DDoS resilience
Prove your limits shed abuse while real users get served.
DDoS Resilience is a one-time Optics add-on that finds out what an attack would do to you, in private. It floods a site you own with the traffic an attacker would send, and scores one question: did the abuse get turned away while a real customer kept getting served?
It attacks the way abuse does
Sudden floods, connections held open to tie your app up, oversized requests, and traffic aimed squarely at the parts that cost you money. Each one tests a different defence.
It scores who still got served
A run passes when the abuse gets turned away while a real customer, checked at the very same moment, is still served quickly. Locking everyone out fails too — that is an outage you caused yourself.
It only ever aims at you
Runs target infrastructure you own and nothing else. Production and third-party hosts are refused before a single request is sent.
Stay open for business when the traffic turns hostile.
- Throws a flood at your own app so you learn this in private
- Shows whether real customers kept getting served through it
- A score you can put in front of a customer or an auditor
- Your defences, visible on your dashboard
A scorecard, not a hope
A weighted score per run, protection cards on the monitoring dashboard showing which defences held, and the run history behind them.
Setup
Point the runner at a host you own. Results upload against the project's own key, next to your pentest and load-test runs.
$249
Pay once and DDoS Resilience is unlocked for your whole organization, on top of a Pro or Team plan. Not a subscription, and never priced per run.
Resilience Suite — $619
Pentest, Load Testing, and DDoS Resilience in one purchase. 17% off buying them separately — save $128.
See the suiteWhat is DDoS Resilience in Optics QA?
It is a fire drill for your app. Optics sends the kinds of traffic an attacker sends — sudden floods, connections held open to tie your app up, requests deliberately chosen to cost you money — at a site you own, and scores whether your defences turned the abuse away while a real customer kept getting served.
Will it attack my production site?
No. Runs only ever target infrastructure you own, and production and third-party hosts are refused before a single request is sent. The point is to find out what your defences do before real abuse does.
What counts as passing?
Turning the abuse away, not merely staying up. A run passes when the hostile traffic gets refused while a real customer, checked at the very same moment, is still being served quickly. Locking everyone out fails the run too — that is an outage you caused yourself.
Is this a subscription?
No. DDoS Resilience is a one-time $249 purchase that unlocks the capability for your whole organization, on top of a Pro ($69/month) or Team ($249/month) plan.
Where do results show up?
Every run comes back with a score, and your dashboard shows which defences held: whether floods were turned away, whether slow connections were cut off, and whether an attacker could have run up your bill. Runs are kept, so you can see the score move release to release.
Is DDoS Resilience included in the Resilience Suite?
Yes. The Resilience Suite bundles Pentest, Load Testing, and DDoS Resilience in one $619 one-time purchase — 17% off buying them separately, saving $128. One purchase unlocks all three for your whole organization.
