DDoS mitigation is increasingly delivered as part of a broader infrastructure product.
Hosting providers include protection with compute and network services. Game hosting platforms treat mitigation as a core feature. Independent mitigation providers operate their own detection systems, filtering policies, customer portals, and response processes.
In many cases, the limiting factor is not the mitigation software itself. It is the underlying network: sufficient capacity, resilient transit, presence in the right locations, and the ability to absorb attacks that exceed the capacity of an individual provider's edge.
That is the layer Wirescope is designed to provide.
With the launch of v1, we are introducing wholesale pricing for hosting providers, mitigation companies, network operators, and infrastructure platforms that want to integrate Wirescope into their own services. Launch pricing is materially below the rates we expect to offer once the network reaches a more mature stage and is available to a limited number of early partners.
The objective is straightforward: place meaningful production traffic on the network, validate the platform under real operating conditions, and build the next stage of Wirescope alongside the companies using it.
Who this is for
Hosting providers
For hosting companies operating their own ASN and address space, mitigation should not require a separate integration for every customer.
Prefixes can be announced to Wirescope and protected at the network layer, allowing the workloads behind them to inherit DDoS mitigation without per-server agents, DNS changes, or customer-side configuration.
This makes protection practical to include as part of a standard hosting product rather than treating it as a separate security service.
Game hosting platforms
Game networks have different requirements from conventional web infrastructure. Maintaining availability is not enough if mitigation introduces excessive latency, jitter, packet loss, or aggressive rate limiting.
Wirescope is intended to provide protected IP addresses and prefixes that remain usable during attacks while allowing filtering policy to be adapted to the traffic characteristics of the protected workload.
DDoS mitigation providers
Wirescope is also designed to operate beneath existing mitigation platforms.
Providers that already maintain their own detection, policy, customer management, and filtering systems may use Wirescope for protected transit, additional regional capacity, or overflow handling when an event exceeds the capacity of their own edge.
We do not require partners to replace the systems they have already built. In many deployments, our role is simply to provide additional network capacity beneath them.
Networks and connectivity integrators
Operators reselling IP transit or managed connectivity can use Wirescope to offer transit with integrated DDoS mitigation rather than sourcing transit and protection as separate services.
What partners are reselling
Wholesale customers receive access to the same underlying infrastructure described in Introducing Wirescope.
Traffic is filtered inline at the point where it enters the Wirescope network, with full BGP control and core locations in Ashburn, Frankfurt, and Amsterdam. The v1 edge is built around multiple 400GbE upstream interfaces and is designed to absorb and classify attacks exceeding 1 Tbps within the Wirescope network.
From a commercial perspective, several principles are central to the service.
Attack traffic is not billable
Traffic identified as part of a DDoS attack is excluded from bandwidth billing.
Partners therefore do not need to account for the possibility that a large attack will directly increase their transit invoice. Protection can be incorporated into a hosting or connectivity product using predictable commercial assumptions rather than attack frequency or attack size.
Wirescope remains an infrastructure provider
Our role is to provide the network layer beneath our partners.
We do not sell hosting services to a hosting provider's customers, and we do not approach the end customers of mitigation partners. Services can be delivered entirely under the partner's own brand, and white-label operation is the default rather than a separate product tier.
Standard network operations remain standard
Partners can bring their own address space, establish BGP sessions, announce or withdraw prefixes, and adjust routing policy without turning routine network changes into commercial events.
We do not charge per-prefix fees or treat normal routing controls as optional add-ons.
The hyperscale backstop does not reach your contract
A fair question from anyone who has used a mitigation provider sitting on top of a hyperscaler: does the Cloudflare layer mean per-prefix charges, minimum prefix sizes beyond what the global routing table already imposes, forced DNS changes, or restrictions on how you run BGP?
No. That relationship is ours, and it stops at our edge.
You announce prefixes to Wirescope over ordinary BGP, add and withdraw them as routine operations, keep your own address space and ASN, and set your own routing policy. When an event escalates to the backstop, the routing work happens on our side. Your session, your announcements, your policy, and your invoice are unchanged, and attack traffic remains excluded from billing throughout.
v1 launch pricing
Wholesale pricing is structured around the deployment rather than a single published rate.
The appropriate commercial model depends on factors including committed bandwidth, interface requirements, locations, and whether the service is being used for protected transit, mitigation-only connectivity, or overflow capacity behind an existing mitigation edge.
For that reason, we quote wholesale deployments individually.
However, several terms apply to all v1 launch agreements:
- Rates agreed during v1 remain fixed for the initial contract term.
- Attack traffic remains excluded from billing at every volume tier.
- There is no per-prefix pricing penalty.
- Standard BGP and routing controls are included with the service.
- We will not accept a deployment we do not believe the current network can support properly.
Launch pricing is available only during the v1 period. Partners that join during this stage retain the commercial terms agreed at launch even as standard pricing changes.
Founding partner programme
We are allocating a limited number of founding partner positions during v1 because we intend to work closely with our initial wholesale customers.
These early deployments will have a disproportionate influence on how Wirescope develops. We want enough engineering capacity to understand each partner's architecture, traffic profile, operational requirements, and customer expectations rather than treating onboarding as a purely transactional process.
