PUBLIC · securepeak.comAS216096 · L-717869-S
SecurePeak
AS216096 · 32 PoPs · anycast v4/v6 · private dark fibre

Edge infrastructure for latency-bound security workloads.

Not a general-purpose CDN. Every workload here sits inline in a handshake, a key exchange or a detection loop, where a late answer is equivalent to a wrong one: revocation status, key and trust-anchor distribution, CT and timestamping, resolver security, telemetry ingest for XDR, and inline scrubbing. Each is published against the budget it must meet, at P99, across all regions.

SP-EDGE-VID-01 · backbone tour · 0:46 · loopsOpen full size ↗
lg.securepeak.com · AS216096
$show bgp summary | as 216096
 
origin AS216096 SECUREPEAK RPKI valid 8/8
transit AS1299 AS2914 AS174 AS3257 AS6939
ix 30 exchanges peers 376
backbone >25,000 km dark fibre MACsec L2
 
anycast 32/32 pops p50 EMEA 3ms AMER 5ms APAC 6ms AFR 7ms
scrubbing 6.4 Tbps inline 0ms Δ under attack
Workloads

What runs at the edge, and the budget each is held to.

WorkloadProtocolBudgetP99 · 24h
Revocation statusOCSP · stapling10ms7.4ms
CRL / filter distributionHTTP · delta CRL · CRLite20ms11ms
Key & trust-anchor distributionsigned bundles · RFC 501120ms9ms
Short-lived credential issuanceACME · SSH CA · KMS broker50ms31ms
TimestampingRFC 3161 TSA · PTP-disciplined15ms8ms
CT log mirror & monitorRFC 6962 · get-sth25ms14ms
Secure resolutionDoT · DoH · DNSSEC10ms6ms
XDR telemetry ingestOTLP · mTLS30ms19ms
Inline scrubbingL3/L4 · 6.4 Tbps0ms Δ0ms Δ

Budgets are end-to-end at the PoP, P99 over a trailing 24 hours, excluding client last-mile. Signing operations (OCSP, TSA, DNSSEC) are pre-computed against HSM-held keys and served as static, signed artefacts; nothing at the edge holds a private key that can sign on demand.

SP-EDGE-MAP-01 · anycast footprintRPKI valid 8/8 · 30 IX · 376 peersLooking glass ↗PeeringDB ↗Data sheet ↗
Global topology

Points of presence

AND ×2
EMEA · HQ
1ms
BCN
EMEA
2ms
MAD
EMEA
2ms
PAR
EMEA
2ms
LON
EMEA
2ms
AMS ×2
EMEA
2ms
FRA
EMEA
3ms
ZRH
EMEA
3ms
VNO
EMEA
4ms
SOF
EMEA
4ms
ESB
EMEA
5ms
LCA
EMEA
5ms
NYC ×2
Americas
2ms
IAD
Americas
3ms
MIA
Americas
3ms
MCI ×2
Americas
4ms
DFW
Americas
4ms
FMT
Americas
6ms
MEX
Americas
6ms
GIG
Americas
8ms
TYO ×2
APAC
4ms
HKG
APAC
5ms
BOM
APAC
6ms
SYD
APAC
8ms
LOS
Africa
7ms
JNB
Africa
7ms
NBO
Africa
8ms
32 PoPs in 27 metros · 14 EMEA · 10 Americas · 5 APAC · 3 Africa
Regional P50

Latency budget

EMEA · 14 pops3ms
Americas · 10 pops5ms
APAC · 5 pops6ms
Africa · 3 pops7ms
Scrubbing capacity6.4 Tbps
Dark fibre> 25,000 km
Tier 1 transitAS1299 · AS2914 · AS174 · AS3257
Pipeline

Edge processing

StageOperationBudget
IngressAnycast routing0ms
TLS / WAFTermination + filtering< 1ms
ComputeLogic + ML inference< 3ms
TelemetryLog + metric capture< 4ms
ResponseClient delivery< 5ms
< 10ms
Latency to 95% of users
99.999%
Measured availability
< 8ms
OCSP response (P99)
< 60s
Revocation propagation
OCSP response P99 · last 24h, all regions7.4ms
OCSP response P99 · last 24h, all regions — 7.4ms. range 6.6 to 9.3 over 24 points. threshold 10; not breached.
00:0006:0012:0018:00

The dashed line is the SLO, not the mean. An OCSP response that lands after the TLS handshake has stapled a stale status has already failed — so P99 is reported against the 10ms line, per region, every hour.

Revocation & trust

Certificate infrastructure

OCSP responses pre-signed at the CA and replicated to every PoP; delta CRLs and CRLite-style filters distributed the same way. Revocation reaches all 32 nodes in < 60s. CT logs are mirrored and monitored with sub-hour alerting on mis-issuance.

Key distribution

Keys, trust anchors, secrets

Root stores, DNSSEC anchors, SSH CA keys and hybrid PQ KEM public keys served as signed, versioned bundles. Short-lived credential issuance and KMS envelope-decrypt brokered at the PoP; private keys stay in HSMs behind the backbone.

Transport

Private backbone

Over 25,000 km of leased dark fibre plus dedicated submarine capacity, lit with our own DWDM. Inter-regional traffic is MACsec-encrypted at Layer 2 and never traverses the public internet. AS216096 takes transit from Arelion (AS1299), NTT (AS2914), Cogent (AS174) and GTT (AS3257), plus Hurricane Electric (AS6939), and peers at 30 internet exchanges — no client path depends on a single upstream. PTP-disciplined clocks at every PoP for RFC 3161 timestamping and log ordering.

Telemetry

XDR ingest fabric

Endpoint and network telemetry terminates at the nearest PoP, is normalised and forwarded over the backbone. Sketch-based aggregation (Count-Min, HyperLogLog) runs at ingress so detection thresholds adapt before data reaches the core.

Resolution

Resolver security

DNSSEC-validating DoT/DoH resolvers with pre-signed zones and RPZ feeds updated from the advisory pipeline. Anycast-served, so validation cost is paid within the same budget as an unvalidated answer.

Availability

Inline DDoS scrubbing

6.4 Tbps of scrubbing capacity, inline at every PoP — not a separate scrubbing centre. Attack traffic never reaches the backbone and clean-traffic P99 is unchanged during an attack.

Transit · peering · AS216096
As observed in the global routing table · bgp.he.net · PeeringDB

Carrier and exchange marks belong to their owners and indicate an interconnection, not an endorsement. IX list from PeeringDB · 30 exchanges.