Everything between your users and your origin.
A single control plane for routing, caching, security and observability — managed declaratively and deployed to the edge in seconds.
Edge network
42 points of presence on a private backbone. Anycast routing places every client on the nearest healthy node, with automatic failover between regions.
Programmable gateway
Define authentication, rate limits, header rewriting and traffic splitting as version-controlled config. Preview changes before they go live.
Caching engine
Surrogate keys, tag-based purge and stale-while-revalidate. Cache dynamic responses safely with fine-grained TTL and vary rules.
Security layer
Managed TLS 1.3, volumetric DDoS mitigation and a rule-based WAF with managed rulesets and per-route overrides.
Observability
Structured access logs, RED metrics per route and real-time alerting via webhooks, Slack or email.
Origins & shielding
Connect any origin — cloud, on-prem or object storage — with origin shielding to collapse requests and cut egress cost.
How a request flows
Each request is terminated, inspected, matched against your routing rules and served from cache or origin — all within a few milliseconds at the edge.
| Stage | What happens |
|---|---|
| 1. Terminate | TLS 1.3 handshake completes at the nearest PoP. |
| 2. Inspect | WAF and rate-limit rules evaluate the request. |
| 3. Route | Path and host rules select the matching backend or function. |
| 4. Serve | Cache hit returns instantly; misses fetch from a shielded origin. |
| 5. Observe | Latency, status and cache outcome are recorded and streamed. |