For founding partners, that means working directly with our network and engineering teams throughout deployment and into production. We expect to collaborate on routing design, filtering policy, capacity planning, incident behaviour, and the operational tooling required to make Wirescope fit naturally into the partner's existing platform.
The number of founding seats is therefore deliberately limited. Each partner represents not only committed network capacity, but also engineering time and an ongoing technical relationship. We would rather work closely with a smaller group of initial customers, learn from their production traffic, and build the next version of the platform around those deployments than onboard a larger number of partners with less involvement.
Founding partners receive several additional commitments.
Launch pricing retained
The rate agreed during v1 is maintained throughout the initial term and honoured at renewal, subject to the terms of the agreement.
Future changes to standard Wirescope pricing do not automatically change a founding partner's rate.
Reserved capacity
Committed capacity is incorporated into network planning rather than treated purely as statistical oversubscription.
This includes maintaining sufficient operational headroom for traffic shifts and rerouting during attacks or network events.
Direct engineering access
Founding partners receive a direct communication channel with the engineers responsible for routing, filtering, and the dataplane.
Operational issues can therefore be discussed with the people who operate the relevant systems rather than being routed exclusively through a conventional tiered support process.
Input into the v2 roadmap
Partner demand will directly influence where Wirescope expands next.
This includes future PoP locations, regional capacity additions, integrations, and network features. Where a partner has significant customer concentration in a market we do not yet serve directly, that information becomes part of the decision process for future deployment.
Early access
Founding partners receive early access to new locations, additional capacity, integrations, and other platform capabilities as they are introduced.
This includes planned v2 carrier additions.
Outcome-based service commitments
For deployments requiring contractual service assurances, we can define performance commitments around measurable outcomes such as service availability and attack leakage at an agreed observation point.
This is generally more useful than expressing mitigation capability only as an aggregate network capacity figure.
White-label operation
Wholesale services are white-label by default.
Partners can expose Wirescope branding where it is commercially useful, including through joint marketing, but there is no requirement to do so.
The founding partner programme is intended for organizations planning to place real production traffic on the network and participate actively in the technical feedback process.
What we ask from early partners
The principal value of the v1 programme is operational feedback from real deployments.
A mitigation network improves by encountering actual customer workloads, attack patterns, routing conditions, congestion events, and failure modes. Production traffic provides information that cannot be replicated completely in a lab or through synthetic load testing.
In return for launch pricing and additional access, we ask partners to provide direct technical feedback when the network does not behave as expected.
We also encourage prospective wholesale partners to trial the platform before making a larger commitment.
A useful evaluation should place a representative workload behind the network, establish an agreed measurement point, and examine the traffic reaching the origin while mitigation is active. Providers intending to resell a mitigation service should validate its behaviour at least as carefully as the customers who will ultimately depend on it.
Onboarding
For most partners, integration is primarily a network operation rather than a product migration.
Depending on the deployment, connectivity may include:
- protected IP addresses for individual systems;
- GRE, IPsec, or QUIC tunnels where direct interconnection is impractical;
- BGP sessions using partner-owned address space;
- direct cross-connects or transport into a Wirescope location; and
- custom routing and filtering policies for specific workloads.
Inbound traffic can be filtered through Wirescope without requiring return traffic to follow the same path, and the service does not require an application-layer proxy in front of the protected workload.
For partners pursuing deeper technical integration, we can provide additional information under NDA regarding dataplane architecture, automation, available capacity, operational interfaces, and the division of responsibility between Wirescope and the partner's own systems.
Routing and interconnection information is also available through our peering documentation.
Current network scope
The v1 network is intentionally focused.
Wirescope currently operates three core locations: Ashburn, Frankfurt, and Amsterdam. Additional carriers, including Arelion and NTT, are planned as part of v2, alongside further geographic expansion.
We do not present three locations as equivalent to a mature global network.
Where partner demand exists outside the current footprint, however, there are intermediate options. Transport can often be extended into another facility before the economics justify deploying a complete Wirescope PoP there.
Understanding where wholesale customers actually need capacity is also one of the primary inputs into our expansion planning.
We will build for partners
To be direct about it: we are willing to build a location because a partner needs one.
A wholesale partner with real traffic in a market is a considerably better reason to deploy than an internal guess about where the network should go next, and partner demand is weighted accordingly. If your customers are concentrated in a city on our roadmap, that is an argument for moving it forward. If they are concentrated somewhere that is not on it, that is an argument for adding it.
There is a range of options between doing nothing and standing up a full PoP, and the right one depends on the volume involved:
- extending transport into a facility so traffic lands locally without a Wirescope PoP there;
- a partial deployment carrying protected capacity in the market;
- a full core PoP with local transit and inline filtering; and
- deploying into a partner's own facility where that is the sensible location.
What we will not do is promise a location we cannot justify, or take a commitment for capacity we are not confident of delivering on the timeline discussed. If a market is not viable yet, we will say so and propose the closest arrangement that is.
Working with Wirescope
If you operate a hosting platform, mitigation service, network, or infrastructure product and need protected capacity underneath it, the v1 wholesale programme is intended for that use case.
We can evaluate the required locations, connectivity model, committed capacity, routing design, and mitigation requirements and determine whether the current network is a suitable fit. Talk to us.
Partners joining during v1 receive launch commercial terms and access to the founding partner programme while capacity remains available.
If you are currently experiencing an attack, use our Under Attack process for immediate assistance.