Comparison
Itnetic is a DDoS-Guard alternative for Layer-7 DDoS protection, WAF and CDN — operated from the Czech Republic, inside the EU, with published GDPR documentation and a free plan that includes every feature. Setup is two DNS records and no nameserver change.
DDoS-Guard and Itnetic occupy the same architectural slot: a reverse proxy in front of your origin that filters attack traffic before it reaches you, combined with a CDN and a web application firewall. If you are comparing them, the questions that usually decide it are where the service is operated from, what you can see in your own logs, and what you have to buy before you can turn a capability on.
DDoS-Guard has operated since 2011 and describes filtering nodes across several regions. Per public corporate records it is registered as Cognitive Cloud LP in Scotland and DDoS-Guard Corp in Belize, and the operating company is based in Russia. For a business inside the EU with a GDPR file to maintain, that is not a technical objection — it is a data-transfer and sub-processor question your DPO will ask, and one you should answer before signing rather than after.
Itnetic is operated from the Czech Republic by a named EU entity, with the Data Processing Addendum, sub-processor list, retention policy and incident response policy published in full. There is one product and every plan gets all of it: Layer-7 mitigation, managed and custom WAF rules, IP reputation, rate limiting, waiting room, per-request logs, origin load balancing, CDN and the public API — on the free plan as well as the €1,000 plan. Plans differ by domain count and delivered bandwidth, and attack traffic is never metered.
The table below compares capabilities only. It makes no claim about anyone's pricing, speed, capacity or network size — just what you can turn on, and on which plan.
Feature comparison
Availability by plan, from each vendor's public documentation. Capabilities only — no pricing or performance claims.
| Capability | Itnetic | DDoS-Guard |
|---|---|---|
| Layer-7 (application-layer) DDoS mitigation | Every plan, including free | Documented — plan-dependent |
| Volumetric L3/L4 absorption | Included — upstream backbone | Documented |
| Managed OWASP WAF filters | Every plan, including free | Documented — plan-dependent |
| Custom WAF rules (path, header, method, country, fingerprint) | Every plan, including free | Plan-dependent |
| IP allow / block lists | Every plan | Documented |
| IP reputation filtering | Every plan | Plan-dependent |
| Verified-bot allowlist | Every plan | Plan-dependent |
| CAPTCHA-free challenge for real visitors | Every plan — proof-of-work, no puzzles | Plan-dependent |
| Adaptive under-attack detection (automatic) | Every plan — trips at the edge in seconds | Plan-dependent |
| Rate limiting | Every plan | Plan-dependent |
| Waiting room / virtual queue | Every plan, including free | Not listed in the published feature set |
| Per-request logs (TLS, client fingerprint, WAF verdict) | Every plan | Plan-dependent |
| Traffic & attack analytics | 24-hour, 7-day and 30-day windows on every plan | Plan-dependent |
| Global CDN caching | Every plan | Documented |
| Automatic TLS certificates | Every plan | Documented |
| Bring-your-own PEM certificate | Every plan | Plan-dependent |
| Origin load balancing with failover | Every plan — up to 8 origins | Documented — plan-dependent |
| Private bucket origins (AWS SigV4 signing) | Every plan | Not listed in the published feature set |
| Real-time attack alerts | Every plan — Discord and email | Plan-dependent |
| Public REST API | Every plan, including free | Plan-dependent |
| Free plan (no card) | Yes — Starter, every feature included | Paid plans; trial availability plan-dependent |
| Self-serve signup without sales contact | Every plan | Plan-dependent |
| Onboarding | Two DNS records — your nameservers stay where they are | DNS-based onboarding |
| Operator and data controller | Czech Republic (EU) | Operating company based in Russia; registered as Cognitive Cloud LP (Scotland) and DDoS-Guard Corp (Belize) per public records |
| DPA, sub-processor list and retention policy published | Published in full | Check the vendor's current legal pages |
Compiled from DDoS-Guard's public service documentation and from publicly available corporate records on 6 August 2026, and describing feature availability at that date. Service contents change — check DDoS-Guard's current pages before making a decision. DDoS-Guard is a trademark of its respective owner; Itnetic Technologies is not affiliated with, endorsed by or sponsored by DDoS-Guard. This page makes no claim about any provider's pricing, performance, capacity or availability, and no allegation of wrongdoing by any party.
