When your infrastructure goes down,
everyone you host goes down with it.
Hosting and infrastructure providers are the highest-leverage target of the AI-attack era: one successful hit cascades to every customer on the box, and to your name. Nemesis protects the whole platform at the infrastructure level, and every app running on it, so a single attack has to beat two layers instead of taking down a shared origin. This is an honest look at where your current setup ends and where we begin.
The shared-responsibility trap
You secure the platform. Your customers are supposed to secure their apps. In practice the seam between those two is exactly where the damage happens, and it is a seam an attacker reads perfectly:
- One soft tenant is a door into the box.You run hundreds or thousands of apps you don't control. The weakest one becomes the blast radius, and the blast radius is shared hardware, a shared IP, a shared reputation.
- A single flood is a shared outage. A volumetric or application-layer attack aimed at one origin saturates the link everyone behind it shares. Every customer on that server goes dark at once, through no fault of their own.
- The origin is findable. A leaked DNS record, a certificate-transparency log, an old subdomain, and the attacker skips your front door entirely and hits the server directly, underneath anything that only guards the DNS route.
- You can't put a per-app WAF on code you don't own.The classic answer, a behavioral firewall per application, assumes you control the application. On a multi-tenant fleet you don't, so most hosts fall back to blunt global rate limits that punish real users and miss real attacks.
- Static defenses lose to AI-speed attacks. Signatures and fixed rate limits were written for human-paced, repetitive attacks. AI generates novel, distributed, low-and-slow patterns faster than anyone updates a rule.
Two layers on every server, one brain over the fleet
Your customers' domains resolve to the Nemesis edge, not to your origins, so floods aimed at a hostname hit absorbent infrastructure. On every server a kernel-level XDP agent drops hostile traffic before the network stack sees it, closing the origin-direct and API doors the edge can't. Every drop across the fleet feeds one brain that immunizes the rest.
- Edge: hide the origin, absorb the flood. Protective DNS plus an optional inline proxy front any infrastructure or sit on top of your existing CDN. The origin IP never appears in public DNS.
- Agent: drop it in the kernel, on the box.One install per server loads an XDP/eBPF data plane that drops known-bad sources, enforces edge-only ingress (so a leaked origin IP still can't be reached directly), and rate-limits new connections, all pre-stack, fail-open, at near-zero cost. Proven in-kernel: a heavy multi-vector flood is dropped at line rate while legitimate traffic keeps flowing.
- Fleet herd immunity. An attacker seen on one customer is promoted to a global blocklist every agent pulls, so the rest of your fleet drops them before they arrive. Cross-site botnets, ramps and carpet-bomb subnets are caught out of band, never in the request path.
- Upstream for the worst case. When a flood is big enough to saturate the pipe before the box can drop it, the agent signals your transit or IX over BGP FlowSpec or RTBH to push the drop above your link.
Earn the right to block. Per tenant, from one console.
A defense you can't trust to block is a defense you leave in monitor mode forever. Every layer, edge and kernel, moves through the same three postures, and you set them from one place over your whole fleet:
- Learn.The system builds a baseline of what each tenant's traffic actually looks like. It never drops.
- Observe. Baselines are ready. It now counts every packet it would have dropped, on real traffic, with the consequence still hypothetical, so you can see the decision before you trust it.
- Enforce. Only now does it drop. You flip it when the numbers are obviously right, and a local kill-switch can pull any server back to observe instantly.
The same three words mean the same thing at the edge and in the kernel. You own the enforcement point: it is a program on your servers you can inspect, stage and turn off, not a verdict made inside a network you can't see.
Defend the traffic and the machine
Traffic is only half of it. The servers themselves are targets, and on a multi-tenant box a single compromise is a data-breach headline. Nemesis Blue is a kernel-level EDR for your hosts: real-time file, network and kernel-module protection via eBPF and LSM, with an immutable audit chain. Shield defends the traffic; Blue defends the machine; both roll up into one fleet console with per-server and per-customer posture.
What we don't claim
The fastest way to lose a security buyer is to overclaim, so, plainly: we do not operate a hyperscale anycast network, and for a pure, arbitrarily-large volumetric flood, raw upstream capacity is the right tool and we are honest that it is not us. What we do is kill most attacks early and on the box, immunize the fleet from the first sighting, and push the worst case upstream over BGP, while covering the origin-direct, API and side-door traffic that anycast in front of you never sees. We prove what the kernel drops, and we start every deployment in observe so you see the decisions before you trust them.
Questions hosting providers ask
How do hosting companies protect against DDoS at the infrastructure level?
Two layers, not one. Nemesis fronts your customers' domains at a DNS edge so the origin IP is never public and floods hit absorbent infrastructure, and it runs a kernel-level XDP agent on each of your servers that drops hostile packets before they reach the network stack. The edge guards the DNS route; the on-server agent guards origin-direct and API traffic the edge never sees. For volumetric that saturates the pipe, the agent signals upstream over BGP FlowSpec / RTBH.
How do I protect every customer app on a shared server when I don't control their code?
You don't have to touch their code. The Nemesis agent installs once per server and protects every app and vhost on it at the network layer, learning each tenant's normal traffic and moving through learn → observe → enforce that you set from one console. Customers who want deeper application protection can add the one-line Shield SDK themselves, but the fleet-wide DDoS and network defense needs nothing from them.
Why are hosting and infrastructure providers a bigger target now?
Leverage. One host sits under thousands of downstream sites, so a single successful attack cascades to every customer on that box plus your reputation. And AI has collapsed the cost of attacking: what used to need a skilled crew now runs as a script at scale, generating novel patterns faster than static rules and rate limits can be written. The economics now favor the attacker unless the defense also scales and learns.
What is fleet herd immunity?
An attacker hitting one customer on your platform is promoted to a global blocklist that every enrolled server pulls, so a box the attacker hasn't even reached yet is already dropping them. Cross-site botnets (herd), single-source ramps, and carpet-bomb subnets are detected out of band and shipped to every agent's kernel. The more of your fleet is protected, the harder the whole platform is to hit.
Is this a Cloudflare alternative for hosting providers?
It complements one and covers what one can't. A global anycast network wins on raw capacity for pure hyperscale volumetric, and we say so plainly. But it only protects what flows through it; the moment traffic reaches your servers another way (origin-direct, API, a leaked IP) it is outside that coverage. The Nemesis agent drops that traffic on the box itself, and you own the enforcement point instead of routing every service through a network you can't inspect.
Can I protect my own servers, not just customer traffic?
Yes. Nemesis Blue is a kernel-level EDR for the hosts themselves: real-time file, network and module protection via eBPF and LSM, so a compromised box on your fleet is detected and contained. Shield defends the traffic; Blue defends the machine. Both report into one console with per-server and per-customer posture.
Make your platform the hard target.
If you run infrastructure, we'll help you pressure-test your DDoS posture and roll Nemesis across your fleet, starting in observe so nothing changes until you say so.
