Skip to content
Citadel · Layer 7 DDoS protection

Make every request earn its way to the origin.

Citadel sits in front of HTTP/HTTPS applications and decides what should pass, be challenged, slowed, cached, escalated or blocked — before your origin spends CPU, database work and bandwidth.

€0 starter tier6 challenge modesPer-path policy

Decision log

How Citadel handles requests: visitors and search crawlers pass through Citadel to the origin, a headless bot fails a JS challenge and is blocked with 403, and an HTTP flood is rate-limited with 429.

How it connects

Point one A record. Citadel protects the site.

Cloudflare stays your DNS and edge. Citadel is the reverse proxy behind it that decides which requests reach your origin.

  1. VisitorBrowser, bot or flood
  2. Cloudflare edgeProxied (orange cloud) A record
  3. CitadelReverse proxy checks every request
  4. Your originReceives clean traffic only
  1. Add the domain in the Citadel portal

    Enter the origin IP or hostname, the port and the TLS-to-origin setting.

  2. Point a proxied A record at Citadel

    Copy the ingress IP from the domain page. In Cloudflare DNS, point the apex and each protected hostname to it with Proxied on, and set SSL/TLS to Full.

  3. Citadel confirms the connection

    It checks about every minute, or select Check connection. The domain changes from Awaiting DNS to Active.

Cloudflare DNSYour zone stays in Cloudflare
TypeNameContentProxy status
A@Citadel ingress IPProxied
AwwwCitadel ingress IPProxied
MX@Your mail serverDNS only

Mail, TXT and other non-web records do not change. A DNS-only (grey cloud) web record skips Citadel. Cloudflare setup guide

Citadel protects Layer 7 HTTP/HTTPS traffic. Network-layer mitigation is a separate edge task.

Attack timeline

The edge takes the flood. The origin barely notices.

A 17-minute HTTP flood, drawn with the Edge, Proxy and Blocked series that Citadel Analytics uses. Move across the chart to read each moment.

A 17-minute HTTP floodExample attack · 14:00 to 14:30
  • Edge requests
  • Blocked at the edge
  • Proxied to origin
Peak at the edge
18.7kr/s
Peak at the origin after Auto escalated
671r/s
Attack requests stopped at the edge
95.9%
Requests the origin never saw
16.4M
Requests at the edge climb from about 500 to 18.7k per second at 14:04. For one minute some of the flood reaches the origin, then Auto raises the challenge level to JS and origin traffic falls back to about 671 requests per second until the attack ends at 14:21.

Why Layer 7 is different

Attack traffic can look normal until you inspect what it is doing.

That is why Citadel focuses on requests, paths and sessions instead of pretending every DDoS problem is just a bandwidth problem.

HTTP flood

High request volume that looks valid enough to make the application and database do real work.

Recommended setting

Auto with a rate-limit preset. Auto escalates during the flood and heals when traffic calms.

Traffic shape
  1. 1Rate signals
  2. 2Challenge
  3. 3Strike
  4. 4Temporary ban

Control surface

Strong defaults, explicit exceptions, visible outcomes.

Citadel is designed so an operator can understand why traffic changed state without guessing what an invisible black box decided.

Six challenge levels, one per domain

Pick how much friction a domain adds. Select a level to see who gets through.

Friction

Starts at a calm baseline, escalates during an attack and heals when traffic calms. The starting point for public websites.

Visitors in a browser
Calm until attacked
APIs and webhooks
May be interrupted under attack
Allowlisted clients
Bypass

Allowlists

Matching clients bypass challenges, including Lockdown.

  • Path/api/
  • IP or CIDR203.0.113.0/24
  • User-AgentStatusMonitor/2.1

Rate limits and strikes

Repeat offenders escalate step by step instead of one blunt rule.

  1. Strike 1
  2. Strike 2
  3. Temporary ban
  4. Recovers

Cache before origin

Eligible static responses come from cache, so repeat requests skip origin work.

Cached.css.jsimagesfonts
Bypassed/api//admin/

Alerts and origin health

Email and webhook events, plus health probes with latency and status.

  • WebhookAttack started
  • EmailAttack ended
  • HealthOrigin probe 200

Your own challenge and error pages

Paste an HTML shell per page type. Citadel injects the real verification controls.

Challenge pages
  • JS challenge
  • Interaction
  • Lockdown
Error pages
  • 403 Blocked
  • 429 Rate limited
  • 502 · 503 · 504
<h1>{{BRAND}}</h1>
<p>{{MESSAGE}}</p>

Access, security and error logs

Access entries with method, path, status, IP, ASN, country and latency. Security entries for challenges, blocks, rate limits and bypasses. Error entries for origin 502, 503 and 504. Trace one request by its ID. Kept for 15 days, with sensitive query values redacted.

Request IDMethodPathStatusResult
r-7f3aGET/pricing200Proxied
r-81c2POST/login403Challenge failed
r-9d04GET/search?q=[redacted]429Rate limited
r-a6e1POST/api/webhook200Allowlisted bypass
r-b257GET/checkout502Origin unreachable
r-c9f8GET/reports504Origin timeout

Citadel portal

Run your protection yourself, from one portal.

Every setting on this page is self-serve. Billing, invoices and tickets stay in the StealthRDP client area.

Command center

  • Domains already synced and domains awaiting DNS
  • Your service plan and remaining billing-period bandwidth
  • Recent proxied and blocked requests, and live traffic
Read the Overview guide

Plans

Same protection model. Choose the domain and bandwidth allowance.

Start free, then scale the allowance when the number of protected properties or clean traffic grows.

Citadel
Starter
€0/mo

For smaller websites that want the same core request controls.

Protected domains
2 domains
Clean bandwidth
10 GB / month
Challenge modes
Cookie · JS · Interaction · Auto
Attack mode
Lockdown + allowlists
Most popular
Growth
€49/mo

For production sites that need more protected domains and traffic.

Protected domains
5 domains
Clean bandwidth
50 GB / month
Challenge modes
Cookie · JS · Interaction · Auto
Attack mode
Lockdown + allowlists
Citadel
Scale
€149/mo

For multi-site deployments and larger clean-traffic allowances.

Protected domains
10 domains
Clean bandwidth
100 GB / month
Challenge modes
Cookie · JS · Interaction · Auto
Attack mode
Lockdown + allowlists

Included with every plan

  • Layer 7 (HTTP/HTTPS) DDoS protection
  • Cloudflare edge + Citadel reverse proxy
  • Auto challenge escalation (Cookie → JS → Interaction)
  • Lockdown mode for active attacks
  • Real-time traffic and attack analytics
  • Custom challenge templates
  • Custom error pages
  • Access logs, error logs and error tracing
  • Self-serve Citadel portal
  • Point your A record — we protect the site
Citadel

Protect the origin without turning the website into a CAPTCHA wall.

Start with the free tier, then tune protection by domain and path as traffic changes.

WhatsApp support