Products / Sentry Compute
Anycast Routed VMs. Untouchable
Live on the bleeding edge of our anycast network and DDoS mitigation stack. Every packet scrubbed at line rate while you operate inside the security perimeter.
DDoS Protected Hosting on Our Edge
Most DDoS protection sits in front of someone else's server. Sentry Compute puts your workload directly on our anycast network, so attack traffic never has to traverse a public path to reach you.
Anycast IP, Included
Every VM is provisioned with a native anycast IP from the global edge. Players, customers, and clients reach the closest edge automatically. No DNS tricks, no proxying, no extra hops.
Always-On Protection
The same line-rate filtering that powers Network Protection runs in front of every VM. Volumetric floods, SYN floods, and amplification attacks die at the edge, before your hypervisor ever sees a packet of them.
Bidirectional Filtering
Both directions of traffic ride the anycast range. Outbound replies stay inside the perimeter end to end, on the same path packets came in on.
Minimal Added Latency
No scrubbing detour, no GRE tunnel, no upstream provider. Your workload runs on the same edge that filters its traffic, so protection costs single-digit milliseconds, not a round trip to a scrubbing center.
Modern Hardware
High-clock CPUs and locally-attached NVMe storage, tuned for game servers, real-time backends, and latency-sensitive APIs. The tick rate holds because the hardware was picked for it.
Full Control
Linux or Windows with full root or administrator access, a KVM console for out-of-band management, and a firewall control panel. It is your machine; we just keep the internet polite to it.
Self-Service From the Dashboard
Deploy From the Dashboard
Pick a plan and a location and the instance comes online in minutes, protected from the first boot, with its anycast address already announced.
Reinstall & Rescue
Reinstall the OS, reset credentials, or rename the instance yourself, any time, without a ticket. Bad night? Fresh OS in minutes, same IP, same protection.
Metered Transfer
Bandwidth is metered with a per-plan allowance and transparent overage, visible live in the dashboard before it bills. See Plans & Pricing.
Game Query Caching
Server-browser queries like A2S are answered from edge cache at every site, so query floods never reach the VM. See Game Query Caching.
Keep Exploring
Frequently Asked Questions
What is DDoS protected compute?
Is Sentry Compute a DDoS protected VPS?
How is this different from typical secure cloud hosting?
What hardware and OS options does DDoS protected hosting include?
How do I get a DDoS protected compute instance?
Deploy Inside the Perimeter
Pick a plan in the dashboard and your VM comes online protected, with its anycast address already announced