Edge CDN

Acceleration and security, on one edge

Our own POPs steer visitors by Anycast or GSLB, serve cache at the edge and stop attacks before they reach your origin. Certificates, WAF, rate limits and the rules engine are all self-service in the console.

  • Self-operated POPs · Anycast / GSLB
  • Free certificates, auto-issued
  • WAF + CC + rate limiting
  • HTTP/3

Plans and add-ons are shown after sign-in — no public list price yet.

Capabilities

What ships in the console

Each item below is a live console feature gated by your plan — not a roadmap.

Self-operated POPs · Anycast / GSLB

Multiple edge POPs with manual CNAME, DNS (GSLB) or Anycast VIP steering — switch modes any time.

Free certificates, auto-issued

Verify the domain with one TXT record and ACME issues and renews the certificate; bring your own PEM if you prefer.

WAF + CC + rate limiting

OWASP CRS WAF with detect / block modes, a CC guard and multi-rule rate limits keyed by IP, header, cookie or query.

Rules engine

Match on path, header, cookie, method, scheme or host; redirect, block, rewrite, cache, switch origin or set headers.

HTTP/3

QUIC on every POP for faster handshakes on lossy mobile networks — one switch, plan or add-on.

Origin Shield

The primary POP becomes a second-tier cache so a miss on any POP hits your origin once, not N times.

Cache, purge & prefetch

Per-path TTLs, status-code TTLs, query and cookie handling; purge by URL, prefix, tag or site; prefetch to every POP.

Analytics & logs

Traffic, requests and hit ratio per domain; top URLs, status codes and per-POP breakdown; security events once ready.

Billing

Clean traffic only

Usage counts the bytes delivered to real visitors. Requests blocked by the WAF, CC guard or rate limits are stopped at the edge and never appear on your bill.

  • Blocked and challenged requests are excluded from metered traffic
  • Quota, overage and p95 are visible live in the console
  • Purge and prefetch have daily quotas that reset at 00:00 UTC
Which one?

Edge CDN vs CDN

Both products are sold side by side. Pick Edge CDN when you need security and routing control; the classic CDN remains the simplest way to cache static assets.

Backend
Edge CDN runs on our own POPs; CDN uses a partner network.
Security
Edge CDN bundles WAF, CC, rate limits, geo / UA / referer lists and signed URLs.
Control
Edge CDN adds steering modes, a rules engine, Origin Shield and HTTP/3.
See the classic CDN →
Onboarding

Four steps, fully self-service

  1. Add the domain and origin

    Order a plan, then enter the hostname to accelerate and where it should fetch from.

  2. Verify ownership

    Add one TXT record as shown and click verify.

  3. Point DNS at the edge

    CNAME the domain to the steering target (or use the Anycast VIP).

  4. Tune at the edge

    Certificates issue automatically; cache, security and rules can be changed any time.

Frequently asked questions

How is Edge CDN different from the CDN product?
Do I need to buy a certificate?
What does "clean traffic" mean for billing?
Can I move between steering modes?
What happens when I hit a limit?

Read the full Terms of Service →

Put security and speed on the same edge

Sign up free, order a plan and go live in minutes — open a ticket if anything blocks your migration.