Back to case studies

Professional Association · 2026

aesYc

aesYc

CloudflareL7 DDoSMigrationSecurity

When a website is your main public channel and it starts going down under attack, you don't need a ticket: you need someone to stop it today and fix the problem at the root. That is exactly what we did for aesYc.

The challenge

aesYc's website was under application-layer (Layer 7) DDoS attacks: waves of seemingly legitimate HTTP requests, designed to exhaust CPU, connections and the database until the site went down. This kind of attack is not stopped by a simple network firewall, because the traffic mimics that of a real user.

Their previous hosting, a generic provider, neither told that traffic apart nor had the capacity to absorb it, and the team had no in-house technical profile to respond. The result: the platform went offline precisely at its busiest moments, with the reputational damage that means for an association.

The solution

We tackled the problem in two stages: stop the attack, and then leave the platform ready so it would not happen again.

  • Layer 7 DDoS mitigation: we configured the protection rules leveraging Cloudflare's global network, filtering malicious traffic at the edge before it reaches the origin server. Rate limiting, browser challenges and reputation-based blocking to separate bots from people.
  • Migration to our infrastructure: we moved the site to our servers in Spain, on the AS215691 network, with direct control of the environment and no middlemen.
  • Web-server tuning: we tuned the server to handle the expected request volume (workers, connection limits, timeouts and compression) so it performs under real load.
  • Caching system: we set up content caching to serve most requests without touching the application, cutting latency and resource usage.
  • Hardening and audit: we configured the environment with security best practices and ran a full audit to verify the platform was left as protected as possible.
  • Direct support: we became their go-to technology partner, with no ticket queues or third-party helpdesk.

Results

  • Layer 7 attacks mitigated: malicious traffic is filtered at the Cloudflare edge before it touches the server.
  • A website that stays stable under load, with server and cache tuned to withstand traffic peaks.
  • Infrastructure in Spain, under our control, with no reliance on a generic host.
  • A hardened, audited environment with security best practices applied.
  • A single provider for hosting, protection and support, with a direct line to whoever runs the platform.

Have a similar project?

Tell us about your challenge. We reply in under 24 hours.