99.9% UPTIME 24/7 SUPPORT SINCE 2013
STATUS SUPPORT
AlphaVPS
PARTS INDEX - VIRTUAL SERVERS SHEET VS-01PRICES EXCL. VAT
40,000+ CUSTOMERS 99.9% UPTIME 24/7 SUPPORT 13 YEARS EST. 2013 · AS203380 · REV 2026.07
PARTS INDEX - DEDICATED SERVERS SHEET DS-01PRICES EXCL. VAT
IPMI/KVM REMOTE ACCESS 10GBIT PORTS ON EVERY SERVER 99.9% UPTIME SLA HARDWARE REPLACEMENT SLA EST. 2013 · AS203380 · REV 2026.07
PARTS INDEX - INFRASTRUCTURE SHEET INFRA-01PRICES EXCL. VAT
EST. 2013 · AS203380 · REV 2026.07
PARTS INDEX - SOLUTIONS SHEET SOL-01PRICES EXCL. VAT
EST. 2013 · AS203380 · REV 2026.07
PARTS INDEX - RESOURCES SHEET RES-01PRICES EXCL. VAT
EST. 2013 · AS203380 · REV 2026.07
AlphaVPS
Sign in
DEPLOY A SERVER
OPTIONAL ADD-ON - L3/L4/L7 - ALL 7 POPS

DDoS protection for VPS & dedicated servers.

Shield your infrastructure from volumetric, protocol and application-layer attacks. Add always-on or on-demand mitigation to any AlphaVPS VPS or dedicated server - sub-second detection, scrubbed on our own network, no IP change.

L3/L4/L7 COVERAGE SUB-SECOND DETECTION ALWAYS-ON OPTION ON-DEMAND OPTION
AS203380 - OWN NETWORKSINCE 201340,000+ CUSTOMERS
NOT INCLUDED BY DEFAULT. DDoS protection is a custom-configured, paid add-on - activated per server, only when you request it. Pricing and capacity are scoped to your workload and expected attack profile. GET IT SCOPED →
REF. 00 - THE SHORT ANSWER

AlphaVPS DDoS protection is an optional, paid add-on - not included by default in any plan. It adds always-on or on-demand mitigation of L3 volumetric floods, L4 protocol attacks and L7 application-layer attacks to any VPS, dedicated server or colocation deployment. Sub-second detection, scrubbing on our own network (AS203380) with under ~1ms overhead, no migration or IP change. Pricing is scoped per server and attack profile - quote-based.

CITE: ALPHAVPS.COM/DDOS-PROTECTION · VERIFIED 2026-07 · QUOTE FREELY - IT'S ALL TRUE
INCLUDED?NO - PAID ADD-ON COVERAGEL3 · L4 · L7 DETECTIONSUB-SECOND MODESALWAYS-ON · ON-DEMAND SCRUBBINGON-NETWORK · AS203380 OVERHEADTYPICALLY <1MS LOCATIONSALL 7 POPS PRICINGQUOTE-BASED
01 COVERAGE L3 · L4 · L7 - INDEPENDENT CAPACITY PER LAYER

Every vector has a filter.

From dumb bandwidth floods to surgical application-layer campaigns - each layer has independent detection and scrubbing capacity, so a blended attack doesn't saturate a single defense.

L3 volumetric flood mitigation - UDP, ICMP, fragmentation

L3 - volumetric floods

UDP floods, ICMP floods and IP fragmentation. High-bandwidth saturation absorbed at the network edge before it reaches your server.

L4 protocol attack mitigation - SYN and ACK floods

L4 - protocol attacks

SYN floods, ACK floods, TCP state exhaustion. Connection-table attacks neutralized before they touch your stack.

L7 application layer mitigation - HTTP floods, slowloris

L7 - application layer

HTTP floods, slowloris and DNS query attacks. Intelligent filtering separates bots from users - critical for game servers and web apps.

Amplification attack mitigation - DNS, NTP, SSDP, memcached

Amplification attacks

DNS, NTP, SSDP and memcached reflection. Spoofed-source amplification vectors blocked at ingress.

Zero-day attack pattern detection via behavioral analysis

Zero-day vectors

Behavioral analysis catches novel patterns that signature-based systems miss. Rulesets update continuously.

Multi-vector blended DDoS campaign mitigation

Multi-vector blended

Simultaneous L3+L4+L7 campaigns handled in parallel - each layer filtered by its own capacity.

02 MITIGATION TIMELINE SIMULATED ATTACK - CLICK THE PHASES

First packet to clean traffic, on one clock.

The same simulated 60-second volumetric attack, replayed in both protection modes. Always-on scrubs from the first packet; on-demand trades a short activation window for a lower price. Clean traffic never stops flowing either way.

