For small businesses
Small sites get attacked by the same botnets as big ones — but the controls that stop them tend to live on plans a five-person company cannot justify. Itnetic puts all of them on every plan, starting at free, with no sales call and no annual contract.
The uncomfortable thing about running a small site is that attackers do not scale their effort to your size. A booking page for a dental practice and a checkout for a marketplace look identical to a botnet renting capacity by the hour. What differs is what happens next: the marketplace has someone on call, and you have a Tuesday.
That is the real reason feature gating hurts small businesses more than anyone. The moment you need a virtual queue, a managed ruleset or the log line explaining why a customer got blocked is exactly the moment you find out it is a plan or two above where you are, and you are being asked to make a purchasing decision while the site is down.
Itnetic exists on the other side of that trade. One product, every feature on every plan, and plans that differ only by how many domains you point at us and how much real traffic we deliver. Free is genuinely free — no card, no trial clock.
By what you actually need
Framed by requirement rather than product name. Availability by plan, from each vendor’s public documentation.
| What a small site needs | Itnetic | Cloudflare |
|---|---|---|
| Stay up during an application-layer flood | Every plan, including free | Every plan |
| Managed OWASP filters (SQLi, XSS, file inclusion) | Every plan, including free | Paid plans |
| Block a specific abusive path, country or IP yourself | Every plan — custom rules with typed fields | Plan-dependent limits |
| Hold a rush at the door instead of dropping it (waiting room) | Every plan, including free | Business and Enterprise |
| See exactly why a customer was blocked | Every plan — per-request log with the rule name | Raw log export on Enterprise (Logpush) |
| Know an attack started without watching a dashboard | Every plan — email and Discord alerts | Plan-dependent |
| Keep the site fast for visitors far from the server | Every plan — CDN caching | Every plan |
| Keep serving if the server dies | Every plan — up to 8 origins with failover | Paid add-on |
| HTTPS without touching a certificate | Every plan — automatic | Every plan |
| Free plan with no card | 1 domain, 2 GB delivered traffic / month, every feature | Free plan available |
| Cheapest paid step up | €5/month — 2 domains, 10 GB | Published on their pricing page |
| Buying process | Self-serve, monthly, cancel any time | Self-serve below Enterprise |
| Who you email with a problem | A named operator in the Czech Republic | Support tier depends on plan |
| Attack traffic billed against your quota | Never — mitigated bytes are excluded | Not metered |
Compiled from Cloudflare’s own public documentation and plan pages on 10 September 2026, and describing feature availability by plan at that date. Plan contents change — check Cloudflare’s current pages before making a decision. Cloudflare is a trademark of Cloudflare, Inc.; Itnetic Technologies is not affiliated with, endorsed by or sponsored by Cloudflare, Inc. Prices named on this page are Itnetic’s own; this page makes no claim about any other provider’s pricing, performance, capacity or availability.
The Starter plan costs nothing, needs no card, and does not expire. It carries one domain and 2 GB of delivered traffic a month — and the same Layer-7 mitigation, managed WAF, custom rules, waiting room, request logs, alerts, CDN and API as the €1,000 plan. If your site is a brochure, a booking page or a small shop, that is very often the whole answer, and the paid tiers only enter the picture when you outgrow the bandwidth.
Power you cannot use is not power. Custom WAF rules here are typed fields — pick the field (path, header, method, country, IP, client fingerprint), pick the operator, pick allow, block, challenge or log — instead of an expression language you have to learn before you can stop a bot at 11pm. Every rule can be set to log-only first, so you can watch what it would have caught before it catches a customer.
It is rarely a headline-grade volumetric flood. It is a scraper hammering your product pages until the database gives up, a credential-stuffing run against your login, a competitor’s cheap booter aimed at your checkout during a sale, or a spam wave hitting your contact form. All four are Layer-7 problems, all four look like traffic, and all four are handled by defences that are switched on from the first request rather than bought after the fact.
Two DNS records at whatever provider you already use — you do not hand over your nameservers, which also means your email records, your existing DNS setup and your registrar are untouched. If you have a web person, this is ten minutes of their time. If you do not, the dashboard shows the exact records to copy, and the domain goes green on its own once they resolve.
Itnetic is operated from the Czech Republic by a named individual, with a Data Processing Addendum, a published sub-processor list, a documented retention policy and an incident-response policy — all readable in full, in English and Czech, without asking a salesperson. For a small business inside the EU, that is usually the shortest path through a GDPR question from a client or an insurer.
FAQ
Yes. The Itnetic Starter plan is free, requires no card and includes one domain with 2 GB of delivered traffic a month — with the same Layer-7 DDoS mitigation, managed WAF, custom rules, waiting room, per-request logs, alerts and CDN as every paid plan. Attack traffic does not count against the quota.
It needs Layer-7 protection, which is a slightly different thing. Volumetric floods aimed at small sites are rare; scrapers, credential stuffing, spam waves and cheap booters aimed at a checkout are common, and they are what actually takes a small site offline. Those are stopped by request-level defences, not by bandwidth.
€5/month for 2 domains and 10 GB of delivered traffic, €29 for 5 domains and 50 GB, €99 for 10 domains and 1 TB. Every plan carries every feature — you are only ever paying for size.
No, because nothing about your DNS changes hands. You keep your provider and your registrar, and add two records: a TXT proof and one traffic record for the hostname you want protected. MX and everything else stay exactly as they are.
Yes, and those are the most common shape here. The endpoints attackers flood on WordPress — xmlrpc.php, wp-login.php, admin-ajax.php and unbounded search queries — are exactly what custom rules and rate limits are for, and edge caching absorbs read traffic that a security plugin running inside PHP never gets the chance to see.
No. Sign up, add a domain, pay monthly by card if you outgrow free, cancel whenever. The only conversation is if you want a custom plan beyond the published tiers.
You will not, from the attack. Mitigated traffic — challenge pages, blocked requests, rate-limit responses — is reported separately and subtracted before your quota is metered. A flood cannot bill you into an overage.
Same provider, different question — each page compares what matters to one specific use case.
Same method, different provider — feature availability by plan, with the date it was checked.
Two DNS records, no nameserver change, free plan with no card.