[ FOR HOSTING & INFRASTRUCTURE ]

When your infrastructure goes down,
everyone you host goes down with it.

Hosting and infrastructure providers are the highest-leverage target of the AI-attack era: one successful hit cascades to every customer on the box, and to your name. Nemesis protects the whole platform at the infrastructure level, and every app running on it, so a single attack has to beat two layers instead of taking down a shared origin. This is an honest look at where your current setup ends and where we begin.

The shared-responsibility trap

You secure the platform. Your customers are supposed to secure their apps. In practice the seam between those two is exactly where the damage happens, and it is a seam an attacker reads perfectly:

Two layers on every server, one brain over the fleet

users +attackersNemesis edgeDNS route · origin hiddenabsorbs the floodserver 01 · XDP agentdrops in the kernelmany apps · many tenantsserver 02 · XDP agentdrops in the kernelmany apps · many tenantsserver 03 · XDP agentdrops in the kernelmany apps · many tenantsfleet herd immunityclean onlyorigin-direct → dropped in-kernel

Your customers' domains resolve to the Nemesis edge, not to your origins, so floods aimed at a hostname hit absorbent infrastructure. On every server a kernel-level XDP agent drops hostile traffic before the network stack sees it, closing the origin-direct and API doors the edge can't. Every drop across the fleet feeds one brain that immunizes the rest.

Earn the right to block. Per tenant, from one console.

A defense you can't trust to block is a defense you leave in monitor mode forever. Every layer, edge and kernel, moves through the same three postures, and you set them from one place over your whole fleet:

The same three words mean the same thing at the edge and in the kernel. You own the enforcement point: it is a program on your servers you can inspect, stage and turn off, not a verdict made inside a network you can't see.

Defend the traffic and the machine

Traffic is only half of it. The servers themselves are targets, and on a multi-tenant box a single compromise is a data-breach headline. Nemesis Blue is a kernel-level EDR for your hosts: real-time file, network and kernel-module protection via eBPF and LSM, with an immutable audit chain. Shield defends the traffic; Blue defends the machine; both roll up into one fleet console with per-server and per-customer posture.

What we don't claim

The fastest way to lose a security buyer is to overclaim, so, plainly: we do not operate a hyperscale anycast network, and for a pure, arbitrarily-large volumetric flood, raw upstream capacity is the right tool and we are honest that it is not us. What we do is kill most attacks early and on the box, immunize the fleet from the first sighting, and push the worst case upstream over BGP, while covering the origin-direct, API and side-door traffic that anycast in front of you never sees. We prove what the kernel drops, and we start every deployment in observe so you see the decisions before you trust them.

Questions hosting providers ask

How do hosting companies protect against DDoS at the infrastructure level?

Two layers, not one. Nemesis fronts your customers' domains at a DNS edge so the origin IP is never public and floods hit absorbent infrastructure, and it runs a kernel-level XDP agent on each of your servers that drops hostile packets before they reach the network stack. The edge guards the DNS route; the on-server agent guards origin-direct and API traffic the edge never sees. For volumetric that saturates the pipe, the agent signals upstream over BGP FlowSpec / RTBH.

How do I protect every customer app on a shared server when I don't control their code?

You don't have to touch their code. The Nemesis agent installs once per server and protects every app and vhost on it at the network layer, learning each tenant's normal traffic and moving through learn → observe → enforce that you set from one console. Customers who want deeper application protection can add the one-line Shield SDK themselves, but the fleet-wide DDoS and network defense needs nothing from them.

Why are hosting and infrastructure providers a bigger target now?

Leverage. One host sits under thousands of downstream sites, so a single successful attack cascades to every customer on that box plus your reputation. And AI has collapsed the cost of attacking: what used to need a skilled crew now runs as a script at scale, generating novel patterns faster than static rules and rate limits can be written. The economics now favor the attacker unless the defense also scales and learns.

What is fleet herd immunity?

An attacker hitting one customer on your platform is promoted to a global blocklist that every enrolled server pulls, so a box the attacker hasn't even reached yet is already dropping them. Cross-site botnets (herd), single-source ramps, and carpet-bomb subnets are detected out of band and shipped to every agent's kernel. The more of your fleet is protected, the harder the whole platform is to hit.

Is this a Cloudflare alternative for hosting providers?

It complements one and covers what one can't. A global anycast network wins on raw capacity for pure hyperscale volumetric, and we say so plainly. But it only protects what flows through it; the moment traffic reaches your servers another way (origin-direct, API, a leaked IP) it is outside that coverage. The Nemesis agent drops that traffic on the box itself, and you own the enforcement point instead of routing every service through a network you can't inspect.

Can I protect my own servers, not just customer traffic?

Yes. Nemesis Blue is a kernel-level EDR for the hosts themselves: real-time file, network and module protection via eBPF and LSM, so a compromised box on your fleet is detected and contained. Shield defends the traffic; Blue defends the machine. Both report into one console with per-server and per-customer posture.

Make your platform the hard target.

If you run infrastructure, we'll help you pressure-test your DDoS posture and roll Nemesis across your fleet, starting in observe so nothing changes until you say so.