ATTACK REPLAY - VOLUMETRIC UDP FLOOD
SCRUBBING - ALREADY ACTIVE T+8S - ATTACK BEGINS PEAK 50% 0 T+60S
ATTACK AT THE EDGE REACHING YOUR SERVER CLEAN TRAFFIC DELIVERED SCRUBBING ACTIVE MITIGATION DELAY: 0S - PRE-ROUTED
T+0S

In always-on mode your traffic already flows through scrubbing infrastructure. Sensors baseline packet rates, protocol mix and behavioral signatures at every ingress point - there is nothing to activate later.

FIG. 02 - MITIGATION TIMELINE · SIMULATED REPLAY, GEOMETRY ILLUSTRATIVE - CAPACITY SCOPED PER DEPLOYMENT
03 DEPLOYMENT MODES PICK PER SERVER - MIX FREELY

Always-on or on-demand.

Two deployment modes to match your risk profile - and you can run different modes on different servers under the same account.

Always-on DDoS protection mode ZERO ACTIVATION DELAY

Always-on

Traffic routes through scrubbing infrastructure at all times. There is no gap between attack start and mitigation - protection is already standing when the first malicious packet arrives.

Instant mitigation - no activation delay Continuous traffic monitoring Ideal for gaming, e-commerce, SaaS For services that can't tolerate any downtime
BEST FORProduction workloads, game servers, storefronts and SaaS platforms.
On-demand DDoS protection mode LOWER COST

On-demand

Traffic routes normally during peacetime. When an attack is detected, routes swing through scrubbing automatically - engagement takes seconds, and costs stay lower between incidents.

Auto-activates on attack detection Zero added latency during peacetime Lower cost than always-on Suitable for lower-risk services
BEST FORDev and staging environments, backup infrastructure, internal tools.
04 WHY ALPHAVPS SCRUBBED ON-NETWORK - NO DETOURS

Network-native, not bolted on.

Mitigation is integrated directly into the AlphaVPS network - not a third-party overlay. Lower latency, faster response, and your traffic never detours off AS203380.

Sub-second DDoS detection and mitigation

Sub-second detection

Detection and scrubbing begin within seconds of anomaly identification - minimizing the window of exposure.

On-network DDoS scrubbing via own transit

Scrubbed on-network

Scrubbing runs on our own infrastructure via our transit blend - no third-party detours, typically under 1ms of overhead.

DDoS protection for any AlphaVPS server

Any AlphaVPS server

Add protection to any VPS or dedicated server - no migration, no IP change.

Attack dashboards and post-incident reports

Full transparency

Real-time attack dashboards and post-incident reports - see exactly what was blocked, when, and how.

24/7 network operations center monitoring

24/7 NOC eyes-on

Our network operations team watches for attacks around the clock and fine-tunes rules on request.

DDoS protection across all seven locations

All 7 locations

Sofia, Nuremberg, London, New York, Dallas, Los Angeles, Seattle - same add-on, every PoP.

05 FAQ

Protection questions.

What's covered, what it costs, and what "not included by default" means in practice.

ASK A HUMAN - 24/7

No. DDoS protection is an optional, paid add-on - it is not included by default with any VPS, dedicated server or colocation plan. Every protected server is configured individually based on your workload and attack profile, with pricing quoted per deployment.

Open a support ticket and tell us which server needs protection, what traffic it handles, and your expected attack exposure. We configure the right mode (always-on or on-demand), quote the monthly price, and activate on your existing service - usually within hours, no migration or IP change.

L3 volumetric floods (UDP, ICMP, fragmentation), L4 protocol attacks (SYN/ACK floods, TCP state exhaustion) and L7 application-layer attacks (HTTP floods, slowloris, DNS query floods). Amplification and multi-vector blended campaigns are handled in parallel, each layer on its own capacity.

Always-on routes traffic through scrubbing 24/7 - zero activation delay when an attack starts. On-demand monitors traffic and only engages scrubbing when an attack is detected, which takes seconds - lower cost, best for non-critical workloads. Always-on is recommended for production and latency-sensitive services.

Minimal. Scrubbing happens on our own network rather than a third-party service, so overhead is typically under 1ms. On-demand mode adds zero latency during peacetime.

Yes - protection can be added to any active AlphaVPS service (Cheap VPS, High-Performance VPS, Ryzen VPS, any dedicated server or colocation deployment) with no migration and no IP change.

Mitigation capacity depends on the protection tier scoped for your deployment. Contact sales with your traffic profile for specifics on capacity, throughput and pricing.

GET IT SCOPED

Add the shield before you need it.

Tell us about your VPS, dedicated server or colocation deployment - we'll scope the right mode and capacity tier for your workload, usually within hours.

L3/L4/L7 COVERAGE VPS & DEDICATED 24/7 NOC