L7 behavioral protection
Request behavior is scored per proxy, and abusive sources are banned with timed durations before they reach your origin.
Everything Pixel Shield runs between the public internet and your game servers.
Request behavior is scored per proxy, and abusive sources are banned with timed durations before they reach your origin.
Per-IP packet and connection rates enforced in kernel space on every node, tuned per proxy within validated bounds.
Every node reports heartbeat, capacity and version to the control plane. Credentials stay AES-256-GCM encrypted at rest.
Bytes in, bytes out and request counters roll up daily per proxy, so plan limits are measured, not guessed.
Dedicated listen ports on edge nodes forward clean TCP and UDP traffic to your game server, with weighted, health-checked backends behind each one.
Global and per-proxy blocklists and whitelists for CIDR entries, with temporary rules that expire on schedule.
A proxy is a dedicated listen port (or SNI hostname) on an edge node. Clean traffic is forwarded to your backends; attack traffic never makes the trip.
Rate policy executes in kernel space on the node itself, so floods are dropped before user space ever sees them. Every field is validated against declared bounds.
The L7 engine scores request behavior per proxy and bans abusive sources for a timed duration, with a live event feed behind every decision.
Each node runs the RouteX agent and reports to the control plane. Key material is stored encrypted and never returned to clients unmasked.
Traffic counters roll up daily per proxy, powering quota enforcement and the usage charts in the console.
Blocklists and whitelists apply globally or per proxy. Temporary entries expire on schedule, enforced by a background worker.