If your customers are in the EU, your processor choice is not only a technical decision. You need a Data Processing Addendum, a current sub-processor list, a documented retention period for every category of personal data you hand over, a route for erasure requests, and a defensible answer about where the data physically goes. Itnetic publishes all of that in full rather than on request, and it is operated by a named Czech entity you can email directly.
Volumetric floods are the easy half of the problem — they are loud, and the backbone absorbs them. The attacks that actually take sites down look like visitors: slow-drip request floods, credential stuffing, fake checkouts, scrapers rotating through residential addresses. Itnetic profiles every request by path, header shape and TLS fingerprint, and flips a host into challenge mode within a second of a spike, at the edge, without waiting for a control-plane round trip.
A protection service that only shows you aggregate graphs asks you to take its word for what it blocked. Itnetic keeps unsampled per-request logs on every plan, each entry carrying the TLS fingerprint, the client signature, the cookie echo class, the WAF verdict, the cache result, the serving origin and the origin timing. That is what lets you prove a cutover happened, find a bypass path hitting your origin directly, and tell a scraper apart from a customer instead of guessing.
Signup is self-serve. The Starter plan is free, takes no card, and is not a feature-stripped demo — it is the same edge, the same pipeline and the same protections as the paid plans, including the waiting room, the WAF, the API and the logs. That matters most when you are evaluating under pressure: you can be protected while you are still deciding.
Both services sit in front of your origin as a reverse proxy, so migration is a DNS change rather than a re-architecture. Add the domain, verify it, point two records — your nameservers and registrar stay where they are, which also means you can move one hostname across and leave the rest of the zone alone while you watch it behave. Most customers are fully protected within five minutes, and per-request logs let you confirm the cutover happened rather than assume it. Remember to firewall your origin to the edge afterwards, or the old direct path stays open.
FAQ
The deciding factor for most EU businesses is the data-protection file rather than the filtering itself: which entity processes the data, where it sits, and whether the DPA, sub-processor list and retention policy are published. Itnetic is operated from the Czech Republic by a named EU entity with all of those published in full, and includes Layer-7 mitigation, WAF, waiting room, per-request logs and CDN on every plan including the free one.
According to publicly available corporate records checked on 6 August 2026, the operating company is based in Russia, with registrations as Cognitive Cloud LP in Scotland and DDoS-Guard Corp in Belize, and it describes filtering nodes across several regions. Corporate structures change — verify against current records and the vendor's own legal pages before deciding. For an EU controller this is a sub-processor and data-transfer question to resolve with your DPO.
Yes. The Itnetic Starter plan is free, needs no card, and includes one domain with 2 GB of delivered traffic per month — with the same Layer-7 DDoS mitigation, WAF, waiting room, per-request logs, API and CDN as every paid plan. Attack traffic is not counted against that quota.
Yes. Both are reverse proxies in front of your origin, so the change is at DNS level. Add and verify the domain on Itnetic first, confirm the edge is serving it correctly on a test hostname, then move the production record. Because you keep your own nameservers you can migrate one hostname at a time rather than the whole zone.
No. Setup is two DNS records at whatever DNS provider you use today.
Itnetic protects HTTP and HTTPS applications, including APIs and WebSocket traffic. API paths can be marked so they are defended with per-client rate limits and behavioral signatures instead of browser challenges, answering with 429 or 403 rather than an HTML interstitial. It does not sell protected hosting, protected VDS or bare-metal servers — if you need a protected game server on a raw UDP protocol, that is a different category of product.
No. Scrubbed attack traffic is never metered, on any plan. Only legitimate, delivered traffic counts toward your quota.
Detection runs on the edge node serving the request, so a host flips into challenge mode within roughly a second of a spike rather than after a round trip to a central controller. The first node to see an attack also pushes it to the rest of the fleet, so a bot bounced at one point of presence does not simply re-resolve to another one that has not noticed yet.
Same method, different provider — feature availability by plan, with the date it was checked.
Two DNS records, no nameserver change, free plan with no card.