CorePilot DDoS
What the service does, what it aims for, and — stated plainly and up front — what it does not and cannot promise.
← Back to sign inTraffic crossing the transit edge toward your address space is monitored for volumetric denial-of-service attacks. When one is identified, mitigation is applied at the network edge, you are notified, and the current state and history of your circuits are visible in the customer portal.
Protection is provided per circuit — a location, its registered address ranges, and the contracted rate agreed for it — for a stated term.
This is a best-effort mitigation service, not an availability guarantee. We commit to watching, to acting, and to telling you what we saw. We do not commit to any particular outcome of an attack, because the outcome depends on the size and shape of the attack and on the capacity of networks upstream of ours.
These reasons are specific and measured. They are stated here rather than buried in a liability clause, because knowing them lets you make better decisions about your own resilience.
Mitigation is applied at our edge routers. An attack large enough to saturate a transit circuit has already congested that circuit before the packets reach a router we can program. Dropping them at our edge does not un-congest the link they arrived on. This is the most important limit, and it is a property of physics and topology rather than of any product.
Flow is exported by the routers, written into 60-second capture files, and evaluated once a rotation. A finding must persist across two consecutive captures before mitigation may act — a single measurement artifact must never disconnect a customer. That is roughly two to four minutes for a sustained attack. An attack shorter than that is recorded and reported, and is over before mitigation could act.
Flow is sampled, typically at 1:1000. Small or low-rate attacks may not be visible, and every bandwidth figure shown is a statistical estimate rather than an exact count.
Automatic mitigation is limited to signatures that can be identified with confidence. Other classes — including application-layer attacks, low-and-slow attacks, and attacks that resemble legitimate traffic — are reported but not automatically mitigated. The restraint is deliberate: acting on a weaker signal disconnects customers who are not under attack.
Mitigation rate-limits a matching traffic class at the edge. It does not distinguish an attacker's packet from a legitimate packet of the same shape, so some legitimate traffic in that class is affected while a rule is in force. This service does not include traffic scrubbing or packet-level cleaning.
Detection depends on the routers exporting flow and on the collectors receiving it. Mitigation depends on the routers installing the rule. Upstream transit providers may fail, reroute or become congested independently of us.
The clearest thing we can do is separate what we commit to from what we aim for and what we will never promise.
| Tier | Covers |
|---|---|
| Committed | Monitoring is running. You are notified. Records are kept and visible. A person responds. Mitigation is withdrawn when the attack stops. |
| Targeted | Time to detect, time to mitigate, and which attack classes are handled automatically. |
| Never promised | That your service stays up during an attack. That a given volume is absorbed. That every attack is detected. That no legitimate traffic is affected. |
The targets below describe how the platform is configured and what it has been measured to do. They are targets, not warranties, and missing one is not a breach.
| Measure | Target |
|---|---|
| Detect a sustained qualifying attack | < 5 min |
| Apply automatic mitigation | < 5 min |
| Notify you | < 15 min |
| Withdraw mitigation after traffic clears | < 10 min |
| Maximum unattended mitigation hold | 60 min |
| Attack history in the portal | 12 months |
The service is provided on a reasonable-endeavours basis. We do not warrant that any attack will be detected, prevented or successfully mitigated, nor that your service will remain available during an attack.
We are not liable for loss arising from an attack, from the effects of mitigation applied under these terms, or from the failure of any upstream network. Any remedy is limited to the service credits expressly stated in the commercial agreement.