Dynamic content & API acceleration
Route sign-in, queries, orders and personalized content to the origin as required. Cache public static assets separately to support both dynamic interactions and content delivery.
Fixed bandwidth acceleration and tiered security for dynamic websites, SaaS and business APIs, with unmetered normal business traffic.
Align bandwidth, protocols and security from request entry to content delivery.
Route sign-in, queries, orders and personalized content to the origin as required. Cache public static assets separately to support both dynamic interactions and content delivery.
Choose standard tiers from 10–300 Mbps or request custom capacity. Legitimate business traffic is unmetered, with monthly, quarterly or annual terms to match your needs.
All tiers include CC and DDoS protection; WAF starts at Standard. Configure IP, URL, regional and request-source rules to suit your business.
All tiers support HTTPS / SSL, IPv4 and IPv6. Configure a secure entry point with the appropriate domain certificates, origin protocol and application settings.
WebSocket starts at Basic and HTTP/3 at Standard. Choose protocols for your application and validate persistent connections, timeouts and reconnection behavior.
All tiers provide intelligent caching, node failover and real-time monitoring. Use log queries and the cache-rule capabilities of your tier to track application behavior.
Configure dynamic endpoints and static assets separately to reduce ineffective caching and unnecessary origin requests. Your application retains control of sessions, user data and authorization.
Estimate bandwidth from response sizes, request frequency and peak concurrency. Include domain counts and protocol requirements when choosing a tier or planning an upgrade.
Set rules for sign-in, search, queries and callbacks. Use logs and application feedback to tune protection while monitoring the experience of legitimate users.
Support member centers, enterprise portals and online services with both personalized signed-in pages and public content.
Plan bandwidth and access rules for queries, orders, administration and multi-tenant applications based on API request patterns.
Support notifications, status updates and real-time collaboration using the persistent-connection protocols included in your tier.
Work through domains, caching, authentication and peak-load validation before launch.
List root domains, accelerated domains, login endpoints, callbacks and admin entry points. Confirm domain counting and bandwidth allocation rules.
Bypass shared caches for authenticated sessions, personal data and APIs requiring live responses. Configure cache lifetimes and refresh rules separately for static assets.
Retain application authentication, permissions and rate limits. Tune CC protection and WAF against real traffic. Verify third-party callbacks, long requests, cross-origin access and file uploads.
Monitor bandwidth, connection counts, error rates and latency. Test peak traffic and reconnection behavior. Confirm rate limiting, alert channels, the original entry point and rollback steps.
Dynamic Secure Acceleration provides fixed business bandwidth with unmetered legitimate traffic. It suits dynamic sites and APIs that budget ongoing usage by bandwidth. Compare peaks, traffic patterns, network routes and feature tiers before choosing.
Differentiate request types. Route sessions, personal data and real-time APIs to the origin as required, while caching public assets separately. Do not put responses containing user identities or private data into a shared cache.
Measure peak bandwidth, response sizes, request frequency and connections, then factor in domain counts and security requirements. Lite provides 10 Mbps and 3,000 concurrent connections. Higher tiers still depend on available resources and configured policies.
WebSocket starts at Basic; WAF and HTTP/3 start at Standard. Advanced waiting rooms, page integrity protection and other capabilities vary by tier. See the pricing page for the full comparison.
This framework guides pre-activation discussions. Both parties agree on thresholds, notification channels, remediation periods, the scope of intervention and restoration conditions based on the workload, and document them in the service plan.
Normal dynamic page and API traffic runs within the purchased bandwidth, without a separate monthly normal-traffic quota. Sustained use of purchased bandwidth alone should not be classified as abuse.
Discuss bulk downloads, video, large files, proxy forwarding, shared resale or load testing in advance. Eligibility, charges and isolation requirements must be agreed before proceeding.
Investigate attack generation, malicious scanning, open proxies, bypassing limits, and deliberately creating abnormal requests or evading protection. Being attacked by a third party is not equivalent to customer-initiated abuse.
Record affected periods, services and reviewable evidence. Notify the customer through agreed channels, then jointly investigate and remediate. Trigger thresholds and remediation periods are confirmed before activation.
Agree on rate limiting, rule adjustments, isolation or suspension based on impact. Establish emergency intervention and notification order, remediation verification, restriction removal and restoration conditions in advance.
Upgrade differences, additional services, cancellation and other charges follow rules agreed in advance. Provide a review channel; undisclosed usage thresholds must not trigger automatic additional fees.
From personal projects to corporate operations, find the protection solution that's right for you.