Security at the speed of light

Edge Infrastructure

Purpose-built global network for security operations that cannot tolerate latency.

We designed and operate a purpose-built edge network for security-critical operations. Certificate validation, XDR telemetry, threat intelligence distribution—operations where milliseconds matter.

This is not a general-purpose CDN. It is security infrastructure purpose-built for operations where latency translates to risk. We serve OCSP responses in single-digit milliseconds globally.

Global Edge Network — Points of Presence & Fiber Backbone NYCNYC 2ms IADIAD 3ms LAXLAX 8ms LHRLHR 2ms AMSAMS 2ms FRAFRA 3ms HKGHKG 5ms NRTNRT 4ms SINSIN 5ms SYDSYD 8ms SEASEA 10ms ORDORD 5ms DFWDFW 7ms ATLATL 6ms MIAMIA 9ms TORTOR 6ms MEXMEX 14ms DENDEN 7ms GRUGRU 35ms BOSBOS 4ms CDGCDG 5ms MXPMXP 6ms MADMAD 8ms WAWWAW 7ms ARNARN 6ms ISTIST 12ms DXBDXB 22ms DELDEL 18ms BOMBOM 20ms BKKBKK 12ms CGKCGK 15ms ICNICN 6ms KIXKIX 5ms MELMEL 10ms DUBDUB 4ms JNBJNB 45ms
Major PoP
Edge Node
Fiber Backbone
Americas
NYC/IAD/BOS/ORD/ATL P50< 5ms
LAX/DEN/DFW/SEA P50< 10ms
Total PoPs13
EMEA
LHR/AMS/FRA/DUB P50< 3ms
ARN/MAD/WAW/IST P50< 8ms
Total PoPs12
Asia-Pacific
HKG/NRT/SIN P50< 6ms
DEL/BOM/BKK/ICN P50< 15ms
Total PoPs11
Global
Worldwide P95< 10ms
Availability99.999%
Total PoPs36

Network Architecture

Anycast routing with automatic failover across six continents

Global Topology

Anycast routing with sub-second failover. Private backbone between major regions eliminates public internet transit. Peering with thousands of networks globally. Latency measured from client perspective—we optimize for end-user experience.

Anycast with sub-second failover Private backbone between regions Thousands of peering relationships Zero single points of failure
Network Performance
< 10ms
Latency to 95% of users
99.999%
Measured availability
6
Continents covered
Tbps
DDoS mitigation capacity

Certificate Infrastructure

Real-time trust validation at global scale

OCSP at the Edge

Pre-signed OCSP responses at every edge location. Client queries resolve locally. Revocation propagates globally in under 60 seconds. Let's Encrypt serves ~100,000 OCSP responses/sec; we engineer for similar scale with lower latency.

Let's Encrypt Engineering "OCSP Caching Improvements" — ~100K responses/sec Engineering Blog (2022)

CT Log Monitoring

Real-time Certificate Transparency monitoring. Research by Pletinckx et al. (NDSS 2024) documented CT monitor delays from 2-34 days. Our monitoring achieves sub-hour alerting.

Pletinckx, Kohls, Dumitras et al. "Certificate Transparency Revisited" NDSS (2024)
Certificate Operations
< 8ms
OCSP response (P99)
< 60s
Revocation propagation
M/s
OCSP capacity
Real-time
CT monitoring

XDR Telemetry Fabric

Security telemetry at scale with edge processing

Edge Processing

Telemetry processing at edge reduces detection latency and central load. Initial threat detection using deployed ML models. Cross-source correlation before aggregation. Intelligence propagates in under 60 seconds.

Sub-100ms ingestion latency Edge-based initial detection Streaming analytics at edge Sub-minute intelligence propagation

IDS/IPS at Wire Speed

Network-based intrusion detection and prevention at our edge. Signature-based detection, protocol anomaly detection, behavioral analysis, encrypted traffic analysis using metadata without decryption. DDoS mitigation at multi-terabit scale.

XDR Performance
Billions
Events processed daily
< 100ms
Ingestion latency
< 5s
Detection latency
< 60s
Intel propagation

Private Backbone

Dark fiber and submarine cable infrastructure

Optical Transport Layer

Our private backbone operates on leased dark fiber and dedicated submarine cable capacity. All inter-regional traffic traverses encrypted optical channels—never the public internet. This eliminates BGP hijacking risk and reduces latency variance to near-zero.

Dark fiber across 3 continents Submarine cable diversity MACsec encrypted at Layer 2 Sub-millisecond jitter

DDoS Mitigation

Inline volumetric attack absorption at every PoP

Multi-Terabit Scrubbing

DDoS mitigation is inline at every edge location—not a separate scrubbing center with added latency. Each PoP contributes to a combined multi-terabit mitigation capacity. Local scrubbing means attack traffic never traverses the backbone, and clean traffic latency remains unchanged during active attacks.

Inline at every PoP Multi-Tbps aggregate capacity Zero added latency during attack Automatic L3/L4/L7 detection
Edge Processing Pipeline
INGRESS Anycast routing 0ms TLS / WAF Termination + filtering < 1ms EDGE COMPUTE Logic + ML inference < 3ms TELEMETRY Log + metric capture < 4ms RESPONSE Client delivery < 5ms total
Edge data center
Edge Infrastructure
Purpose-built facilities at 20 global locations
Network fabric
Fiber Network
Private backbone connecting all regions

Start a Conversation

Tell us about your security requirements. We respond within 24 hours.

Encrypted transmission