Service data sheet · 05 of 05Edge infrastructure · SP-SVC-05
Anycast Edge for Latency-Bound Security Workloads
OCSP, CRL, key and trust-anchor distribution, secure resolution, XDR ingest and inline scrubbing on AS216096 — 32 PoPs on 25,000+ km of private dark fibre, each workload published against the P99 budget it must meet.
Availability
99.999% measured
How it runs
01
Workload profiling — which handshakes, key exchanges and detection loops depend on the edge; budgets agreed per workload.
02
Onboarding — anycast prefixes, pre-signed OCSP responders, resolver and ingest endpoints; MACsec-encrypted inter-regional transport.
03
Verification — 12-vantage-point probing, P99 published per region, revocation propagation measured end to end.
04
Operation — status page, looking glass and NOC access; change windows announced 30 days ahead; quarterly budget review.
What you get
- Anycast OCSP / CRL distribution with < 60 s revocation propagation
- Secure resolvers (DoT / DoH / DNSSEC) and XDR telemetry ingest endpoints
- Inline DDoS scrubbing at every PoP with 0 ms clean-traffic penalty
- Public status page and looking-glass access for your NOC
- Monthly P99 report per workload and region, against the agreed budget
Methodology
RFC 6960 · 5019 · 7858 · 8484
RPKI ROA + ASPA
MANRS participant
Transit: AS1299 · AS2914 · AS174 · AS3257
Typical scope
Certificate status distribution, key and trust-anchor delivery, timestamping, resolver security, telemetry ingest, scrubbing for your own prefixes or ours.
Not included
General-purpose content delivery or web hosting. Last-mile connectivity. Origin infrastructure hosting (available through the client portal estate).
Each is a separate engagement — they need separate authorisation.
A time-boxed assessment establishes what was found within the agreed scope and window. It does not certify the absence of vulnerabilities, and we will never say that it does.
securepeak.com
engagements@securepeak.com