Skip to content
← All posts

GGProtect · August 2026 · 3 min read

500 million requests, stopped.

What a web application firewall actually does, measured over a period where nobody had to think about it.

500Mrequests

Blocked

Filed under

GGProtect

Five hundred million requests reached GGProtect and went no further. No customer saw them. No origin server spent a cycle on them. No engineer was paged.

That is the number, and the interesting part is what it means rather than how large it is.

What that traffic was

It was not one dramatic attack. Attacks like that make good screenshots, but they are a small fraction of what actually hits a public application.

The bulk of it is constant, low-grade, automated noise: scanners looking for a known weakness, credential stuffing against login pages, bots scraping content, and probes checking whether a well-known vulnerability was ever patched. It never stops, it costs the sender almost nothing, and it only has to work once.

Why blocking at the edge matters

A request your server refuses is still a request your server handled. It used a connection, some processor time, and some bandwidth you paid for. Multiply that by five hundred million and you are funding an attacker with your own hosting bill.

GGProtect runs across 34 regions, so this traffic is stopped near where it originates instead of at your front door. Your infrastructure never sees it, and your customers never queue behind it.

The measure of a good quarter

Security done well is invisible, which makes it hard to sell and easy to underfund. There is no incident to point at, no war story, no all-hands recovery. Just an application that kept working.

So this is our version of a war story: half a billion requests that stopped at the edge, and a set of customers who spent that period thinking about their product instead of their firewall.