AWS Shield

AWSSecurityFree tier available

Managed DDoS protection service with always-on Standard tier for CloudFront and Route 53 edge, and Advanced tier adding 24/7 DDoS Response Team access, cost protection, and enhanced Layer 7 detection

Jurisdictional exposure

Provider HQ
USSeattle, USA

Subject to CLOUD Act, FISA-702, DPF

Region locations
APACCNEEAEUUKUSOther40 regions across 7 jurisdictions
Sovereign option
Yes — 6 sovereign-flagged regions available

Attributes

SLA Uptime
99.9%
Always On
Yes

Sub-services (3)

Shield Standard

Always-on L3/L4 DDoS protection for CloudFront, Route 53, and Global Accelerator

Shield Advanced

Subscription-tier protection with L7 detection and DDoS cost protection

Shield Response Team

24/7 access to the AWS DRT during active DDoS events

Compliance & Certifications

This service is attested for the following frameworks. Always verify with the provider before relying on a specific compliance posture.

Where this runs

40 regions
28 countries
6sovereign
Sovereign regions (6)
  • AWS European Sovereign Cloud (Brandenburg) · BrandenburgAWS European Sovereign Cloud
  • AWS GovCloud (US-East) · AshburnAWS GovCloud (US)
  • AWS GovCloud (US-West) · HillsboroAWS GovCloud (US)
  • AWS European Sovereign Cloud (Brandenburg) · BrandenburgAWS European Sovereign Cloud
  • China (Beijing) · BeijingAWS China (Sinnet)
  • China (Ningxia) · YinchuanAWS China (NWCD)
Commercial regions (34)

Europe (8)

  • Europe (Paris)
  • Europe (Frankfurt)
  • Europe (Ireland)
  • Europe (Milan)
  • Europe (Spain)
  • Europe (Stockholm)
  • Europe (Zurich)
  • Europe (London)

North America (7)

  • Canada West (Calgary)
  • Canada (Central)
  • Mexico (Central)
  • US East (N. Virginia)
  • US West (Oregon)
  • US East (Ohio)
  • US West (N. California)

South America (1)

  • South America (São Paulo)

Asia (11)

  • Asia Pacific (Hong Kong)
  • Asia Pacific (Hyderabad)
  • Asia Pacific (Mumbai)
  • Asia Pacific (Jakarta)
  • Asia Pacific (Osaka)
  • Asia Pacific (Tokyo)
  • Asia Pacific (Malaysia)
  • Asia Pacific (Singapore)
  • Asia Pacific (Seoul)
  • Asia Pacific (Taipei)
  • Asia Pacific (Thailand)

Oceania (3)

  • Asia Pacific (Melbourne)
  • Asia Pacific (Sydney)
  • Asia Pacific (New Zealand)

Middle East (3)

  • Middle East (Bahrain)
  • Israel (Tel Aviv)
  • Middle East (UAE)

Africa (1)

  • Africa (Cape Town)

Tags

Equivalent services on other platforms

Alibaba Web Application FirewallAlibaba

Managed WAF protecting web apps from OWASP Top 10 attacks, bot traffic, API abuse, and data scraping, with global and China regional deployment, custom rule engine, and unified consoles across Anti-DDoS and Security Center

Azure DDoS ProtectionAzure

Managed Distributed Denial-of-Service protection for Azure resources with always-on traffic monitoring, adaptive real-time tuning, cost-guarantee protection against scale-out attacks, and integration with Azure Monitor for attack analytics and telemetry

Cloudflare Magic TransitCloudflare

L3 DDoS scrubbing and IP transit for enterprise data centres — BGP advertises customer prefixes from Cloudflare's edge, clean traffic flows back via GRE / IPsec / private peering. Sub-3-second time-to-mitigation with no rerouting on the customer side.

Cloudflare Bot ManagementCloudflare

Machine-learning bot classification at the edge — scores every request 1-99 and exposes that to WAF rules. Distinguishes search-engine crawlers, scrapers, credential-stuffing tools, and headless browsers without breaking legitimate automation.

Cloudflare API ShieldCloudflare

API-specific security layer — schema validation, mTLS client authentication, rate-limiting per JWT subject, sensitive-data detection in responses, and API discovery / inventory that auto-surfaces unknown endpoints.

Cloudflare WAFCloudflare

L7 web application firewall protecting against OWASP Top 10 risks with Cloudflare-managed rule sets, custom expression-based rules, exposed-credentials detection, rate-limiting integration, and machine-learning attack-score signals tuned across the global traffic graph

Cloud Temple Anti-DDoSCloud Temple

Volumetric and application-layer DDoS protection for services hosted on Cloud Temple, with sub-second detection and automated mitigation across the SecNumCloud-qualified perimeter

Gcore DDoS ProtectionGcore

Always-on L3/L4/L7 DDoS mitigation delivered at Gcore's edge POPs, with traffic scrubbing, capacity in the multi-Tbps range, and SLAs against volumetric and application-layer attacks

Gcore WAAPGcore

Web application and API protection with OWASP rule sets, bot management, API schema enforcement, and rate limiting — delivered at the CDN edge with a single configuration surface

Cloud ArmorGCP

Edge DDoS protection and web application firewall with managed rule sets for OWASP Top 10, adaptive bot protection, and reCAPTCHA Enterprise integration

Huawei Web Application FirewallHuawei

Managed web application firewall with OWASP Top 10 rule sets, bot management, anti-crawler, CC (challenge-collapsar) attack mitigation, custom rule engine, and regional deployment with integrated DDoS protection

IONOS DDoS ProtectionIONOS

Always-on volumetric and protocol-level DDoS mitigation at the network edge, with automatic detection and scrubbing for L3/L4 attacks targeting Compute Engine, Load Balancer, and Public IP resources

OCI Web Application FirewallOracle

Layer-7 protection against OWASP Top 10 attacks (SQLi, XSS, RCE), bot traffic, and DDoS at the application layer. Edge-deployed for global protection or regional for backend-fronted apps.

Web Application FirewallT Cloud

L7 web application firewall protecting against OWASP Top 10 risks — SQL injection, XSS, command injection — with managed rule sets, custom rules, IP allow/block lists, and bot-detection heuristics tuned for OTC-hosted apps

Pricing

Pricing model:freemium