NordHealth runs a news publisher serving customers across North America. Before Deflecto, attacks meant diverting traffic to a scrubbing provider and waiting.
The challenge
Bonus abuse by automated account creation.
The result
- 258 attacks mitigated in the first year
- Median time to mitigation 614 ms
- 15% lower origin infrastructure cost
- Zero customer-visible outages
We replaced a CAPTCHA that cost us conversions with something our customers never see.
CISO, NordHealth
How do you avoid challenging uptime monitors and partners?
Carpet bombing is nasty. Good to see a clear explanation of it.
Verified good bots and allow-listed partners bypass challenges entirely.
Nice to read a vendor blog that admits what went wrong.
Machine-readable ranges are at /ips.json and via the API.
Interesting that most attacks are under ten minutes. Our experience is similar.
Could you share the dataset behind the percentages?
Machine-readable ranges are at /ips.json and via the API.
Interesting that most attacks are under ten minutes. Our experience is similar.
Thanks! Yes — the risk score and its components are included in every log record.
The billing model is what got our finance team on board, honestly.
Would love a follow-up on how you handle HTTP/3 fingerprinting.