Log in

We carry the traffic. You ship.

Origin shield / ingestion

Hide behind us.

Clients connect to EchoRelay, never to you. Auth, validation, and limits run at the edge — your real servers stay off the map.

At the edge

Threats hit us first.

Your servers, invisible.

Clients connect to us, never to you. Your real infrastructure stays completely off the map.

Flood protection, built in.

We stand between you and the internet. We rate-limit and allowlist, so bursts hit us first — and stop there.

Nothing malformed slips through.

Payloads validated against your schema. Malformed data stops at the edge.

Ingest without exposure.

Take webhooks and inbound traffic on an EchoRelay endpoint — authenticated, validated, rate-limited. Your origin never takes a public hit.

Secrets you keep.

Bring your own keys. We store them encrypted and can’t read them.

How it works

In front, not exposed.

  1. Clients connect to us

    Callers and webhook senders reach your EchoRelay endpoint — never your origin, which stays off the public map.

  2. We screen at the edge

    We authenticate the request, validate it against your schema, rate-limit, and allowlist — so bursts and malformed data stop here.

  3. Only clean traffic reaches you

    Your origin only ever hears from us — authenticated and validated. It never takes a public hit.

Flood protection means we rate-limit and allowlist — not a scrubbing CDN. The edge is the part of your stack that’s allowed to be on the public internet, so the rest doesn’t have to be.

Questions

Origin shield, answered.

Do my servers ever take public traffic?
No. Clients connect to EchoRelay; your origin only ever hears from us, so it can live off the public internet entirely.
Does origin shield protect against DDoS?
Not the way a scrubbing CDN does. We rate-limit and allowlist, so bursts and abuse hit us first — but we do not absorb volumetric attacks for you. Flood protection is the honest term for what the edge does.
Do you verify webhook signatures like Stripe or GitHub?
We authenticate inbound traffic with a project key you mint and validate payloads against your schema — but per-provider HMAC signature verification is not something we do today.
Where do my outbound credentials live?
Bring your own keys. We store them encrypted, cannot read them, and mask them in logs and audit views.

Not the right shape? To push one request out to many services rather than take traffic in, use Fan-out. To keep a shadow copy of inbound traffic for audit, add Mirror.

Off the map. Still reachable.

No credit card required.

Currency: