CloudPe has moved its DDoS protection to Cloudflare Magic Transit, giving customers stronger security and lower latency at the same time.
CloudPe has upgraded the DDoS protection across its infrastructure to Cloudflare Magic Transit. The result is a network that stops attacks closer to where they start and sends clean traffic to CloudPe data centres faster than before.
Why CloudPe made the change
Earlier, protection at the BOM2 data centre ran through HyperFilter in Germany. At the BOM3 data centre, it ran through Voxility in Singapore. Both caught attacks reliably.
But this resulted in latency climbing around 100ms. So CloudPe ran the protection passively. Traffic flowed directly under normal conditions, and the scrubbing only switched on once an attack was detected. It worked, but it was reactive by design. There was always a gap between the first malicious packet and the moment defences came up.
Cloudflare Magic Transit removes this compromise. It operates in more than 700 locations across 300 cities, including India, so filtering happens right where the traffic starts instead of halfway around the world. Latency drops to near zero (around 2ms), keeping the DDoS active all the time.
Customers get a secure network that filters attacks and keeps latency low at the same time, rather than trading one for the other.
As businesses scale their critical cloud, GPU, and AI workloads across India, security can never be an afterthought. Our investment in DDoS protection is part of our continued effort to build infrastructure that businesses can rely on. By upgrading to Cloudflare, we are shifting from a reactive posture to proactive defense without compromising on network performance or cost efficiency. Our commitment is to provide a resilient, high-availability cloud ecosystem that our customers can trust at every stage of their growth.
~ Ishan Talathi, Founder & CEO
How Cloudflare’s secure network filters attacks
Cloudflare now advertises CloudPe’s IP prefixes from its global Anycast network using the Border Gateway Protocol (BGP). In practice, that means Internet traffic heading to these prefixes is guided to Cloudflare first. Here is what happens next:
- All inbound Internet traffic destined for these prefixes first reaches the nearest Cloudflare data centre.
- Cloudflare continuously inspects and analyses incoming traffic in real time.
- Malicious traffic such as volumetric DDoS attacks, SYN floods, UDP floods, amplification attacks, and Layer 3 and Layer 4 attacks are automatically detected and mitigated within Cloudflare’s network.
- Only clean, legitimate traffic is forwarded to CloudPe’s data centres over secure GRE/IPsec tunnels.
- This prevents malicious traffic from reaching CloudPe’s upstream providers and infrastructure. Overall network stability and availability improve, even during an active attack.
What this means for CloudPe customers
The upgrade delivers two wins that usually pull against each other:
- Security goes up: Attacks are detected and stopped inside Cloudflare’s network before they ever reach CloudPe infrastructure. Upstream providers stay protected, and services stay available even while an attack is in progress.
- Latency goes down: Filtering now happens in India, close to the source of traffic, instead of thousands of kilometres away in Germany or Singapore. Legitimate users reach CloudPe services faster.
The bottom line
CloudPe has always backed its performance with numbers, running 40% faster and up to 60% more effectively than hyperscalers. This upgrade adds another layer to that story.
Stronger protection. Better uptime. DDoS always on. That is the result of moving DDoS protection to Cloudflare Magic Transit, and it is live across CloudPe infrastructure now.