast sites announcing AS402349; unicast cities worldwide.
Wire-speed drops
Attacks die at the NIC driver, at line rate, by default.
Hardware offload
Hot banlists pushed down into NIC flow tables.
Fingerprinting
JA4 TLS and HTTP fingerprints sort real clients from scripts.
L3-L7 coverage
One platform, one dashboard, one bill.
Usage-based billing
No contracts. Pay only for the clean traffic you move.
Public record
Looking glasses, PeeringDB, and BGP.tools. Check us first.

Filtering at Wire Speed

Every packet that reaches a Gateway Sentry PoP walks this path in microseconds

01
Ingress

Anycast lands each packet at the nearest PoP, splitting attack load across sites.

02
XDP parse

Driver-level parse and sanity checks before the kernel allocates anything.

03
Protocol programs

TCP and UDP programs apply rate limits, fingerprints, and state checks.

04
Verdict

Malicious packets drop at line rate; hot banlists offload to NIC hardware.

05
Delivery

Clean traffic forwards to your origin or your Sentry Compute VM.

clean trafficattack traffic, dropped at stage 04

Locations

One Edge, Worldwide

Anycast sites announce the same prefixes everywhere at once; unicast PoPs put protected endpoints exactly where your players and users are.

A global anycast + unicast network · full roster on the Network page

Solutions

Built for Your Workload

Game servers

Minecraft, FiveM, Rust, ARK, and Source engine servers stay online through the attacks that come with success. Protocol-aware filtering at the port level, anycast proximity for latency.

MinecraftFiveMRustARKSource
Explore

Hosting providers

Protect an entire customer base without re-architecting. Per-customer protected IPs, tenant isolation, and infrastructure that scales with your customer base.

per-customer IPstenant isolation
Explore

SaaS & web platforms

Apps, panels, storefronts, and APIs behind L7 protection: fingerprinting, rate intelligence, and a WAF that tell real users apart from bots.

WAFbot defenseAPI protection
Explore

Provision It Yourself

A protected IP from the dashboard in minutes: allocated, announced from every anycast site, filtering applied, forwarding live.

Open Dashboard
control.gatewaysentry.com · new serviceExample
Anycast IP allocated198.51.100.240.6 s
Announced globallyglobal anycast edge1.1 s
Filtering profile appliedgame server preset0.3 s
Forwarding to origin203.0.113.70.4 s
Service protectedready for traffic2.4 s

Frequently Asked Questions

What is DDoS mitigation?
DDoS mitigation is the process of detecting and filtering malicious traffic before it overwhelms your infrastructure. Gateway Sentry routes traffic through a global edge network where AI-powered detection drops attack packets at line rate, so only clean traffic reaches your origin.
Does Gateway Sentry provide AI-powered DDoS protection?
Yes. Gateway Sentry uses real-time fingerprinting, packet analysis, and behavioral detection to identify threats as they arrive. AI-powered detection is included with every product, including network, web, and Sentry Compute.
What does L3-L7 protection cover?
L3-L7 protection defends every layer of the stack: network-layer (L3/L4) defense stops SYN floods, UDP floods, and amplification attacks, while application-layer (L7) defense stops HTTP floods, bots, and credential stuffing through fingerprinting and a WAF.
How much does Gateway Sentry cost?
Pricing is usage-based with no contracts or minimums. Network protection is $3.50 per TB plus $4.39 per IP, and web protection is $30 per TB plus $0.55 per million requests. You pay only for what you use.
How fast can Gateway Sentry stop a DDoS attack?
Attacks are mitigated in under one second. Malicious traffic is neutralized at the edge across the global network, so clean traffic continues to your origin with minimal impact.

Get Protected in Minutes

Provision from the dashboard in minutes. Usage-based billing from the first packet, no contracts.