Edge protection

Four defenses in one managed service. Always-on DDoS protection, a managed Web Application Firewall, a global CDN, and bot control, sitting in front of your Dropsolid-hosted platform.

The shift

Four tools in one operating model

Business-critical sites face volumetric DDoS attacks, application-layer floods, malicious bots and inconsistent latency for visitors around the world. Handling any one of these separately means multiple vendor contracts, split accountability, and specialist expertise you may not have in-house. When something goes wrong, it takes days to work out whose problem it is.

Edge Shield replaces four tools with one operating model.

What Edge Shield does

pidpa use case desktop screen
  1. Always-on DDoS protection

    Automatic mitigation of volumetric and application-layer attacks (Layer 3 to 7), absorbed across a global edge network before they reach your application. No scrubbing-centre detours.
  2. Managed web application firewall

    OWASP Top 10 coverage and modern attack protection, with contextual request analysis for accurate blocking and very few false positives. Rules updated automatically.
  3. Global CDN

    Content cached close to visitors for faster load times, offloads the origin, and keeps sites stable during traffic spikes.
  4. Bot management

    Smart signal intelligence to separate good bots from bad bots. Stops scraping, credential stuffing, account takeover and inventory hoarding.

How it works

Traffic reaches the edge, not the origin

Traffic reaches the edge

Every request is handled at the global edge network before it touches your application.

Threats are inspected

DDoS, WAF and bot controls evaluate every request against managed policies.

Clean traffic is accelerated

The CDN serves cached content globally and forwards legitimate requests to your origin.

Custom

Custom WAF rules, managed by us

Custom WAF rules are designed, implemented and managed by Dropsolid. You don't have the manage any rules yourself.

Rules

Rule changes are free within reason

Changes

Larger or repeated changes are quoted as time and materials

24/7

Incident response is 24/7

Wha't's included

Always-on DDoS protection. Automatic mitigation absorbed across a global network.

Managed WAF with OWASP Top 10 coverage and contextual detection.

Global CDN with automatic cache invalidation via cache tags (Drupal 8+).

Bot management across scraping, credential stuffing, account takeover and inventory hoarding.

Predictable annual fee. No usage-based or traffic-based billing. Attack spikes never create surprise costs.

Enterprise-level support for every Edge Shield client, regardless of tier.

Fully managed by Dropsolid. Design, platform-aware tuning, continuous optimisation. One accountable partner.

One TLS certificate included per tier. Additional certificates available as an add-on.

Unlimited redirects included at no certificate cost. Redirects use Let's Encrypt with a 95% uptime target.

hero image ai
Fair use policy

Edge Shield

Edge Shield's WAF and DDoS protection operate on requests per second measured after caching. To keep protection effective and fair for everyone on the shared edge, each protected site or application is expected to reach at least 80% cacheability.

If a site does not reach 80% cacheability and seriously impacts our available capacity, Dropsolid reserves the right to move that site to CDN-only protection until cacheability is improved. The site stays online and cached. We always give advance warning. Once cacheability is improved, full WAF and DDoS protection is restored.

Data

Data processing and residency

Edge traffic is processed on a global edge security platform. Data-processing and residency documentation, and a Data Processing Agreement (DPA), are available on request from your Dropsolid contact.

Ready to talk about Edge Shield