Always on, never a tier
Layer 3/4 filtering sits upstream of every port for every customer. There is no “protected IP” to buy, because selling protection you already have is a shakedown.
How traffic actually reaches Chișinău, what happens to it on the way, and the things we deliberately do not do to it.
Transit
Both carriers carry traffic at all times. A standby link is a link nobody has tested since the day it was installed.
| Item | Today | What that means |
|---|---|---|
| Two carriers, blended | 20 Gbps | Both live, both carrying traffic. Not a primary with a cold standby — a failure removes capacity, never connectivity. |
| BGP, our own decisions | Full tables | We take full routes from both and choose per prefix. A carrier having a bad day in Frankfurt does not become your bad day. |
| A third on order | In progress | Two upstreams is the minimum to survive one. Three is the minimum to survive one while another is doing maintenance. |
| IPv6 on every port | /64 routed | Not a tunnel and not an afterthought. Native dual stack, a routed /64 per machine, reverse DNS yours to set. |
Chișinău sits one hop off the European backbone through Bucharest — 12 ms away — which is why a single-country network can still answer Frankfurt in 35 ms. The latency map has the rest.
Under attack
The industry standard response to a flood is to null-route the victim. It protects the provider and finishes the attacker’s job for them. We filter, and we keep you reachable.
Always on, never a tier
Layer 3/4 filtering sits upstream of every port for every customer. There is no “protected IP” to buy, because selling protection you already have is a shakedown.
2 Tbps of scrubbing capacity
Volumetric floods are absorbed upstream of our transit, not at our edge. Our own capacity is 20 Gbps; nothing that large ever reaches it.
We do not null-route you
The reflex of most hosts under attack is to blackhole the target and call it mitigation. We filter and keep you reachable, and we call before we ever consider anything else.
Application-layer floods are a conversation
Layer 7 cannot be solved upstream without reading your traffic, which we do not do. So we work it with you — rules, rate limits, an anycast front if you want one.
By omission
On a network, what is absent matters as much as what is installed. These are absences by design, not by oversight.
No traffic inspection
No DPI, no TLS interception, no flow sampling beyond what BGP needs to route. We could not tell you what protocol you run without asking.
No 24-hour flow archive
Connection metadata expires after a day. There is no long-term netflow store, because a store is a thing that can be requested.
No shaping, no fair use
The port is the port. Unmetered means unmetered, and there is no clause further down redefining it at 80% duty cycle.
No forced upstream filtering
We do not accept carrier-side blocklists that would silently drop your traffic. If something must be blocked, a court says so and we tell you.
Do not take our word
Every figure on this page is testable from your own machine, in about a minute, without an account.