Platform

Everything between your users and your origin.

A single control plane for routing, caching, security and observability — managed declaratively and deployed to the edge in seconds.

Edge network

42 points of presence on a private backbone. Anycast routing places every client on the nearest healthy node, with automatic failover between regions.

Programmable gateway

Define authentication, rate limits, header rewriting and traffic splitting as version-controlled config. Preview changes before they go live.

Caching engine

Surrogate keys, tag-based purge and stale-while-revalidate. Cache dynamic responses safely with fine-grained TTL and vary rules.

Security layer

Managed TLS 1.3, volumetric DDoS mitigation and a rule-based WAF with managed rulesets and per-route overrides.

Observability

Structured access logs, RED metrics per route and real-time alerting via webhooks, Slack or email.

Origins & shielding

Connect any origin — cloud, on-prem or object storage — with origin shielding to collapse requests and cut egress cost.

How a request flows

Each request is terminated, inspected, matched against your routing rules and served from cache or origin — all within a few milliseconds at the edge.

StageWhat happens
1. TerminateTLS 1.3 handshake completes at the nearest PoP.
2. InspectWAF and rate-limit rules evaluate the request.
3. RoutePath and host rules select the matching backend or function.
4. ServeCache hit returns instantly; misses fetch from a shielded origin.
5. ObserveLatency, status and cache outcome are recorded and streamed.