Edge protection
Four defenses in one managed service. Always-on DDoS protection, a managed Web Application Firewall, a global CDN, and bot control, sitting in front of your Dropsolid-hosted platform.
Four tools in one operating model
Business-critical sites face volumetric DDoS attacks, application-layer floods, malicious bots and inconsistent latency for visitors around the world. Handling any one of these separately means multiple vendor contracts, split accountability, and specialist expertise you may not have in-house. When something goes wrong, it takes days to work out whose problem it is.
Edge Shield replaces four tools with one operating model.
What Edge Shield does
Always-on DDoS protection
Automatic mitigation of volumetric and application-layer attacks (Layer 3 to 7), absorbed across a global edge network before they reach your application. No scrubbing-centre detours.Managed web application firewall
OWASP Top 10 coverage and modern attack protection, with contextual request analysis for accurate blocking and very few false positives. Rules updated automatically.Global CDN
Content cached close to visitors for faster load times, offloads the origin, and keeps sites stable during traffic spikes.Bot management
Smart signal intelligence to separate good bots from bad bots. Stops scraping, credential stuffing, account takeover and inventory hoarding.
Traffic reaches the edge, not the origin
Traffic reaches the edge
Every request is handled at the global edge network before it touches your application.
Threats are inspected
DDoS, WAF and bot controls evaluate every request against managed policies.
Clean traffic is accelerated
The CDN serves cached content globally and forwards legitimate requests to your origin.
Custom WAF rules, managed by us
Custom WAF rules are designed, implemented and managed by Dropsolid. You don't have the manage any rules yourself.
Rules
Rule changes are free within reason
Changes
Larger or repeated changes are quoted as time and materials
24/7
Incident response is 24/7
Wha't's included
Always-on DDoS protection. Automatic mitigation absorbed across a global network.
Managed WAF with OWASP Top 10 coverage and contextual detection.
Global CDN with automatic cache invalidation via cache tags (Drupal 8+).
Bot management across scraping, credential stuffing, account takeover and inventory hoarding.
Predictable annual fee. No usage-based or traffic-based billing. Attack spikes never create surprise costs.
Enterprise-level support for every Edge Shield client, regardless of tier.
Fully managed by Dropsolid. Design, platform-aware tuning, continuous optimisation. One accountable partner.
One TLS certificate included per tier. Additional certificates available as an add-on.
Unlimited redirects included at no certificate cost. Redirects use Let's Encrypt with a 95% uptime target.
Edge Shield
Edge Shield's WAF and DDoS protection operate on requests per second measured after caching. To keep protection effective and fair for everyone on the shared edge, each protected site or application is expected to reach at least 80% cacheability.
If a site does not reach 80% cacheability and seriously impacts our available capacity, Dropsolid reserves the right to move that site to CDN-only protection until cacheability is improved. The site stays online and cached. We always give advance warning. Once cacheability is improved, full WAF and DDoS protection is restored.
Data processing and residency
Edge traffic is processed on a global edge security platform. Data-processing and residency documentation, and a Data Processing Agreement (DPA), are available on request from your Dropsolid contact.