Security

TLS 1.3, origin shielding, L3–L7 DDoS mitigation, token authentication and DDoS-protected Anycast DNS on the same edge.

Controls in the request path

TLS, origin protection, DDoS mitigation and Anycast DNS as implemented in Cloud CDN and Cloud DNS. Due diligence is handled with the customer.

TLS 1.3 delivery

Serve traffic over HTTPS with TLS 1.3 and 0-RTT, managed or custom certificates, SNI and TLS version control on each Cloud CDN distribution.

Reduced origin exposure

Place Cloud CDN between public users and origin infrastructure. Origin Shield, origin groups and TLS origin validation keep the origin off the public path.

L3–L7 DDoS mitigation

Multi-layer protection against volumetric and application attacks sits in the delivery path, alongside access policies and secure token authentication.

DNS resilience

Authoritative Anycast DNS on 210+ servers stays reachable during large traffic events, with health checks, DNSSEC and IPv6 support.

Access control

Token authentication, access control lists, CORS headers and forced HTTPS redirects control who can reach content at the edge.

Operational isolation

Projects, product-specific configuration and API credentials keep CDN and DNS changes on separate operational surfaces.

Before the application

Cloud DNS controls resolution on a DDoS-protected Anycast network. Cloud CDN terminates TLS at the edge, applies access policy, serves cacheable content and limits how often users need to reach the origin. Each layer has a different responsibility.

  1. 01

    Resolve

    Authoritative DNS answers through 210+ DDoS-protected Anycast servers.

  2. 02

    Route

    GeoDNS, weighted policy and health checks determine eligible application endpoints.

  3. 03

    Deliver

    Cloud CDN serves TLS 1.3 traffic, applies access controls and returns eligible cached content.

  4. 04

    Protect origin capacity

    Caching, Origin Shield, serve-stale and L3–L7 DDoS mitigation protect origin capacity.

Close-up of a keyboard lock key, representing encryption and access control

Operational security

Keep infrastructure changes intentional.

The Management Console organizes customer resources around projects and product-specific configuration. API access can be controlled through project credentials, while CDN and DNS settings remain separate operational surfaces.

Discuss your security requirements

Security due diligence

Get the information your review requires.

Security reviews depend on the workload, architecture and commercial requirements. Aptranet can provide current information relevant to your technical and commercial evaluation.

Contact Aptranet

Design security into your edge architecture.

Get started with our Management Console in less than 2 minutes, or connect with an expert to supercharge your business today.