ESpanix Shield is DDoS protection built into the exchange: we detect and block the attack inside the ESpanix network, before it reaches your port. No diversions, no added latency.
- No added latency: legitimate traffic travels straight through. The path under attack is the same as the path in calm conditions: no GRE tunnels, no extra hops.
- Certified sovereignty and security: mitigation happens inside the ESpanix network, certified to ISO/IEC 27001 and to the Spanish National Security Framework (ENS) at High category. Your traffic never leaves Spain.
- Precision: granular filtering that separates attack sources from the real user arriving over the same network, without discarding whole prefixes.
- Protection in both directions: we also identify attack traffic leaving your network, keeping your infrastructure out of global campaigns.
| Feature | Traditional model (cloud scrubbing) | ESpanix Shield (edge mitigation) |
|---|---|---|
| Traffic path | Divert → external centre → return | Direct, no diversions |
| Added latency | Whatever the trip to the scrubber costs | None |
| Sovereignty | Third parties, possibly outside the EU | ESpanix network, in Spain |
| Complexity | Per-customer BGP/GRE configuration | No changes to your network |
| Granularity | Risk of prefix-level discard | Granular filtering |
| Traffic direction | Inbound only | Inbound, plus outbound detection |