OrbisPlay runs a education platform serving customers across the Benelux. Before Deflecto, attacks meant diverting traffic to a scrubbing provider and waiting.
The challenge
Extortion emails followed by short, intense floods.
The result
- 314 attacks mitigated in the first year
- Median time to mitigation 871 ms
- 39% lower origin infrastructure cost
- Zero customer-visible outages
We replaced a CAPTCHA that cost us conversions with something our customers never see.
CTO, OrbisPlay
Great write-up. We saw almost the same pattern on our login endpoint last month.
Our auditors asked for exactly this kind of incident evidence under DORA.
Great to hear, thanks for sharing your experience.
The point about origin IPs leaking through certificate transparency logs is underrated.
How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?
This matches what we see in iGaming around big matches.
How do you avoid challenging uptime monitors and partners?