StreamMaster Shield delivers multi-layer L3/L4/L7 DDoS mitigation, real-time traffic filtering, and intelligent rate limiting for any organisation that holds data worth protecting — from datacenters and hosting providers to healthcare, finance, government, education, e-commerce, and SaaS. Deploy for your own infrastructure or resell it under your own brand. TLS 1.3 on every plan.
Intelligent, automated threat mitigation protecting every layer of your network — from the moment traffic arrives to the moment it reaches your origin.
IP allow/deny lists, CIDR range filtering, and protocol-level attack mitigation at the network layer — blocking the majority of threats before they connect.
Connection tracking, port-based filtering, and SYN flood protection at the transport layer, keeping your services reachable when it matters most.
Token-bucket rate limiting per license key, configurable per tier — up to 200,000 requests per minute — so legitimate traffic always gets through.
Every server receives a unique, cryptographically random license key. Impossible to guess, brute-force, or duplicate — only authorised nodes pass through.
Route all traffic through Shield to your origin servers transparently — full reverse proxy with no changes required on your existing infrastructure.
Live traffic monitoring, request volumes, block rates, and connection tracking through the customer portal — refreshed every five seconds.
Every Shield plan is protected by TLS 1.3 in standard HTTPS — encrypted end-to-end and indistinguishable from regular web traffic. Your data stays protected in transit, on any network.
Your real server address stays hidden behind the Shield proxy, so attackers cannot bypass protection to target your origin directly.
Always-on, automated mitigation that absorbs attacks around the clock — no staffing, no manual intervention, no gaps in coverage.
If your organisation depends on critical data being online, StreamMaster Shield keeps it protected — whatever the sector, whatever the attack.
Protect customer racks, transit, and cross-connects from volumetric and protocol attacks — and add resellable protection to every cabinet you lease.
Keep shared, VPS, and dedicated hosting online under sustained abuse, and turn DDoS protection into a recurring revenue line for every client.
Safeguard patient portals, EHR systems, and telemedicine platforms from downtime that puts lives, care, and compliance at risk.
Keep online banking, trading platforms, and payment gateways available under attack — where every second of downtime carries real cost.
Protect citizen-facing services and internal systems from disruption and unauthorised access, on a platform that keeps identities hidden.
Defend student portals, LMS platforms, and research systems through enrolment peaks, exam periods, and open days.
Never lose a sale to an outage. Protect checkout, inventory, and customer accounts during traffic surges and flash sales.
Absorb DDoS floods while keeping latency low for players, viewers, and live events — without buffering, lag, or dropouts.
One license per node. Protect APIs, applications, and customer data behind a clean, encrypted reverse proxy with predictable pricing.
Protect more customers, earn more margin. Resell StreamMaster Shield under your own brand to any organisation that depends on uptime — wholesale pricing, automated license management, and full revenue tracking, built for datacenters, hosting providers, MSPs, and technology vendors.
Up to 40% discount on all tiers. Set your own retail price and keep the margin.
Auto-generated invoices for every license. Track wholesale cost vs retail price.
Real-time revenue tracking, margin analysis, and per-reseller breakdowns.
Create, suspend, and manage licenses for your customers from one admin panel.
Whether you run a datacenter, manage hosting infrastructure, operate a hospital network, or deliver government IT services — StreamMaster Shield gives you enterprise DDoS protection you can sell to your customers at a healthy margin, with none of the operational overhead.
*Based on 40% reseller discount. Your retail price is what you charge customers.
Every request is inspected across multiple layers before it reaches your origin — clean traffic passes through, attacks are stopped in their tracks.
Incoming requests hit the Shield proxy node first. Your origin server IP stays hidden and protected.
Each request is checked against the license database. Only valid, active licenses pass through.
L3 IP/CIDR filtering, L4 connection tracking, and L7 rate limiting applied in sequence on every request.
Clean traffic is forwarded to your upstream server. Attacks are blocked before they reach your origin.
Everything below ships as part of your Shield subscription — each phase is hardened, verified and enabled automatically as it is delivered.
The features that make "bulletproof" true.
The moat competitors cannot easily copy.
What scales the business without you.
After the product is reliable and proven.
Defense in depth.
When real bottlenecks demand it.
The Shield promise: every stream URL is always working, always fast, always protected — a block never takes a customer down, and the origin is never reachable.
One license protects one server. Every tier includes the managed reverse proxy, origin IP hiding, TLS 1.3 encryption, and real-time analytics.
Enter your Shield license key to view your protection dashboard
Loading...
Run this curl command to verify your license is working:
If active, you will get a JSON response with your license status. If the license is invalid, the request is blocked.
Point your domain(s) through Shield:
Set this in your DNS provider (e.g., Cloudflare, Namecheap, GoDaddy). TTL: 300s recommended.
Every proxied request must include the X-Shield-License HTTP header:
This header is required for authentication. Requests without a valid license are blocked at L3.
X-Shield-License header in reverse proxy configuration.https://shield.streammaster.co.uk. Pass license via HTTP request header.X-Shield-License with your key to each request and point the host at Shield.Shield wraps every request in standard HTTPS with TLS 1.3, encrypted end-to-end and indistinguishable from regular web traffic. Your data stays protected in transit, on any network.
Client Connects
A client visits your domain → DNS points to Shield
TLS Termination
Shield terminates HTTPS, validates license, applies filters
Origin Forwarded
Clean traffic proxied to your server → origin IP stays hidden