GDPR and request logs: what we store and why (part 2)
gDPR and request logs: what we store and why sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.The numbersAcross the…
gDPR and request logs: what we store and why sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.The numbersAcross the…
Here is a question we could not answer well a year ago: what really happens with rate limiting APIs without breaking legitimate integrations? We can answer it now.Protecting the originNone of this…
Over the last few months we have spent a lot of time on preparing evidence for an ISO 27001 audit after an incident. This is what we learned.Observability firstEvery mitigation decision is…
We get asked about the economics of DDoS-for-hire in 2026 more than almost anything else, so here is the long answer.Observability firstEvery mitigation decision is logged with its reasons, and every log…
how to hide your origin IP properly sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.Protecting the originNone of this…
Here is a question we could not answer well a year ago: what really happens with how we test WAF rules against seven days of real traffic? We can answer it now.The…
Over the last few months we have spent a lot of time on scraper bots are getting better at pretending to be Chrome. This is what we learned.Measuring successWe track three numbers…
Here is a question we could not answer well a year ago: what really happens with keeping search engine bots happy while blocking scrapers? We can answer it now.Protecting the originNone of…
We get asked about per-tenant rate limits for SaaS platforms more than almost anything else, so here is the long answer.What we changedWe moved the decision from a single threshold to a…
We get asked about extortion DDoS campaigns target payment providers again more than almost anything else, so here is the long answer.What actually happens during a floodThe first thing to fail during…
qUIC and HTTP/3 at the edge: what changes for DDoS mitigation sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.Lessons…
bot management without CAPTCHAs sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.Compliance is a side effectRegulators increasingly ask for…