Most DDoS mitigation products are either a scrubbing centre you divert to after the damage has started, or a CDN with a rate limiter bolted on. Deflecto is neither: filtering is always on, inline, and priced so that attack volume never shows up on your bill.
Network and transport layer
SYN, ACK and RST floods, UDP reflection and amplification (DNS, NTP, memcached, CLDAP, SSDP), GRE and fragmented-packet floods are dropped at the edge using stateless filters and SYN cookies before they consume a single connection slot on your infrastructure.
Application layer
HTTP floods are the attacks that take real businesses offline, because every request looks legitimate on its own. Deflecto scores each request against client reputation, TLS and HTTP/2 fingerprint consistency, request-rate baselines per route and per session, and header-order anomalies. Clients that score poorly are challenged, not blocked — so false positives cost a real user a few hundred milliseconds, not a lost sale.
Slow and low
Slowloris, slow POST and slow-read attacks are neutralised by terminating connections at the edge with strict header, body and idle timeouts. Your origin only ever sees complete requests.
What you see
Every attack gets an incident timeline: start, peak, vectors, top sources by ASN and country, what was challenged, what was dropped and what reached your origin. Exportable as JSON or PDF for your auditors.