The mitigation layer that works the moment you point DNS at it.
Layer7 is a reverse proxy and WAF that sits in front of your site, drops attack traffic at our edge, and passes clean requests to your origin. There's no "under attack" button to flip, and no rules you have to configure before the next flood lands. Move your domain onto our nameservers, or point a CNAME at us and keep your DNS.
Register, verify your email, add your domain, check out. Protected as soon as payment clears.
What is Layer7?
Most services hand you a control panel and expect you to know which knobs to turn before an attack hits. We think that's backwards. Out of the box, Layer7 is configured the way we'd configure it for ourselves, and you can still write your own rules whenever you want.
Protected at request one
Mitigation engages from the first request, not after your error rate crosses some threshold. Small sites get the same defense as large ones.
No interstitial by default
Bot scoring runs on TLS fingerprints, header consistency, and request cadence, not a JS challenge a headless browser can pass. Real users never see a wall.
Same protection on every plan
The full mitigation engine runs for every plan, free included. Paid plans buy control on top: your own rules, more hostnames, more seats. Nobody gets a weaker defense for paying less.
Rules without code
Need an exception? Add your own allow and block rules from the dashboard, per domain, with no config language to learn. Mitigation works by default, so we recommend custom rules only when absolutely necessary.
No rate limiting
We don't believe in it. A rate limit throttles your real users at the worst possible moment and calls it mitigation. Layer7 scores and filters every request instead, so clean traffic keeps flowing at full speed, even in the middle of an attack.
Origin that stays hidden
We provision origin-side mTLS by default and rotate the cert on a schedule. If your origin IP leaks, the connection still has to prove it came from our edge.
Where this runs today. While we build our own scrubbing network, Layer7 runs on Cloudflare's serverless edge. To be clear about who does what: Cloudflare's application-layer mitigation and bot protection are switched off for the traffic we handle. Everything that judges your traffic, the scoring, the challenges, the rules, is Layer7's engine. When our network comes online, your setup won't change.
Two ways to connect.
Both get the same mitigation; the difference is how much of your DNS we handle.
Nameserver setup
RecommendedDelegate the domain to Layer7 nameservers and manage DNS in the dashboard like normal, with mitigation on top.
- Covers the whole domain: apex and every subdomain
- Full DNS management in the Layer7 dashboard
- Nameserver changes can take hours to propagate
- Requires a paid plan, Pro or above
CNAME setup
Keep your DNS where it is. Point a hostname at your Layer7 target and it's protected.
- Works from any DNS provider, nothing to delegate
- Covers the hostnames you point, up to your plan's allowance
- The apex needs CNAME flattening at your DNS host
- Available on every plan, free included
Pricing.
Per protected domain, billed monthly. Mix plans across domains. The defense is identical on every plan; paying gets you more control, not better protection.
- 3 protected hostnames1
- 25 custom rules2
- 3 team seats3
- CNAME or Nameserver setup
- 15 protected hostnames1
- 64 custom rules2
- 10 team seats3
- CNAME or Nameserver setup
- Unlimited hostnames1
- 64 custom rules2
- Custom seats
- CNAME or Nameserver setup
- Hostname counts apply to CNAME setup only. Nameserver setup covers the whole domain, apex and every subdomain, with nothing to count.
- Custom rules are rules you add yourself; the protection underneath is the same on every plan, free included. Most sites never need one, mitigation works by default.
- Seats are people you invite besides yourself. Pending invitations count toward the limit.
What we've been up to.
A running log of attacks we've absorbed, work that shipped, and the people we've helped take off the internet. Entries before 2026 come from the network R&D that became this product.
Live now: self-serve signup Live
Register, add a domain, and you're protected the same day. Pro and Business check out online; the free tier is by application. Our own scrubbing network is in development; your setup won't change when it lands.
975k rps flood: 22 requests reached the origin
125.8 million requests in one flood, roughly 975,000 per second, and more than 99.9999% of it filtered at the edge. The count comes from the origin's own access log, not our analytics.
Aisuru botnet: intelligence shared with law enforcement War Room
Provided attack telemetry and infrastructure mapping that supported the effort against the Aisuru botnet. Write-up on the War Room blog.
Kimwolf botnet: primary intelligence source War Room
Our threat intelligence was first to reach investigators on Kimwolf and helped drive the law-enforcement response. The traffic we don't deliver to customers is data, and we'd rather it shut something down at the source.
Dashboard & rule editor in closed testing
The control panel, analytics views, and the rule editor entered hands-on testing with a small group of partner sites running real production traffic.
Origin protection hardened
Shipped origin-side mTLS with automatic certificate rotation, so a leaked origin IP no longer means a bypassed WAF.
Bot scoring engine rebuilt
Moved bot detection onto TLS fingerprinting, header consistency, and request-cadence analysis. Now it scores every request instead of leaning on a JS interstitial.
Custom rule engine shipped internally
Rules versioned like code and deployed to every edge node in seconds. Built it for our own operators first, then started widening access.
Closed testing with partner sites
Began running a handful of real sites fully behind Layer7 to shake out edge cases the synthetic load tests never produced.
2.62B PPS L4 attack mitigated
Mitigated a high-volume Layer 4 DDoS attack peaking at 2.62 billion packets per second and 1.4 terabytes per second over a 3-minute burst, without any disruption or packet loss.
1B PPS L4 attack mitigated
Mitigated a sustained Layer 4 DDoS attack averaging nearly 1 billion packets per second for 16 minutes straight, without any disruption.
Out-of-network auto-scaling ready
Mitigation nodes outside the core network now auto-deploy in seconds, adding global surge capacity when traffic spikes.
15M RPS attack mitigated
Tested against a massive Meris-based Layer 7 attack on WHMCS. Over 99.99% of traffic filtered with PoW and zero rate limiting.
Live botnet testing completed
System proven effective under real attacks from Meris, Gorilla, and Mirai variants with no performance degradation.
API development progress
Core account API endpoints created and tested. Mitigation endpoints are now in development.
Cooperation with law enforcement described above does not imply endorsement by any agency.