Gateway Sentry

Products / Web Protection

Web Protection

HTTP floods, bots, and credential stuffing stopped at the edge by request fingerprinting, rate intelligence, and a composable WAF. Real users never notice.

$30 per TB$0.55 per 1M requests0 code changesL7 at the edge

What It Stops

HTTP Floods

Request floods are identified by fingerprint and behavior rather than volume alone, so distributed attacks that mimic real browsers still get caught. The tell is in how a client speaks, not how loudly.

Slowloris & Slow Attacks

Connection timeout analysis and header completion tracking neutralize slow-connection attacks before pools exhaust. Half a request, forever, gets disconnected before it costs a worker.

Bots & Credential Stuffing

Session scoring and challenges stop automated abuse while trusted visitors pass through untouched. Only suspicious sessions ever see a challenge.

Scrapers & AI Crawlers

Block or challenge automated user agents, including AI scrapers, with wildcard matching and per-IP rate limits. Your content stays yours to give away on purpose, not by default.

The Life of a Request

Every request takes the same short path through the edge before it ever reaches you

Arrive at the Nearest Edge

The global network lands each request at the closest point of presence, so judgment happens near the client instead of in front of your origin.

Fingerprint & Score

Connection fingerprints and behavioral signals identify the real client behind the request, with zero added latency for the ones that check out.

Rules Apply Per Route

Your flow rules run against the path: rate limits, blocks, headers, CORS, caching. The login page and the data API each get exactly the policy you wrote for them.

Serve, Challenge, or Block

Clean traffic is served from cache when possible or forwarded to your origin; suspicious sessions meet an edge-served challenge; abuse stops here and is never billed.

Live in Minutes

Protection that deploys like a DNS change, because it is one

Point Your DNS

Traffic reaches the edge first and only clean requests reach your origin. There is no procurement cycle and no appliance; deployment takes minutes.

No SDKs, No Agents

Nothing to install and no code changes. Challenges are served from the edge with no third-party scripts or external dependencies.

Passive First

Graduated protection modes let the edge observe before it enforces, escalating from monitoring to challenges to blocking only as threat conditions require.

Every Feature, Every Plan

Fingerprinting, the WAF, bot challenges, and AI scoring all ship together. Nothing is held back for a higher tier and nothing is priced per feature.

Real Users Never Notice

Fingerprinting is integrated with zero added latency, and only suspicious sessions ever advance to a challenge. Your users experience your product; the pipeline stays backstage.

Attacks Cost You Nothing

Malicious requests are filtered at the edge and excluded from your bill entirely. You pay for the traffic you wanted, at usage-based rates, and the flood is our problem.

Frequently Asked Questions

What is an L7 DDoS attack?
An L7 (application-layer) DDoS attack targets the web application itself rather than the network, using seemingly legitimate HTTP requests to exhaust server resources. Examples include HTTP floods, Slowloris, and HTTP/2 Rapid Reset, which are hard to detect because they mimic real user traffic.
How does Gateway Sentry provide L7 DDoS protection?
Gateway Sentry analyzes request patterns, connection parameters, and session context at the edge to identify application-layer attacks without impacting real users. Connection fingerprinting and behavioral analysis distinguish genuine browsers from automated tools, even when bots forge headers to impersonate them.
Can Gateway Sentry stop a Slowloris DDoS attack?
Yes. Slowloris holds connections open by sending partial HTTP headers at slow intervals to exhaust the server's connection pool. Gateway Sentry uses connection timeout analysis and header completion tracking to neutralize Slowloris before connections accumulate.
Does L7 DDoS protection slow down my website?
No. Fingerprinting is integrated with zero added latency, and clean traffic is served from cache when possible or forwarded to origin. Graduated protection modes let you balance security and user experience, escalating only when threat conditions require it.
How much does application-layer DDoS protection cost?
Web (L7) protection is usage-based pay-as-you-go at $30 per TB plus $0.55 per million requests, so you only pay for the traffic you serve. See the pricing page for full details.

Get Protected in Minutes

Point your DNS at the edge; every protection ships with every plan