Comparison

The EU-operated DDoS-Guard alternative, with a free plan

Itnetic is a DDoS-Guard alternative for Layer-7 DDoS protection, WAF and CDN — operated from the Czech Republic, inside the EU, with published GDPR documentation and a free plan that includes every feature. Setup is two DNS records and no nameserver change.

DDoS-Guard and Itnetic occupy the same architectural slot: a reverse proxy in front of your origin that filters attack traffic before it reaches you, combined with a CDN and a web application firewall. If you are comparing them, the questions that usually decide it are where the service is operated from, what you can see in your own logs, and what you have to buy before you can turn a capability on.

DDoS-Guard has operated since 2011 and describes filtering nodes across several regions. Per public corporate records it is registered as Cognitive Cloud LP in Scotland and DDoS-Guard Corp in Belize, and the operating company is based in Russia. For a business inside the EU with a GDPR file to maintain, that is not a technical objection — it is a data-transfer and sub-processor question your DPO will ask, and one you should answer before signing rather than after.

Itnetic is operated from the Czech Republic by a named EU entity, with the Data Processing Addendum, sub-processor list, retention policy and incident response policy published in full. There is one product and every plan gets all of it: Layer-7 mitigation, managed and custom WAF rules, IP reputation, rate limiting, waiting room, per-request logs, origin load balancing, CDN and the public API — on the free plan as well as the €1,000 plan. Plans differ by domain count and delivered bandwidth, and attack traffic is never metered.

The table below compares capabilities only. It makes no claim about anyone's pricing, speed, capacity or network size — just what you can turn on, and on which plan.

Feature comparison

Itnetic vs DDoS-Guard: what each plan includes

Availability by plan, from each vendor's public documentation. Capabilities only — no pricing or performance claims.

CapabilityItneticDDoS-Guard
Layer-7 (application-layer) DDoS mitigationEvery plan, including freeDocumented — plan-dependent
Volumetric L3/L4 absorptionIncluded — upstream backboneDocumented
Managed OWASP WAF filtersEvery plan, including freeDocumented — plan-dependent
Custom WAF rules (path, header, method, country, fingerprint)Every plan, including freePlan-dependent
IP allow / block listsEvery planDocumented
IP reputation filteringEvery planPlan-dependent
Verified-bot allowlistEvery planPlan-dependent
CAPTCHA-free challenge for real visitorsEvery plan — proof-of-work, no puzzlesPlan-dependent
Adaptive under-attack detection (automatic)Every plan — trips at the edge in secondsPlan-dependent
Rate limitingEvery planPlan-dependent
Waiting room / virtual queueEvery plan, including freeNot listed in the published feature set
Per-request logs (TLS, client fingerprint, WAF verdict)Every planPlan-dependent
Traffic & attack analytics24-hour, 7-day and 30-day windows on every planPlan-dependent
Global CDN cachingEvery planDocumented
Automatic TLS certificatesEvery planDocumented
Bring-your-own PEM certificateEvery planPlan-dependent
Origin load balancing with failoverEvery plan — up to 8 originsDocumented — plan-dependent
Private bucket origins (AWS SigV4 signing)Every planNot listed in the published feature set
Real-time attack alertsEvery plan — Discord and emailPlan-dependent
Public REST APIEvery plan, including freePlan-dependent
Free plan (no card)Yes — Starter, every feature includedPaid plans; trial availability plan-dependent
Self-serve signup without sales contactEvery planPlan-dependent
OnboardingTwo DNS records — your nameservers stay where they areDNS-based onboarding
Operator and data controllerCzech Republic (EU)Operating company based in Russia; registered as Cognitive Cloud LP (Scotland) and DDoS-Guard Corp (Belize) per public records
DPA, sub-processor list and retention policy publishedPublished in fullCheck the vendor's current legal pages

About this comparison

Compiled from DDoS-Guard's public service documentation and from publicly available corporate records on 6 August 2026, and describing feature availability at that date. Service contents change — check DDoS-Guard's current pages before making a decision. DDoS-Guard is a trademark of its respective owner; Itnetic Technologies is not affiliated with, endorsed by or sponsored by DDoS-Guard. This page makes no claim about any provider's pricing, performance, capacity or availability, and no allegation of wrongdoing by any party.

An EU operator, and a GDPR file you can actually assemble

If your customers are in the EU, your processor choice is not only a technical decision. You need a Data Processing Addendum, a current sub-processor list, a documented retention period for every category of personal data you hand over, a route for erasure requests, and a defensible answer about where the data physically goes. Itnetic publishes all of that in full rather than on request, and it is operated by a named Czech entity you can email directly.

