Gateway Sentry

Products / Sentry Compute

Anycast Routed VMs. Untouchable

Live on the bleeding edge of our anycast network and DDoS mitigation stack. Every packet scrubbed at line rate while you operate inside the security perimeter.

from $13 per monthanycast native IP included2.1+ Tbps in front of itin + out bidirectional filteringfull root KVM console included

DDoS Protected Hosting on Our Edge

Most DDoS protection sits in front of someone else's server. Sentry Compute puts your workload directly on our anycast network, so attack traffic never has to traverse a public path to reach you.

Anycast IP, Included

Every VM is provisioned with a native anycast IP from the global edge. Players, customers, and clients reach the closest edge automatically. No DNS tricks, no proxying, no extra hops.

Always-On Protection

The same line-rate filtering that powers Network Protection runs in front of every VM. Volumetric floods, SYN floods, and amplification attacks die at the edge, before your hypervisor ever sees a packet of them.

Bidirectional Filtering

Both directions of traffic ride the anycast range. Outbound replies stay inside the perimeter end to end, on the same path packets came in on.

Minimal Added Latency

No scrubbing detour, no GRE tunnel, no upstream provider. Your workload runs on the same edge that filters its traffic, so protection costs single-digit milliseconds, not a round trip to a scrubbing center.

Modern Hardware

High-clock CPUs and locally-attached NVMe storage, tuned for game servers, real-time backends, and latency-sensitive APIs. The tick rate holds because the hardware was picked for it.

Full Control

Linux or Windows with full root or administrator access, a KVM console for out-of-band management, and a firewall control panel. It is your machine; we just keep the internet polite to it.

Self-Service From the Dashboard

Deploy From the Dashboard

Pick a plan and a location and the instance comes online in minutes, protected from the first boot, with its anycast address already announced.

Reinstall & Rescue

Reinstall the OS, reset credentials, or rename the instance yourself, any time, without a ticket. Bad night? Fresh OS in minutes, same IP, same protection.

Metered Transfer

Bandwidth is metered with a per-plan allowance and transparent overage, visible live in the dashboard before it bills. See Plans & Pricing.

Game Query Caching

Server-browser queries like A2S are answered from edge cache at every site, so query floods never reach the VM. See Game Query Caching.

Frequently Asked Questions

What is DDoS protected compute?
DDoS protected compute is a virtual machine that runs directly inside Gateway Sentry's anycast edge network, so attack traffic is scrubbed at line rate before it reaches your hypervisor. Always-on 2.1 Tbps mitigation drops volumetric floods, SYN floods, and amplification attacks at the edge.
Is Sentry Compute a DDoS protected VPS?
Yes. Every Sentry Compute VM is provisioned with a native anycast IP and always-on DDoS protection, giving you a DDoS protected VPS with full root or administrator access on Linux or Windows.
How is this different from typical secure cloud hosting?
Most DDoS protection sits in front of someone else's server. Sentry Compute hosts your workload on our own anycast network, so there is no scrubbing detour, no GRE tunnel, and no upstream provider, keeping added latency in single-digit milliseconds.
What hardware and OS options does DDoS protected hosting include?
You choose high-clock multi-core CPUs, the memory you need, and locally-attached NVMe storage, on Ubuntu, Debian, or Windows. A native anycast IP and a KVM console for out-of-band management are included.
How do I get a DDoS protected compute instance?
Pick a plan and location in the dashboard and deploy. Supported locations provision instantly, and your instance comes online in minutes with its anycast IP already protected.

Deploy Inside the Perimeter

Pick a plan in the dashboard and your VM comes online protected, with its anycast address already announced