MULTI-LAYER EDGE SECURITY
The Dome
Stop attackers at every layer of your infrastructure.
Multi-layer edge security with WAF, network isolation, and runtime protection.
THE PROBLEM
Your Perimeter Is Swiss Cheese
Traditional security stops at the firewall. But attackers don't. Once inside, they move laterally — from endpoint to database, from API to admin panel.
Edge Only
WAF blocks the front door. Attacker walks through the API. 47% of breaches start with valid credentials.
Flat Network
Everything talks to everything. One compromised endpoint means total access. Lateral movement takes minutes.
Blind Spots
You can't stop what you can't see. East-west traffic is invisible. Attackers live in your blind spots for months.
THE SOLUTION
Four Layers. Total Protection.
The Dome wraps your infrastructure in concentric layers of security.
Every packet inspected. Every connection verified. Every threat stopped.
Coraza WAF
Application layer protection. OWASP Top 10. SQL injection. XSS. ModSecurity rules. Stops attacks before they reach your app.
Cilium
Network policies with identity awareness. mTLS everywhere. Encrypted east-west traffic. Service mesh without the complexity.
L2 Isolation
ARP protection. MAC filtering. Network segmentation at the data link layer. Stops lateral movement cold.
eBPF / Tetragon
Runtime enforcement at the kernel level. Syscall filtering. Process monitoring. No blind spots. No agents.
BUILT ON
Open source security foundations
100% open source. No vendor lock-in. You own your security.
WHO THIS IS FOR
Built for Teams That Run Infrastructure
The Dome is designed for organizations where uptime, compliance, and network security are non-negotiable.
Platform / DevOps Teams
Running Kubernetes clusters, managing microservices, and need network-level security that works with your existing stack. No vendor lock-in.
Government / Sovereign Buyers
Need sovereign cloud, data residency guarantees, and compliance with national security frameworks. Built on 100% open-source tech.
Companies on Kubernetes
Running production workloads on K8s and need east-west traffic control, runtime visibility, and lateral movement prevention without the complexity.
DEPLOYMENT
Protected in Minutes
Point Your DNS
Connect your domain and route traffic through The Dome edge network.
We Create Your Zone
The Dome configures your protected security zone automatically.
Join the Mesh
Connect internal services with secure segmentation and visibility.
You're Protected
Your infrastructure is protected across every security layer.
GLOBAL NETWORK
Close to Your Users. Everywhere.
The Dome edge network provides low-latency protection close to your users and infrastructure.
Americas
Europe
Asia-Pacific
Middle East
Africa
PRICING
Choose Your Protection Layer
Dome Edge
Public-facing protection
Protect your websites, APIs, and public applications. No agent required.
- Point DNS to The Dome
- WAF + Cilium + eBPF at edge
- DDoS protection
- Bot mitigation
- Real-time threat dashboard
- Nearest PoP routing
- Internal traffic protection
- Zero-trust mesh
- Service-to-service mTLS
Dome Mesh
Internal infrastructure protection
Zero-trust for your internal services. Every connection authenticated and encrypted.
- Kuma dataplane on your services
- mTLS everywhere
- Service-to-service policies
- Lateral movement prevention
- Full traffic observability
- Control plane hosted by H2
- Public traffic filtering
- WAF protection
- DDoS mitigation
Dome Complete
Total protection
Edge + Mesh. Public and internal. Everything protected, end-to-end.
- Everything in Edge
- Everything in Mesh
- End-to-end visibility
- Unified policy management
- Priority support
- Dedicated security engineer
Ready to deploy The Dome?
Stop attackers at every layer.
Get protected in minutes.