// VPS / SHIELD

Stay online when
someone wants you offline

Shield is our always-on DDoS-protected VPS line. Layer 4 + Layer 7 mitigation, tuned per workload by our team — no waiting, no reconnects, no excuses.

// built_for

High-target services where downtime costs you money or players.

// gaming

Game servers

FiveM, Minecraft, Rust, DayZ, SA:MP, Palworld, and 28+ protocol profiles in total. Per-game mitigation rules.

// commerce

Web shops

Cart sessions and checkout APIs survive volumetric and L7 attacks without breaking the user flow.

// reach

Public websites

News, forums, dashboards, controversial speech. Reverse-proxied challenge layer keeps bots out, real humans in.

// infra

APIs & back-ends

Authentication endpoints, webhooks, SaaS back-ends — protected at line rate without rewriting your stack.

// always_on

Mitigation runs before the attack, not after.

Traffic to a Shield VPS crosses our scrubbing layer 24/7 — every packet, every connection, regardless of whether anyone is currently throwing one at you. There's no detection window, no failover shuffle, no brief blip while we re-route. The moment a malicious flow hits, it gets dropped.

Standard VPS runs in reactive mode — fine for back-office workloads, wrong for anything where five seconds of jitter is a refund or a rage-quit.

// shield

0s

Time to mitigation — always-on, no detection window

// standard

~5s

Reactive: detection + reroute window, brief reconnect possible

// layer 4

Volumetric & protocol attacks dropped at the edge

// layer 7

Per-application filters, UDP and TCP, tuned by us

// layer_7

Application-aware filtering for game protocols and HTTPS.

L4 protection alone leaks complexity into the application — slow loris, query floods, fake handshakes, malformed game packets. Shield parses traffic at the protocol layer and drops what doesn't belong.

// game_protocols

L7 game-protocol filters

Pre-built filters for FiveM, Minecraft, Rust, DayZ, ARK, Source engine, SAMP, and more — both UDP and TCP. We maintain the signature list. New protocol? We add it.

  • ·Per-game packet shape validation
  • ·Auth handshake gating
  • ·Connection-rate per source IP
  • ·Tuneable per server (you tell us)

// reverse_proxy

Reverse proxy for HTTPS

A fully-customizable challenge layer in front of your web app — JavaScript verification, CAPTCHA, JA3/JA4 fingerprinting, country rules. Similar shape to Cloudflare, hosted by us, tuned by us.

  • ·JS challenge + optional CAPTCHA
  • ·Per-route rules (allow API, gate /login)
  • ·Bot fingerprinting (JA3 / JA4)
  • ·Custom challenge page on your brand

// supported_protocols

28+ application profiles, filtered at the packet layer.

Each profile understands the protocol it protects — not just IPs and ports. Don't see yours? We add new profiles on request, and tune any of these to your server. UDP and TCP both covered.

// game_servers Game servers

FiveM / RedM (Cfx.re)

UDP

Full Cfx.re framework protection for GTA V and RDR2 roleplay servers, with optional strict deep-packet inspection.

Standard Experimental Strict DPI

Minecraft (Java)

TCP

Protocol-aware filtering for Java Edition servers and proxies (Velocity, BungeeCord, Paper).

Rust (RakNet)

UDP

RakNet handshake validation for Facepunch's Rust — bot joins and connection floods dropped at the edge.

Rust Console (DTLS)

UDP

DTLS session validation for the console edition, with a stricter profile available for sustained pressure.

Standard Strict

DayZ:SA / ArmA III

UDP

Keeps Bohemia survival and mil-sim sessions clean of spoofed and malformed traffic.

Multi Theft Auto (MTA:SA)

UDP

Packet validation for the long-running GTA: San Andreas multiplayer mod.

San Andreas Multiplayer (SA:MP)

UDP

Filtering for classic SA:MP roleplay and freeroam servers and their query traffic.

alt:V Multiplayer

UDP

Community GTA V multiplayer platform, validated at the protocol layer.

SCUM

UDP

Open-world survival sessions shielded from join floods and query abuse.

SCP: Secret Laboratory

UDP

Round-based horror servers kept playable under sustained pressure.

7 Days to Die

UDP

Co-op survival servers protected without touching your mod stack.

Conan Exiles

UDP

PC and console survival sessions, protocol-validated.

experimental

Palworld

UDP

Dedicated Palworld servers filtered against connection floods.

experimental

Mordhau

UDP

Competitive medieval melee servers kept lag-free during attacks.

