Anycast edge delivery

Your origin answers once. The edge answers everywhere.

1boxCDN terminates TLS, caches and reshapes traffic at 38 points of presence, so a request from Belgrade never travels further than Belgrade. Origin shielding, HTTP/3 and tiered caching are on by default — not upsells.

No card required · 100 GB egress included · Pull zone live in ~40 s

Edge traffic — all PoPs
1 284 970
requests / sec
+2.4% vs 3 h
00:00 UTC 12:00 now
38
Points of presence
24 metro, 14 regional
104 Tbps
Egress capacity
Provisioned, not burst
11 ms
Median TTFB
Cache hit, EU metro
99.99 %
Availability SLA
Measured per PoP

Network

Every PoP runs the full stack

No tiered hierarchy of “edge-lite” nodes. Each location terminates TLS 1.3, serves HTTP/3, runs the compute runtime and holds a full cache tier, so failover is a routing decision rather than a degradation.

RegionMetroIATA Capacityp50 TTFB Hit ratioState
EuropeFrankfurtFRA12.0 Tbps7 ms96.4%active
EuropeAmsterdamAMS10.5 Tbps8 ms95.8%active
EuropeLondonLHR9.0 Tbps9 ms96.1%active
EuropeStockholmARN3.2 Tbps12 ms93.7%active
EuropeBelgradeBEG2.6 Tbps13 ms93.4%active
EuropeIstanbulIST3.0 Tbps16 ms92.9%maintenance
Middle EastDubaiDXB2.8 Tbps24 ms91.4%active
Asia PacificSingaporeSIN6.4 Tbps31 ms93.1%active
Asia PacificTokyoNRT5.6 Tbps33 ms92.6%active
North AmericaAshburnIAD11.0 Tbps34 ms95.2%active
North AmericaLos AngelesLAX8.2 Tbps38 ms94.8%active
South AmericaSão PauloGRU2.4 Tbps52 ms90.3%active
12 of 38 shown Anycast /24 + /48 per metro Open peering policy 60 s probes, 7-day median

Latency

Time to first byte, by region

Cache-hit TTFB from in-region probes. p95 is reported alongside p50 because that is the number your slowest users actually live with.

p50 p95 milliseconds
0 20 40 60 80 FRA AMS LHR BEG IST DXB SIN IAD 19 21 23 31 38 52 68 74

Platform

What runs at the edge

CACHE

Tiered caching with origin shield

A single designated PoP fetches from your origin; the other 37 pull from it. Origin request volume drops by roughly 30× on typical asset workloads.

PURGE

Surrogate-key invalidation

Tag responses with Surrogate-Key and purge thousands of related objects by tag in under 150 ms globally. No wildcard path guessing.

TRANSPORT

HTTP/3 and 0-RTT resumption

QUIC with connection migration, TLS 1.3 with optional 0-RTT for idempotent requests, Brotli and Zstandard negotiated per client.

COMPUTE

Edge functions on WASM

JavaScript and any WASI target, cold start under 5 ms. Rewrite requests, sign URLs, run A/B splits and auth checks before the cache lookup.

MEDIA

On-the-fly image and video

Resize, crop, re-encode to AVIF or WebP and adapt HLS renditions at request time. Derivatives are cached as first-class objects.

SHIELD

L3/L4 absorption and WAF

Volumetric floods are dropped in the fabric before reaching a cache node. Managed rulesets plus your own rate limits, scoped per route.

OBSERVE

Real-time log streaming

Structured access logs to S3, GCS, Kafka or an HTTP sink with roughly 15 s end-to-end lag. Cardinality is yours to choose.

ROUTING

Weighted origin groups

Health-checked origins with failover, canary weights and sticky sessions by cookie or header. Shift traffic without a DNS change.

CONTROL

Config as code

Every zone setting is exposed through the API, the Terraform provider and versioned snapshots. Roll back a bad deploy in one request.

API

Declarative, versioned, boring

The dashboard is a client of the same public API you get. Zone configuration is a single document, so review and rollback work the way the rest of your infrastructure does.

Base URL
https://api.1boxcdn.com/v2

resource "1boxcdn_zone" "assets" {
  name   = "assets.example.com"
  origin = "https://origin.example.com"
  shield = "FRA"

  cache {
    default_ttl            = 86400
    stale_while_revalidate = 60
    honor_origin_ttl       = true
    key_ignore_query       = ["utm_*", "fbclid"]
  }

  tls {
    min_version  = "1.2"
    hsts_max_age = 31536000
  }

  # Set to 0 to disable image processing
  image_optimizer_quality = 82
}

Pricing

Egress is metered. Features are not.

Every plan gets the whole platform — compute, WAF, image processing, log streaming. Plans differ in committed volume and how fast a human answers you.

Starter
$0 /mo

100 GB egress included, then pay as you go.

  • Unlimited zones and domains
  • Edge functions, 1M invocations
  • Community support
Growth
$49 /mo

5 TB committed egress, $0.009/GB overage.

  • Origin shield and tiered cache
  • Real-time log streaming
  • 99.99% SLA with credits
  • Email support, 4 h first response
Enterprise
Custom

Committed contracts from 100 TB/mo.

  • Dedicated capacity and private PoPs
  • BYOIP and custom BGP communities
  • Named solutions engineer
  • 15 min response, 24×7
Egress regionStarterGrowthEnterprise
North America & Europe$0.012$0.009from $0.004
Asia Pacific$0.024$0.018from $0.008
Middle East & Africa$0.042$0.031from $0.014
South America$0.038$0.028from $0.012
Per GB, billed monthly in arrearsCache-hit requests are not metered

Operations

Questions we get before signing

How is the 99.99% availability measured?

Per PoP, per calendar month, from external probes in the same metro. A PoP counts as unavailable when it fails to return a cache hit for a canary object within 2 s on three consecutive checks. Anycast withdrawal during maintenance is excluded only when announced 72 h ahead on the status page.

What happens when my origin goes down?

Objects within their stale-if-error window keep serving from cache — the default window is 24 h. Beyond that the edge returns your configured fallback response rather than a generic error, and health checks move traffic to the next weighted origin in the group.

Can I bring my own certificates and IP space?

Yes. Upload a certificate and key, or delegate the ACME challenge and renewal happens automatically. BYOIP with your own prefix and BGP communities is available on Enterprise after a routing review.

Where are access logs stored?

Nowhere by default. Streaming logs are forwarded to your sink and held at most 15 minutes in transit buffers. The aggregate counters behind billing and the dashboard retain no client IP addresses or URLs.

How do I report abuse of content served through the network?

Send the URL and a description to abuse@1boxcdn.com. We acknowledge within one business day, forward the complaint to the responsible customer, and act on valid legal orders from the jurisdiction where the content is hosted.

Point a hostname at the edge

One CNAME, no card, 100 GB on the house.