Controls in the request path
Application policies, TLS, origin protection, DDoS mitigation and Anycast DNS, with a clear role for each product.
Cloud Shield application protection
Protect websites and APIs with managed policies, custom and IP firewall rules, security analytics and optional bot and API security add-ons.
TLS 1.3 delivery
Serve traffic over HTTPS with TLS 1.3 and 0-RTT, managed or custom certificates, SNI and TLS version control on each Cloud CDN distribution.
Reduced origin exposure
Place Cloud CDN between public users and origin infrastructure. Origin Shield, origin groups and TLS origin validation keep the origin off the public path.
L3–L7 DDoS mitigation
Multi-layer protection against volumetric and application attacks sits in the delivery path, alongside access policies and secure token authentication.
DNS resilience
Authoritative Anycast DNS on 210+ servers stays reachable during large traffic events, with health checks, DNSSEC and IPv6 support.
Access control
Token authentication, access control lists, CORS headers and forced HTTPS redirects control who can reach content at the edge.
Operational isolation
Projects, product-specific configuration and API credentials keep CDN and DNS changes on separate operational surfaces.
Before the application
Cloud DNS controls resolution on a DDoS-protected Anycast network. Cloud CDN terminates TLS at the edge, applies access policy, serves cacheable content and limits how often users need to reach the origin. Each layer has a different responsibility.
- 01
Resolve
Authoritative DNS answers through 210+ DDoS-protected Anycast servers.
- 02
Route
GeoDNS, weighted policy and health checks determine eligible application endpoints.
- 03
Deliver
Cloud CDN serves TLS 1.3 traffic, applies access controls and returns eligible cached content.
- 04
Inspect application traffic
Cloud Shield evaluates requests using the managed policies and security rules configured for your CDN distribution.
Explore application protection - 05
Protect origin capacity
Caching, Origin Shield, serve-stale and L3–L7 DDoS mitigation protect origin capacity.
Operational security
Keep infrastructure changes intentional.
The Management Console organizes customer resources around projects and product-specific configuration. API access can be controlled through project credentials, while CDN and DNS settings remain separate operational surfaces.
Discuss your security requirementsSecurity due diligence
Get the information your review requires.
Security reviews depend on the workload, architecture and commercial requirements. Aptranet can provide current information relevant to your technical and commercial evaluation.
Contact Aptranet