Start ignoring DDoS attacks, for free.
Every Torchbyte service ships with always-on L3/L4/L7 mitigation powered by Zeroms.net: over 1 Tbit/s of scrubbing capacity with game-aware filtering, at no extra cost.
- +1 Tbit/s
- Mitigation capacity
- <1 ms
- Edge decision time
- 24/7
- On-call mitigation team
- Always-on
- No manual activation
Mitigated at the edge, before it reaches you
Traffic is filtered the moment it enters our network, so attacks are absorbed upstream and your server only ever sees clean traffic.
Every packet inspected
All traffic is inspected, not sampled like sFlow. eBPF/XDP programs process packets before they reach the networking stack, so filtering decisions happen in under a millisecond.
Attacks dropped at the edge
Volumetric floods, protocol abuse and application-layer attacks are absorbed by the Anycast scrubbing cluster anchored in our Bucharest PoP, backed by +1 Tbit/s of Zeroms.net capacity.
Clean traffic forwarded
Only verified traffic reaches your server, with no noticeable added latency. Players and users keep their session. Most never know an attack happened.
Every packet runs through Zeroms.net
Torchbyte's mitigation isn't a bolted-on third party. It is Zeroms.net, the DDoS-protected IP transit platform built by the same team, protecting game server operators since 2021. The promise is in the name: zero added latency, always-on filtering and more than 1 Tbit/s of scrubbing across every point of presence.
- Scrubbing capacity
- 1 Tbit/s+
- Time-to-mitigate
- 0 ms
- Protecting GSPs since
- 2021
- NOC on call
- 24/7
Scrubbing capacity
Time-to-mitigate
Protecting GSPs since
NOC on call
0 ms time-to-mitigate
Always-on filtering with no detection window and no rerouting delay. Every packet is inspected from the very first one, so there is no gap for an attack to slip through.
Filtered at the edge
Attacks are absorbed at the point of presence closest to the source. Clean traffic continues to your server with no GRE hairpinning across continents and no latency spike.
1 Tbit/s+ of scrubbing
More than a terabit per second of capacity across all points of presence, sized to absorb record-breaking volumetric floods without blackholing you.
Protocol-aware profiles
Each profile is purpose-built for its protocol and inspects at the application layer, so legitimate player traffic passes through and attack traffic doesn't.
Real-time dashboard
Live attack visibility (what is being blocked, how much and why) with smart protocol detection that matches your traffic to the right filter automatically.
Full API + 24/7 NOC
Automate prefix announcements, filter profiles and traffic stats over the API. Behind it, a human NOC that calls enterprise clients before they even notice an attack.
Generic web scrubbing can't read a game's UDP traffic. Zeroms.net ships purpose-built filter profiles for the protocols operators actually run:
- FiveM
- alt:V
- SA-MP
- Minecraft Java
- DayZ
- Ark: Survival
- Palworld
- Hurtworld
- Path of Titans
- The Isle
- Arma Reforger
- SCP: Secret Laboratory
- Factorio
- Tibia
- TeamSpeak 3
- Source / A2S
- RakNet
- OpenVPN
- WireGuard
- SSH
- TLS
- RDP
- DNS
- NTP
- HTTP
- FTP
Need to protect a server hosted elsewhere? Zeroms.net delivers clean traffic over a GRE tunnel or direct connection, with a free tier (up to 300 Mbps and a /24) and commitments from 500 Mbps to 10 Gbit/s. Ask us or see zeroms.net.
What we protect against
Full-spectrum mitigation across layers 3, 4 and 7, from raw volumetric floods to targeted application-layer attacks.
Volumetric attacks (L3/L4)
UDP floods, amplification and reflection absorbed by more than 1 Tbit/s of scrubbing capacity, enough for world-record-sized attacks.
Protocol attacks
SYN floods, ACK floods and TCP state exhaustion handled with stateful, protocol-aware filtering.
