Skip to content
Network & hardware

Our own ASN, our own address space, our own opinions about silicon.

IPv4 address space announced from our own autonomous system across 8 locations, 350 Gbps of uplink and 16.5 Tbps of always-on scrubbing — both totalled from the per-site table below, so you can check the arithmetic as well as the claim.

AS64511
Autonomous system
example number — see note below
350 Gbps
Uplink capacity
sum of all sites
16.5 Tbps
Scrubbing capacity
sum of all sites; up to 6.5 Tbps at one
99.9%
Availability commitment
SLA target, not a measurement
About the AS number above
AS64511 is not our registered autonomous system number. Example ASN reserved for documentation (RFC 5398). Our registered ASN is published here at launch. We tell people to look up a host’s ASN before trusting it, so it would be a poor joke to print one here that fails the check without saying so. The uplink and scrubbing figures beside it are real, and they are simply the sum of the per-site column further down this page.
Compute

What is actually in the racks.

Specific part numbers, because 'enterprise-grade hardware' means nothing and everybody says it.

AMD EPYC and Ryzen

EPYC 7443P and 9354P for density, Ryzen 9 5950X and 7950X where single-thread performance matters. Maximum 3:1 vCPU to physical thread on compute nodes, and typically lower.

Enterprise NVMe, RAID-10

Samsung PM9A3 and Micron 7450 class drives in RAID-10 on every compute node. Typical random read exceeds 400k IOPS per node. Not SATA relabelled as fast storage.

DDR4 and DDR5 ECC

ECC throughout, with no exceptions and no consumer memory anywhere in the fleet. Correctable errors are monitored and a drifting DIMM is replaced before it becomes an incident.

Redundant uplinks

Every site has at least three upstream transit providers plus exchange peering. No site depends on a single carrier, and no site depends on a single fibre path.

Always-on scrubbing

Filtering is inline rather than triggered, so there is no detection delay and no BGP re-announcement that advertises the fact you are under attack.

N+1 power and cooling

Tier III or better at every site bar Seychelles, which is Tier II+ in our own cage. Dual feeds, UPS and generator, tested under load monthly rather than annually.

Connectivity

Per-site network detail

Uplink capacity, mitigation capacity and the facility behind each location.

Full location detail
SiteFacilityTierUplinkScrubbingTest IP
🇳🇱 AmsterdamNikhef / AMS-IX campusTier III+100 Gbps6.5 Tbps198.51.100.10
🇷🇴 BucharestM247 BucharestTier III40 Gbps2 Tbps198.51.100.20
🇮🇸 ReykjavíkAdvania ThorTier III20 Gbps1.2 Tbps198.51.100.30
🇧🇬 SofiaTelepoint SofiaTier III40 Gbps1.5 Tbps198.51.100.40
🇲🇩 ChișinăuTrabia MDTier III20 Gbps1 Tbps198.51.100.50
🇵🇦 Panama CityPanama Digital GatewayTier III20 Gbps0.8 Tbps198.51.100.60
🇸🇨 VictoriaNimbusVPS Cage SC-1Tier II+10 Gbps0.5 Tbps198.51.100.70
🇺🇸 Kansas CityWholesale Data Center KC1Tier III100 Gbps3 Tbps198.51.100.80
The test IPs in that last column are examples
Example addresses reserved for documentation (RFC 5737). They do not answer — the live per-site targets go up when each site opens to orders. Please do not read a silent ping as a network problem — there is nothing at the other end of those addresses to answer you yet.
Peering policy
Open peering at every exchange where we have a presence. No ratio requirement, no traffic minimum, no charge. Send your ASN and preferred exchange to [email protected] and we will usually have a session up within two business days. We are also happy to establish private interconnects where volume justifies it.
DDoS mitigation

We do not null-route the victim.

Most budget providers respond to an attack by null-routing the target IP. It protects their network and makes your server unreachable, which from your side is the attack succeeding.

How mitigation works in detail

Standard — included

L3/L4 volumetric filtering on every plan at no charge. SYN, ACK and RST floods, UDP amplification, ICMP floods, fragmented packets, spoofed-source attacks.

Advanced — $5/month

Adds layer-7 inspection, HTTP and HTTPS challenge, TCP fingerprinting and game protocol profiles for Source, Minecraft and FiveM.

Enterprise — $19/month

Dedicated scrubbing profile, custom ACLs, BGP announcement of your own prefix and a direct line to the NOC.

No detection delay

Filtering is inline rather than triggered on detection, so there is no window during which the attack lands before mitigation engages.

Questions

Network FAQ

What hardware do the VPS nodes run on?

+
AMD EPYC 7443P and 9354P for high-density compute nodes, and Ryzen 9 5950X and 7950X for latency-sensitive single-thread workloads. Memory is DDR4 and DDR5 ECC throughout. Storage is enterprise NVMe — Samsung PM9A3 and Micron 7450 class — in RAID-10 on every compute node.

What is your vCPU oversubscription ratio?

+
Compute nodes run at a maximum of 3:1 vCPU to physical thread, and typically well below that. Steal time on a healthy node sits under 1%. You can verify this on your own server with vmstat: the st column reports exactly this, and if you see sustained figures above 5% we want to know because it means a node needs rebalancing.

Do you own your IP space?

+
Yes — we announce IPv4 address space along with IPv6 space from our own autonomous system rather than reselling an upstream's. This matters practically rather than symbolically: a provider reselling someone else's addressing can have a customer's prefix withdrawn by its upstream on a phone call, regardless of its own stated policies. Two caveats come with that claim, since we are asking you to check it. The AS number shown on this page is currently AS64511, a number reserved for documentation by RFC 5398, standing in until our registered number is published at launch — do not treat it as a live lookup. The prefix sizes are published at launch alongside the registered ASN. Until the AS number resolves, a prefix size printed here would be a claim you could not check, so we do not print one.

How does the DDoS protection work?

+
Traffic passes through scrubbing continuously rather than being redirected when an attack is detected, which removes the detection delay during which your service would otherwise be down. Scrubbing capacity sums to 16.5 Tbps across the fleet, but capacity does not pool: the figure that defends you is the one at your own site, which ranges up to 6.5 Tbps and is listed per site in the table above. We do not null-route the customer being attacked — null-routing protects the network by making your server unreachable, which from your side is indistinguishable from the attack succeeding.

Can I announce my own IP prefix?

+
Yes, on dedicated servers, at no charge. We establish a BGP session and announce a prefix you hold, or act as upstream if you have your own ASN. You need a valid RIR object and a route object; our network team walks through it in a ticket. Full-table or default-only, your choice.

What is your peering policy?

+
Open peering at every exchange where we have a presence. We do not require ratio or traffic minimums and we do not charge for peering. Contact the NOC with your ASN and preferred exchange; sessions are usually established within two business days.

Measure it before you buy it.

Every location publishes a ping target and a test file. Do not take our word for any of this.

7-day money-back guarantee · No KYC · Cancel any time from the panel