Edge infrastructure for latency-bound security workloads.
Not a general-purpose CDN. Every workload here sits inline in a handshake, a key exchange or a detection loop, where a late answer is equivalent to a wrong one: revocation status, key and trust-anchor distribution, CT and timestamping, resolver security, telemetry ingest for XDR, and inline scrubbing. Each is published against the budget it must meet, at P99, across all regions.
What runs at the edge, and the budget each is held to.
Budgets are end-to-end at the PoP, P99 over a trailing 24 hours, excluding client last-mile. Signing operations (OCSP, TSA, DNSSEC) are pre-computed against HSM-held keys and served as static, signed artefacts; nothing at the edge holds a private key that can sign on demand.
The dashed line is the SLO, not the mean. An OCSP response that lands after the TLS handshake has stapled a stale status has already failed — so P99 is reported against the 10ms line, per region, every hour.
Carrier and exchange marks belong to their owners and indicate an interconnection, not an endorsement. IX list from PeeringDB · 30 exchanges.
