Gaming & Real-time Video & Streaming E-commerce & Retail Network Pricing Developers FAQ Start free Sign in
312 PoPs · 6 continents · 180 Tbps

Deliver at the edge.
Win the millisecond.

NimbusCDN puts your game patches, live streams and storefronts on an anycast network that terminates, computes and defends in the same hop — so players download faster, viewers stop buffering, and carts stop getting abandoned.

No credit card Live in under 10 minutes SOC 2 Type II · ISO 27001
Global p95 24.3 ms
Cache hit ratio 98.7%
Attack mitigated 4.1 Tbps
◆ Rivenport Games ▲ StreamLoop ● Kestrel Retail ◈ NovaPlay Studios ◇ Meridian Live ■ Hanbok Market ✦ Arcbyte Interactive ◆ Rivenport Games ▲ StreamLoop ● Kestrel Retail ◈ NovaPlay Studios ◇ Meridian Live ■ Hanbok Market ✦ Arcbyte Interactive
312
Points of presence
180 Tbps
Mitigation capacity
99.99%
Contractual uptime SLA
23 ms
Median global RTT
One platform

Four products, one anycast hop

Most stacks bolt a WAF in front of a CDN in front of an origin. NimbusCDN runs delivery, compute, security and media on the same edge node — one TLS termination, one config, one bill.

Content Delivery

Tiered caching with regional shields, origin offload above 98%, instant purge in under 300 ms worldwide.

  • HTTP/3 & QUIC by default
  • Brotli, Zstd, range-aware
  • Surrogate-key invalidation

Edge Compute

Run JavaScript, TypeScript or Wasm within 30 ms of every user. Cold start measured in microseconds.

  • A/B tests & personalization
  • Edge KV & signed tokens
  • Git-based deploys, instant rollback

Edge Security

Always-on L3/L4 scrubbing plus a managed WAF and bot engine that scores requests before they cost you origin.

  • 180 Tbps absorb capacity
  • OWASP Top 10 managed rules
  • Credential-stuffing & scalper bots

Media Services

Ingest once, deliver everywhere: live packaging, per-title encoding, DRM and thumbnails at the edge.

  • LL-HLS & LL-DASH, ~2 s glass-to-glass
  • Widevine, FairPlay, PlayReady
  • AVIF/WebP image pipeline
Built for your workload

Three industries. Three very different definitions of "fast".

A 40 GB patch, a live final, and a Black Friday product page stress completely different parts of a network. We tune the edge per workload instead of shipping one generic config.

Ship a 40 GB patch on launch day without melting your origin

Patch day is a self-inflicted DDoS: millions of clients requesting the same bytes in the same hour. Tiered caching collapses that into a handful of origin fetches, and range-aware delivery keeps resumable downloads saturating the player's link.

Pre-warm before you announce. Push builds to every PoP hours ahead with a single API call.
Anycast UDP for game servers. Matchmaking, lobby and voice traffic ride the same backbone.
Never pay for a leak. Signed URLs and token auth stop CDN-bill farming and asset ripping.
Explore the gaming edge
Launch window · Rivenport Games
98.6%
origin offload at peak
41 min
median full-patch download
2.9 M
concurrent downloaders
0
origin incidents

"We used to schedule patches at 3 a.m. to protect the origin. Now we ship at peak and watch the graph stay flat." — Director of Live Ops

Two-second latency live, without trading away rebuffer ratio

LL-HLS is easy to demo and hard to run at a million concurrents. Our edge packages per-viewer from a single mezzanine ingest, holds partial segments in memory, and degrades a viewer's ladder before it ever stalls.

Just-in-time packaging. One ingest, every format — HLS, DASH, CMAF — no storage fan-out.
Per-title encoding. Same perceptual quality at 22–38% fewer bits on typical catalogues.
Studio-grade protection. Multi-DRM, forensic watermarking and concurrent-stream limits.
Explore video delivery
Championship final · Meridian Live
2.1 s
glass-to-glass latency
0.19%
rebuffer ratio
1.4 M
peak concurrent viewers
31%
egress saved vs. fixed ladder

"Chat was ahead of the stream on our old CDN. That complaint disappeared the week we cut over." — VP Engineering

Hold sub-second LCP through the flash sale, bots included

Peak traffic and peak fraud arrive together. We cache the personalized page at the edge, serve the right image format per device, and price out the scalpers before a request ever reaches your checkout service.

