Our edge network
Servers in places we picked for maximum performance, announcing our own routes. One anycast address sends every visitor to their nearest PoP, a cache hit is answered from local flash in about 15 milliseconds — and everything we store about it stays in the European Union.
9
Edge locations, live right now
7
Countries
~15 ms
Cache hit, at the edge
1 IP
Anycast — the network picks the PoP
The location count is read from our live edge registry, not a marketing figure. We would rather show you a real number than a round one.
Strategically positioned across the globe
Our edge locations are placed in major internet exchange points for optimal routing and minimal latency.
Denmark
Germany
United States
ZA
United States
Brazil
United States
Singapore
Australia
Edge locations
Strategically placed PoPs keep your content milliseconds from your visitors.
Nordic
Copenhagen
Denmark
Western Europe
Falkenstein
Germany
Americas
Fremont
United States
New York
United States
Sao Paulo
Brazil
Seattle
United States
Asia Pacific
Singapore
Singapore
Sydney
Australia
Africa & Middle East
Johannesburg
ZA
One address, answered by whichever PoP is closest
Your zone resolves to a single anycast IP address. That same address is announced from every edge location, so the internet's own routing delivers each visitor to the nearest one. There is no DNS trick deciding it, and nothing for you to configure per region.
Your hostname resolves to one anycast address
Answered by our own authoritative nameservers, which we operate rather than rent.
The internet routes to the nearest announcement
Every edge announces the same prefix over BGP. Each network along the way picks its shortest path, so "nearest" means nearest in network terms, not in kilometres on a map.
That edge answers from local NVMe
A cache hit never leaves the building. TLS terminates there too, so the handshake is local as well.
Only a miss goes to your origin
One request fetches, caches and serves. Every visitor after that is answered locally, in every region at once.
What every edge does before it answers
Each location is a full copy of the platform, not a dumb cache node. Security, optimisation and delivery all happen in the same place, in one pass, with no extra hop between them.
Threat blocklist
A network-wide list of addresses caught attacking any site on the platform is checked first, on every request. An attacker blocked at one customer is blocked at all of them, within 30 seconds.
Firewall rules
Your own IP, country and path rules, plus proof-of-work challenges for anything that looks automated.
Rate limiting and waiting room
Per-zone request limits, and if you have enabled it, the queue that protects your origin on a campaign day.
Cache lookup
Full-page HTML and static assets on local NVMe. This is where the overwhelming majority of requests stop and turn around.
Origin fetch, on a miss only
Over a keep-alive connection back to your server, with the response stored for everyone who asks next.
Transformation
Image resizing and WebP conversion, CSS and JavaScript minification, script injection, ESI fragments and translation — applied on the way out.
Compression and delivery
Brotli over HTTP/3 where the browser supports it, HTTP/2 and gzip where it does not.
Logging
The request is recorded for your analytics, and any security event is queued back to the control plane.
An edge that is unwell removes itself
Anycast makes failover simple, provided a sick node is honest about being sick. Ours are: each edge continuously checks its own health and withdraws its BGP announcement if it cannot serve properly. Traffic moves to the next-nearest PoP within seconds, and nobody files a ticket.
No single point of failure
Every edge is independent. Losing one moves its traffic to its neighbours — there is no central proxy that everything passes through.
by designSelf-withdrawing nodes
If an edge loses contact with the control plane or its web server stops answering, it stops announcing the anycast prefix instead of quietly black-holing requests.
automaticCautious return
A node that recovers waits for a sustained period of good health before announcing again, so a flapping link cannot repeatedly pull traffic into a broken PoP.
cooldownThere is a second benefit customers discover during their first hosting outage: cached pages keep being served from the edge while an origin is down. Anonymous visitors carry on browsing a site whose server is not currently answering anyone.
We do not grade our own homework
Every CDN's internal dashboard says the CDN is fast. That is not evidence, it is a screenshot from inside the building.
So we also measure from outside it, using RIPE Atlas — an independent, globally distributed network of measurement probes run by the regional internet registry, not by us. Probes around the world query our anycast address and trace the path, which tells us which PoP actually answered them and how long it took.
That catches the failure mode that internal monitoring never sees: routing that is working perfectly, but sending a visitor in one country to a PoP on another continent. Every edge looks healthy; the visitor is still slow. Only an outside measurement finds it.
European by default, global when you want it
A global network and European data residency are usually presented as a trade-off. They are not — they are just two different questions, about the delivery path and about where records are kept.
Always in the EU
- The control plane and its database
- Your account, configuration and billing records
- Traffic analytics and request-log storage
- Certificate issuance and private keys
- Our own transactional email infrastructure
Your call, per zone
- Global delivery. Every PoP serves your site, so a visitor in Sydney is answered in Sydney. The default, and the right answer for most sites.
- European edges only. Restrict the zone so requests are only ever served from PoPs inside Europe. Slower for distant visitors, and sometimes exactly what a compliance review requires.
We are a Danish company operating under European law, so this is our default position rather than a product tier. See the privacy policy for exactly what is stored and for how long.
Built on modern technology
No secret sauce, just well-chosen components we run ourselves. Here is what is actually in the path between your origin and your visitor.
The edge web server, with a Lua runtime for the firewall, waiting room and ESI logic that runs in-process rather than as a separate hop.
edgeWe announce our own prefixes from every PoP, so routing is something we can diagnose and fix rather than escalate to a supplier.
anycastNameservers we operate, not rent. Optional for customers — you are welcome to keep DNS wherever it is today.
ns1 · ns2Local flash on every node. A cache hit is a local disk read, which is why it lands around 15 ms.
localFewer round trips to establish a connection, which matters most on the mobile networks where sites feel slowest.
0-RTTBetter compression than gzip on text, applied on the way out with no build step on your side.
on by defaultThe image pipeline behind resizing and WebP conversion — fast and low-memory enough to run inline at the edge.
imagesRemote PoPs reach the control plane over encrypted tunnels, so configuration and logs never cross the public internet in the clear.
WireGuardQuestions, answered
Experience the speed difference
Put your site on the network and watch the first-byte time drop. 25 GB free every month, no card required.