Battlefield 4

UDP

Private and community BF4 servers shielded from volumetric abuse.

Call of Duty: Black Ops II (Plutonium)

UDP

Protection for the community-run Plutonium server platform.

S.T.A.L.K.E.R.: Shadow of Chernobyl

UDP

Multiplayer sessions in the Zone, validated against spoofed packets.

Enginefall

UDP

Megatrain survival shooter servers, protocol-filtered.

experimental

Hytale (QUIC)

UDP

QUIC-based transport profile for Hytale and other modern UDP game back-ends.

GameNetworkingSockets (Valve GNS)

UDP

One profile covering Valheim, V Rising, Satisfactory, Dead by Daylight, Unturned and other GNS-based titles.

experimental

Steam Query (A2S)

UDP

Validates Steam server-browser (A2S) queries for any Steam-listed game, killing reflection abuse.

// voice_&_vpn Voice & VPN

TeamSpeak 3

UDP

Voice servers stay connected while the flood gets dropped.

WireGuard

UDP

Modern VPN endpoints protected without breaking the handshake.

OpenVPN

UDP

Remote-access and site-to-site tunnels kept online under load.

// transport_&_web Transport & web

QUIC / HTTP/3

UDP

The modern UDP transport behind HTTP/3 and next-gen game back-ends, validated at the edge.

DTLS

UDP

Generic Datagram TLS profile for secured UDP applications beyond the named titles above.

// always_on_baseline Universal baseline

Anti-spoofing + rate-limiting

UDP/TCP

Universal source-validation that covers most applications out of the box, before any game-specific tuning.

Per-port lockdown

UDP/TCP

Drops everything on ports you don't declare, so only your real services are ever reachable.

Profiles are maintained and updated continuously. "Experimental" marks a profile still being hardened — it works, we just keep refining it. Mitigation tuning for any title is included with every Shield plan.

// support_included

We tune the rules with you. No upsell, no consulting fee.

Every Shield plan includes hands-on mitigation support. Open a ticket with the attack signature, the affected service, or just the IP being hit — we'll adjust the L7 rules, tighten the challenge layer, or roll a custom filter in minutes. That's the part most providers charge extra for. We don't.

// shield_plans

Pick a tier — protection is included on every one.

Pricing in EUR · 20% Austrian VAT for AT consumers · Reverse charge for EU B2B

Shield S

€6,99 EUR / mo
  • · 1× vCPU · Ryzen 9 9950X
  • · 1 GB DDR5 RAM
  • · 20 GB NVMe SSD
  • · 25 Gbps Shared ? 2 TB Fair-Use
  • · Advanced DDoS Protection
  • · 1× IPv4 Address
Order Now →

Shield M

€10,99 EUR / mo
  • · 2× vCPU · Ryzen 9 9950X
  • · 2 GB DDR5 RAM
  • · 40 GB NVMe SSD
  • · 25 Gbps Shared ? 3 TB Fair-Use
  • · Advanced DDoS Protection
  • · 1× IPv4 Address
Order Now →

Shield L

€16,99 EUR / mo
  • · 2× vCPU · Ryzen 9 9950X
  • · 4 GB DDR5 RAM
  • · 60 GB NVMe SSD
  • · 25 Gbps Shared ? 5 TB Fair-Use
  • · Advanced DDoS Protection
  • · 1× IPv4 Address
Order Now →

Shield XL

€29,99 EUR / mo
  • · 4× vCPU · Ryzen 9 9950X
  • · 8 GB DDR5 RAM
  • · 100 GB NVMe SSD
  • · 25 Gbps Shared ? 8 TB Fair-Use
  • · Advanced DDoS Protection
  • · 1× IPv4 Address
Order Now →

Shield XXL

€54,99 EUR / mo
  • · 6× vCPU · Ryzen 9 9950X
  • · 16 GB DDR5 RAM
  • · 150 GB NVMe SSD
  • · 25 Gbps Shared ? 10 TB Fair-Use
  • · Advanced DDoS Protection
  • · 1× IPv4 Address
Order Now →

Shield Pro

€99,99 EUR / mo
  • · 8× vCPU · Ryzen 9 9950X
  • · 32 GB DDR5 RAM
  • · 200 GB NVMe SSD
  • · 25 Gbps Shared ? 15 TB Fair-Use
  • · Advanced DDoS Protection
  • · 1× IPv4 Address
Order Now →

> under_attack_now?

We onboard active mitigations during attacks. Reach out — bring whatever logs you have, we'll spec a tier and migrate fast.

Talk to us →