Reverse proxy · DDoS scrubbing

Your origin server,
completely invisible

Cachivo puts a distributed proxy cluster in front of your infrastructure. Attacks land on our multi-layer scrubbing edge — your real IP never appears in DNS, certificates, or headers.

No changes required on your server · Protected hostname issued instantly
7
Active PoP nodes
<10min
To add capacity
0
Origin IPs exposed
24/7
Health-monitored
Why Cachivo

Built to absorb what your origin can't

Every protected server gets its own hostname, per-server rate limiting, and a fleet of disposable edge nodes in front of it.

Origin invisibility

Your real FQDN and IP never appear in public DNS, certificates, or response headers. Nodes reach your origin over a private, proxied hostname of its own.

DDoS scrubbing

An anycast edge spanning hundreds of locations absorbs volumetric floods. Our nodes add per-server connection and request-rate limits, SYN tuning, and packet filtering.

Global node fleet

Traffic is load-balanced across health-monitored nodes. A failing node drains automatically and capacity is added in minutes, not days.

Disposable nodes

Nodes are stateless. Any of them can be destroyed and rebuilt from scratch, rejoining automatically — the control plane holds the only source of truth.

Transparent billing

One point protects one server for one month. A full ledger, an automatic grace period, and instant resume the moment you top up.

Full REST API

Everything the dashboard does is scriptable. Mint scoped API tokens and manage servers, customers, and credit from your own tooling.

How it works

Four hops. Only two are visible.

Register a server and it's published as yourname.scrubbing.top. Point your users there — nothing else changes on your side.

Step 1
End user
Connects to your protected hostname — the only address they ever see.
Step 2
Scrubbing edge
Two independent filtering layers: any-port entry filtering, then WAF, DDoS mitigation and load balancing across healthy nodes.
Step 3
Cachivo node
Applies your per-server rate and connection limits.
Step 4
Your origin
Reached privately over its own hostname. Never exposed.
How it works
Every request crosses three independent filtering layers before it reaches your servers. Green is traffic delivered; red is an attack, stopped at whichever layer catches it.
shop.example portal.example 🔒 Origin your-domain.example 🛡️ First L7 Protectionany port · edge filtering 🌩️ Secondary L7 Protectionanycast · DDoS scrubbing 7POPS Third Final WAF + L4WAF · rate-limit · packet filter ⚖️ Load Balancing Servershealth-checked · weighted Backend 1 Backend 2 Backend 3 Backend 4 Origin servers (backend) never exposed
Authentication Streaming Blocked attacks

Illustration, not live data. Every customer sees this same view for their own traffic, with real numbers, inside the panel.

FAQ

Questions

The things people ask before switching their DNS.

Do I have to change anything on my server?

No. Your origin keeps its current setup behind a private proxied hostname of its own. Cachivo becomes the public front door; you simply point users at the new protected subdomain.

What happens if a node goes down?

The edge health-monitors every node and drains an unhealthy one automatically. Because nodes are stateless, a replacement is provisioned and enrolled in minutes.

What if I run out of credit?

Your server enters a grace period (5 days by default) and keeps serving. If it is still unpaid after that it is suspended and visitors see a payment-required page. Topping up resumes it immediately.

Can I automate this?

Yes — every dashboard action is a REST endpoint. Mint an API token in the panel and drive it from your own scripts or CI. See the API documentation.

Does it support non-HTTP traffic?

HTTP and HTTPS are supported today. Raw TCP/UDP forwarding for game servers, RDP and custom ports is on the roadmap.

Put Cachivo in front of it

Register a server, get a protected hostname, and keep your origin off the map.

Open the panel