Application-layer (L7)
HTTP/S floods, DNS abuse and game-engine exploits like query floods filtered without blocking real visitors.
Game servers
Zero-Trust, game-aware profiles for Minecraft, FiveM, Rust, CS2 and more. Packets must pass authentication checks before they reach your server.
Voice & real-time
Low-jitter protection for TeamSpeak, pma-voice, mumble-voip and other latency-sensitive services.
Web, APIs & e-commerce
Keeps websites, control panels and transaction systems responsive and available throughout an attack.
Profiles that speak your game's protocol
Generic web protection isn't enough for real-time UDP traffic. Our Zero-Trust profiles understand the packet structures of popular game engines, so floods are dropped and real players never are.
Minecraft
TCPFilters malicious login floods, query exploits and SYN floods, keeping proxies and backend servers online.
FiveM / RedM
UDP/TCPStops UDP floods targeting the Cfx.re heartbeat and drops spoofed traffic aimed at crashing the FXServer.
Rust & Source games
UDPAdvanced filtering for A2S_INFO query floods and the volumetric UDP attacks common around wipe days.
CS2 & voice servers
UDPSession-validated filtering for competitive servers and VoIP, so matches and calls stay uninterrupted.
Engineered for speed and precision
Mitigation that is fast enough for real-time workloads and precise enough to never get in your users' way.
+1 Tbit/s via Zeroms.net
Scrubbing capacity provided by our mitigation partner Zeroms.net, sized for the largest attacks seen in the wild.
<1 ms edge decisions
XDP kernel programs act on packets before they touch the networking stack, with zero latency impact on legitimate traffic.
eBPF / XDP filtering
Programmable, protocol-aware rules execute at line rate in the kernel and are continuously developed in-house.
Anycast scrubbing
The scrubbing cluster is anchored in our Bucharest PoP, so mitigation happens close to your server, not a continent away.
True traffic inspection
Every single packet is inspected, not sFlow-style samples, so statistics are exact and nothing slips through between samples.
Attack analytics
Statistics on legitimate and malicious traffic help you make better security and capacity decisions.
Protection that adds virtually no latency
Filtering runs in-kernel at the edge with eBPF/XDP, so mitigation decisions are made in well under a millisecond. Legitimate users see no disruption, which is exactly why it suits real-time workloads.
Real engineers, on call around the clock
Always-on automated mitigation handles the vast majority of attacks instantly, the moment malicious traffic hits the edge. For the rare sophisticated or adaptive attacks that try to slip past automation, on-call security engineers from the Zeroms.net team monitor and respond 24/7, a meaningful difference versus fully automated-only solutions.
- Automatic mitigation, always on
- Human escalation for complex attacks
- Continuous monitoring, day and night
What every Torchbyte service gets
Detection, alerting, dual-stack coverage and reporting are part of the platform, not an upsell.
Protection that just works, by default
Nothing to buy and nothing to configure. Enterprise-grade mitigation is built into every server we run.
Included free, always
Every Torchbyte service (game servers, VPS, dedicated, colocation on our upstream and web hosting) ships with full DDoS protection at no extra cost.
Powered by Zeroms.net
Mitigation is delivered with our partner Zeroms.net, whose scrubbing platform is engineered specifically for low-latency, game-heavy traffic.
Zero configuration
Protection is live the moment your service is provisioned. No thresholds to set, no activation delay, nothing to maintain.
Protection for external hosts
Need to protect a server hosted elsewhere? Zeroms.net offers standalone remote protection over GRE/IPIP clean-traffic tunnels. Request a quote at Zeroms.net or ask us.
DDoS protection, answered
The essentials on inclusion, attack coverage, latency, game servers and reporting.
Deploy with +1 Tbit/s of protection included.
Game servers, VPS, dedicated servers and web hosting: every Torchbyte service ships with always-on Zeroms.net mitigation at no extra cost. Need to protect a server hosted elsewhere? Ask about GRE/IPIP remote protection.