  • Operator: Petr Chlíbek, IČO 21210756, Czech Republic.
  • Every retention period in the policy is enforced by a database TTL index, not a clean-up job that can silently stop running.
  • DPA, sub-processors, retention and incident-response policies published in full.
  • Erasure requests delete every record keyed to your account, across every collection.

Layer-7 mitigation that reads the shape of an attack

Volumetric floods are the easy half of the problem — they are loud, and the backbone absorbs them. The attacks that actually take sites down look like visitors: slow-drip request floods, credential stuffing, fake checkouts, scrapers rotating through residential addresses. Itnetic profiles every request by path, header shape and TLS fingerprint, and flips a host into challenge mode within a second of a spike, at the edge, without waiting for a control-plane round trip.

  • Behavioral signatures match the shape of an attack, not just its volume.
  • Repeat offenders are dropped in the kernel, so they cost nothing per request.
  • Real visitors solve an invisible proof-of-work — never a CAPTCHA, never an image grid.
  • An anomaly layer learns each host's own baseline, so a large site is never punished for being large.

Per-request logs, so you can audit the mitigation yourself

A protection service that only shows you aggregate graphs asks you to take its word for what it blocked. Itnetic keeps unsampled per-request logs on every plan, each entry carrying the TLS fingerprint, the client signature, the cookie echo class, the WAF verdict, the cache result, the serving origin and the origin timing. That is what lets you prove a cutover happened, find a bypass path hitting your origin directly, and tell a scraper apart from a customer instead of guessing.

A free plan, and no sales call to start

Signup is self-serve. The Starter plan is free, takes no card, and is not a feature-stripped demo — it is the same edge, the same pipeline and the same protections as the paid plans, including the waiting room, the WAF, the API and the logs. That matters most when you are evaluating under pressure: you can be protected while you are still deciding.

Switching from DDoS-Guard

Both services sit in front of your origin as a reverse proxy, so migration is a DNS change rather than a re-architecture. Add the domain, verify it, point two records — your nameservers and registrar stay where they are, which also means you can move one hostname across and leave the rest of the zone alone while you watch it behave. Most customers are fully protected within five minutes, and per-request logs let you confirm the cutover happened rather than assume it. Remember to firewall your origin to the edge afterwards, or the old direct path stays open.

FAQ

DDoS-Guard alternatives: common questions

What is the best DDoS-Guard alternative for an EU company?

The deciding factor for most EU businesses is the data-protection file rather than the filtering itself: which entity processes the data, where it sits, and whether the DPA, sub-processor list and retention policy are published. Itnetic is operated from the Czech Republic by a named EU entity with all of those published in full, and includes Layer-7 mitigation, WAF, waiting room, per-request logs and CDN on every plan including the free one.

Where is DDoS-Guard based?

According to publicly available corporate records checked on 6 August 2026, the operating company is based in Russia, with registrations as Cognitive Cloud LP in Scotland and DDoS-Guard Corp in Belize, and it describes filtering nodes across several regions. Corporate structures change — verify against current records and the vendor's own legal pages before deciding. For an EU controller this is a sub-processor and data-transfer question to resolve with your DPO.

Is there a free DDoS-Guard alternative?

Yes. The Itnetic Starter plan is free, needs no card, and includes one domain with 2 GB of delivered traffic per month — with the same Layer-7 DDoS mitigation, WAF, waiting room, per-request logs, API and CDN as every paid plan. Attack traffic is not counted against that quota.

Can I migrate from DDoS-Guard without downtime?

Yes. Both are reverse proxies in front of your origin, so the change is at DNS level. Add and verify the domain on Itnetic first, confirm the edge is serving it correctly on a test hostname, then move the production record. Because you keep your own nameservers you can migrate one hostname at a time rather than the whole zone.

Do I have to change my nameservers to use Itnetic?

No. Setup is two DNS records at whatever DNS provider you use today.

Does Itnetic protect APIs and game backends as well as websites?

Itnetic protects HTTP and HTTPS applications, including APIs and WebSocket traffic. API paths can be marked so they are defended with per-client rate limits and behavioral signatures instead of browser challenges, answering with 429 or 403 rather than an HTML interstitial. It does not sell protected hosting, protected VDS or bare-metal servers — if you need a protected game server on a raw UDP protocol, that is a different category of product.

Is attack traffic billed against my bandwidth?

No. Scrubbed attack traffic is never metered, on any plan. Only legitimate, delivered traffic counts toward your quota.

How fast does mitigation engage?

Detection runs on the edge node serving the request, so a host flips into challenge mode within roughly a second of a spike rather than after a round trip to a central controller. The first node to see an attack also pushes it to the rest of the fleet, so a bot bounced at one point of presence does not simply re-resolve to another one that has not noticed yet.

Other comparisons

Same method, different provider — feature availability by plan, with the date it was checked.

Try it on one domain.

Two DNS records, no nameserver change, free plan with no card.