Security

Application protection with Cloud Shield, secure delivery with Cloud CDN and resilient routing with Cloud DNS. Connected controls for every layer of your application.

Controls in the request path

Application policies, TLS, origin protection, DDoS mitigation and Anycast DNS, with a clear role for each product.

Cloud Shield application protection

Protect websites and APIs with managed policies, custom and IP firewall rules, security analytics and optional bot and API security add-ons.

TLS 1.3 delivery

Serve traffic over HTTPS with TLS 1.3 and 0-RTT, managed or custom certificates, SNI and TLS version control on each Cloud CDN distribution.

Reduced origin exposure

Place Cloud CDN between public users and origin infrastructure. Origin Shield, origin groups and TLS origin validation keep the origin off the public path.

L3–L7 DDoS mitigation

Multi-layer protection against volumetric and application attacks sits in the delivery path, alongside access policies and secure token authentication.

DNS resilience

Authoritative Anycast DNS on 210+ servers stays reachable during large traffic events, with health checks, DNSSEC and IPv6 support.

Access control

Token authentication, access control lists, CORS headers and forced HTTPS redirects control who can reach content at the edge.

Operational isolation

Projects, product-specific configuration and API credentials keep CDN and DNS changes on separate operational surfaces.

Before the application

Cloud DNS controls resolution on a DDoS-protected Anycast network. Cloud CDN terminates TLS at the edge, applies access policy, serves cacheable content and limits how often users need to reach the origin. Each layer has a different responsibility.

  1. 01

    Resolve

    Authoritative DNS answers through 210+ DDoS-protected Anycast servers.

  2. 02

    Route

    GeoDNS, weighted policy and health checks determine eligible application endpoints.

  3. 03

    Deliver

    Cloud CDN serves TLS 1.3 traffic, applies access controls and returns eligible cached content.

  4. 04

    Inspect application traffic

    Cloud Shield evaluates requests using the managed policies and security rules configured for your CDN distribution.

    Explore application protection
  5. 05

    Protect origin capacity

    Caching, Origin Shield, serve-stale and L3–L7 DDoS mitigation protect origin capacity.

Operational security

Keep infrastructure changes intentional.

The Management Console organizes customer resources around projects and product-specific configuration. API access can be controlled through project credentials, while CDN and DNS settings remain separate operational surfaces.

Discuss your security requirements

Security due diligence

Get the information your review requires.

Security reviews depend on the workload, architecture and commercial requirements. Aptranet can provide current information relevant to your technical and commercial evaluation.

Contact Aptranet

Design security into your edge architecture.

Get started with our Management Console in less than 2 minutes, or connect with an expert to supercharge your business today.