Plans

Pick the package, not the pieces

A package sets your price, your quotas, your sustained rate limit, how long your logs are kept, what support you get — and which layers are compiled into your request chain at all. A layer your plan does not include is not disabled: it is absent.

Free
$0per month, forever

The perimeter and the delivery path for one site.

Requests
1M / month
Bandwidth
50 GB / month
Rate limit
100 req/s sustained
Log retention
7 days
Support
Community
Custom error pages
—
  • 1 site · 1 DNS zone
  • DNS with DNSSEC
  • TLS + automatic certificates
  • L4 admission + DDoS controls
  • WAF (managed rule set)
  • CDN cache
  • No AI gateway
  • No overage — hard quota
Basic
$25per month

For growing sites — bot defense, captcha and room to scale.

Requests
10M / month
Bandwidth
250 GB / month
Rate limit
1,000 req/s sustained
Log retention
30 days
Support
Email
Custom error pages
Yes
  • Everything in Free, plus:
  • 5 sites · 5 DNS zones
  • Bot management
  • Captcha (proof-of-work + challenge)
  • GeoDNS steering
  • 10 custom WAF rules
  • No AI gateway
  • Overage allowed
Enterprise
Customannual contract

Unlimited scale, dedicated capacity and an SLA.

Requests
Unlimited
Bandwidth
Unlimited
Rate limit
200,000 req/s sustained
Log retention
1 year
Support
Dedicated engineer + SLA
Custom error pages
Yes
  • Everything in Pro, plus:
  • Unlimited sites and zones
  • Unlimited custom WAF rules
  • Dedicated capacity · 99.99% SLA
  • Negotiated overage terms
  • Unlimited AI tokens
  • Overage allowed
What else changes with a package
Beyond the figures above, a package also sets your cache storage allowance, how many DNS records a zone may hold, whether GeoDNS steering is available at all (it is not on Free), and how many custom WAF rules you can write. Everything else about the platform — every layer’s behaviour, the whole Control API, the CLI and the MCP server — is identical on every plan.
How limits behave

What happens at the edge of a plan

Rate limit

The sustained figure is a token bucket, not a fixed window: a burst above it is absorbed from the bucket rather than refused, and a request that exceeds it gets a 429. That is why a spike at the top of the minute does not get double-counted the way a fixed window would.

Monthly quota

Counted from the same per-layer events that feed your analytics, per node and reconciled centrally. Over quota, a plan with overage keeps serving and bills the excess; a plan without one stops. Free is the only plan without overage.

Enabled layers

Not a feature flag checked per request — the layer is left out of the compiled chain entirely, so it costs nothing to be on a plan without it.

Log retention

Request logs and per-layer events expire on your plan’s window — 7 days on Free, 30 on Basic, 90 on Pro, a year on Enterprise. Analytics roll-ups outlive the raw rows, so a trend stays readable after the individual requests have gone.

Changing plan

A change recompiles your configuration and rolls out like any other. Sites beyond a smaller plan’s allowance are disabled rather than deleted, and a later upgrade re-enables exactly those.

Custom error pages

Your own HTML for a block, a rate limit or an origin failure, served from the edge. Available from Basic upward; Free serves the platform’s default pages.