Always-on protection for infrastructure that is exposed by design.
Every Joy server is behind volumetric and L3–L7 scrubbing at no extra charge. Networks that run their own routers get the same filtering as DDoS-protected transit or Virtual Connect over GRE — detected by NeuroMesh NetFlow, diverted by BGP, delivered clean.

Attacks against game hosts, ISPs and SaaS platforms in India are routine, not exceptional, and a filter that has to be switched on after the flood begins is already too late. Joy's scrubbing is always on. NeuroMesh NetFlow collects encrypted flow telemetry from every edge of AS152565, scores anomalies in real time and triggers BGP diversion for the affected prefixes; clean traffic returns to the customer over the backbone, or through a GRE tunnel to a router anywhere on the internet.
Volumetric floods, amplification (DNS, NTP, SSDP, memcached), SYN/ACK storms and L7 request floods are handled automatically. Customers can request custom rules for game protocols, use the 152565:666 community to blackhole a single /32 at every edge, and see mitigation events on the status page when they affect a component. For HTTP origins the CDN adds bot filtering and an optional managed WAF ruleset.
Protection is included with every VPS, bare-metal server and colocation port. Networks that are not in a Joy facility buy it as DDoS-protected transit or as Virtual Connect — BGP over GRE that puts Joy scrubbing in front of infrastructure you already own, from any provider that gives you a public IP with GRE pass-through.
D1 · D2 · D3
The three things this product line is built around — the same three boxes you see on the tile.
Filtering built for floods, protocol abuse and L7
Volumetric floods, amplification vectors, SYN/ACK storms and HTTP request floods are classified by flow telemetry and dropped at the edge; legitimate sessions keep their state and their latency.
Built to absorb and mitigate at scale
Scrubbing capacity at every edge of AS152565 with BGP diversion per prefix, so an attack on one customer never fills the port of another; mitigation events are published on the status page.
Always-on for exposed infrastructure
No activation delay and no per-attack charges. Game servers, DNS, VPN concentrators and public APIs are protected from the first packet, on Joy hardware or on your own router through Virtual Connect.
Specification
| Coverage | Always-on volumetric and L3–L7 filtering for every Joy VPS, dedicated server and colocation port at no extra charge |
|---|---|
| Detection | NeuroMesh NetFlow: encrypted flow telemetry from every edge, real-time anomaly scoring, automatic BGP diversion |
| Vectors | UDP/ICMP floods, DNS/NTP/SSDP/memcached amplification, SYN/ACK storms, HTTP request floods |
| Delivery | Clean traffic over the backbone to Joy servers; DDoS-protected transit on a Joy port; Virtual Connect (BGP over GRE) to your router anywhere |
| Customer controls | Blackhole community 152565:666 per /32 or /128; per-upstream communities; custom rules for game protocols on request |
| HTTP origins | CDN bot filtering on every resource; managed WAF ruleset $10 per hostname per month |
| Pricing (networks) | DDoS-protected transit from $700 / Gbps (95th percentile), 5% discount per doubling of commit; Virtual Connect from $200 for 100 Mbps |
| Visibility | Mitigation events on the status page; traffic graphs and session state on the Network page for transit customers |
Three steps
Traffic is measured at every edge
Flow telemetry from all of AS152565 is scored continuously against per-prefix baselines by NeuroMesh NetFlow.
Attack traffic is diverted and scrubbed
BGP diverts the affected prefix into scrubbing; floods, amplification and request storms are dropped while legitimate sessions pass.
Clean traffic is delivered
Over the backbone to your Joy server, on a protected transit port, or through a GRE tunnel to your own router — with the event visible on the status page.
Where DDoS Protection fits.
Questions about DDoS Protection.
Is protection really free on a VPS?
What is Virtual Connect?
Can I blackhole an address myself?
Will I be told about attacks?
More answers in the full FAQ — billing, network, DDoS, backups, support and legal.
Included with every server · from $700 / Gbps for networks
VPS and dedicated servers are protected at no charge. DDoS-protected transit and Virtual Connect for your own routers are priced per Gbps on the peering page.
Works with
Build DDoS Protection into your stack.
Create an account and deploy in under ninety seconds, or talk to sales about a design for your workload — regions, sizes, timelines and a quote within one business day.



