Large ISPs and enterprise networks block attacks the same way: dropping malicious traffic upstream, before it ever reaches you, not after. Normally that takes a transit contract and a network engineering team. Shield brings that same real-time threat intelligence to a single router for $59/month.

14-day free trial • No card required • Live in minutes, no waiting on a human

Not just your own blocklist — a live feed of attacks other peers on the network have already seen, delivered automatically as BGP routes your router blocks in real time. Also available via API (2,000 req/day) if you want to pull it yourself.

GRE or WireGuard tunnel to a SATIS BGP PoP (Los Angeles, Dallas, or Buffalo), one session, one severity threshold you control.

A free private ASN (64512–65534) and a router that speaks BGP is enough. No transit diversity, no LOA paperwork.

No admin review queue. Request a session, get your config, be live — typically minutes, not days.

From signup to live blackholing in one sitting

Sign up — no card required. Your account starts free; the live BGP session comes from step 2.

From the portal, request peering — live immediately, no waiting on a human to review it and no card on file.

A GRE or WireGuard tunnel config plus a copy-paste BGP peer block, generated for your router's OS — Cisco IOS/IOS-XE, Juniper JunOS, OpenWrt, pfSense/OPNsense, VyOS, OpenBSD, or Linux+BIRD/FRR.

Once peered, malicious IPs above your chosen severity threshold get blackholed — dropped before they reach your network, not after.

Remote-Triggered Black Hole routing: your router announces a more-specific route for a malicious source IP with a special community tag, telling upstream routers to silently drop traffic to/from it — before it ever reaches your network. It's the same technique large ISPs use as part of their mitigation stack, applied to a single-router network. On its own it's very effective against connection-completing attacks — brute force, exploit attempts, C2 callbacks. It doesn't stop a volumetric flood (a UDP or SYN flood, reflection/amplification) unless you also enable uRPF / reverse-path filtering on your own router, which we document but don't configure for you.

No. A single router with a private ASN and a GRE or WireGuard tunnel to a SATIS BGP PoP is enough. Multihoming and public ASNs matter for announcing your own routes to the wider internet — they're not required just to receive and act on our blackhole feed.

Yes, as long as you put your own BGP-capable router behind it. Most residential/business ISP gateways support bridge mode, which hands your public IP straight through to your own router — the cleanest setup. Without bridge mode, your own router still works behind the ISP's box (double-NAT'd); the tunnel to SATIS is outbound-initiated, and consumer/business ISPs don't typically block that. Either way, works equally well for a homelab, a small business office, or a home network — the requirement is the router you put behind your connection, not who your ISP is.

Nothing charges automatically — there's no card on file. If you haven't added a plan, your BGP session is revoked and your account reverts to Community; you'll get a countdown email as the trial winds down so it's never a surprise. Add Shield anytime from the portal, self-service, to keep it running — no phone call or support ticket needed.

Shield is purpose-built for RTBH: one BGP session, one GRE/WireGuard tunnel, focused entirely on blackholing. Need real-time SSE streaming or more sessions? Professional and Enterprise build on the same peering, with a 14-day trial on Professional. Upgrading from the portal takes one click whenever you're ready.

Auto-approved BGP blackholing, live in minutes.

14 days free, no card • $59/mo only if you add a plan • Cancel anytime, self-service