Cache the uncacheable. Edge Side Includes and surrogate keys cache logged-in pages safely.
Images, automatically. AVIF/WebP, device-aware resizing, LQIP — no build step.
Waiting room built in. Fair queueing keeps the store up instead of showing a 503.
Explore commerce delivery
Peak sale weekend · Kestrel Retail
0.84 s
p75 LCP at peak
+12.4%
conversion vs. prior year
61%
image bytes removed
8.9 M
bot requests blocked

"The sneaker drop stayed up and the resale listings didn't appear for three days. That's the whole story." — Head of Digital

Measured, not claimed

The p95 is the number that hurts

Averages flatter every CDN. We publish the tail: 95th-percentile time to first byte from 1,400 independent RUM vantage points, sampled continuously across all six regions.

Third-party RUM, 30-day rolling window, unfiltered
Identical 128 KB payload, cold and warm cache both counted
Raw dataset available under NDA during evaluation
See the full network map
p95 TTFB by region
lower is better
North America18 ms
Industry median47 ms

Europe21 ms
Industry median52 ms

Asia-Pacific29 ms
Industry median71 ms

Sample: 4.2 B requests, 1 Aug – 30 Aug 2026. Figures are illustrative placeholders for this design.

Security at the edge

The fastest request is the one that never reaches your origin

Every NimbusCDN PoP is also a scrubbing centre. Filtering happens where the traffic lands, so mitigation adds no detour and no extra RTT.

Always-on DDoS

Volumetric, protocol and application floods absorbed at 180 Tbps. No redirect, no BGP swing, no "attack mode" you have to remember to enable.

L3 / L4L7UDP game traffic

Managed WAF

OWASP Top 10 rulesets maintained by our threat team, virtual patching for new CVEs, and your own rules in a readable expression language.

Zero-day virtual patchCustom rules

Bot & abuse control

Behavioural scoring separates a scalper from a shopper and a cheat client from a player — challenge, tarpit, or drop, per route.

Scalper defenseCredential stuffingScraping
Developer first

Configuration that lives in your repo

Everything in the dashboard is an API call, and every API call has a Terraform resource. Version your edge the same way you version your app — with review, staging and one-command rollback.

Terraform & Pulumi providers
Staged configs with diff preview
Real-time log streaming
SDKs for Go, Node, Python, Rust
edge/patch-day.ts
// Serve game patches with range-aware caching + token auth.
import { edge, cache, auth } from "@nimbuscdn/edge";

export default edge.handler(async (req, ctx) => {
  const token = await auth.verify(req, { ttl: 900 });
  if (!token.valid) return new Response("forbidden", { status: 403 });

  return ctx.fetch(req, {
    cache: cache.tiered({
      shield:       "auto",       // nearest regional shield
      ttl:          "30d",
      surrogateKey: [`build:${ctx.params.build}`],
      ranges:       true,         // resumable downloads
    }),
  });
});

// Invalidate every PoP for one build in <300ms:
//   nimbus purge --key build:2026.9.1
Observability

Know what the edge did, one second later

Not a five-minute-delayed rollup. Per-request logs stream to your SIEM or object store in real time, and the dashboard queries the same pipeline.

1 s
log delivery latency

Stream to Splunk, Datadog, S3, GCS, Kafka or an HTTPS endpoint.

100%
request sampling

No 1-in-1000 sampling. Every request, every field, retained 30 days.

40+
alertable metrics

Hit ratio, origin health, WAF verdicts, latency percentiles per PoP.

24/7
humans on call

Enterprise plans get a named TAM and a 15-minute P1 response SLA.

Pricing

Pay for bandwidth. Not for surprises.

No charge for TLS, HTTP/3, DDoS mitigation, purges or requests. Commit to volume and the rate drops — that's the whole model.

Free while you build

1 TB of egress and 10 M requests every month, forever. Full WAF and edge functions included.

Regional rates, published

From $0.012/GB in North America and Europe. Every published region's rate is on the pricing page, not behind a form — mainland China is quoted on an Enterprise plan.

No egress cliff

Overage bills at your committed rate. A viral week costs more bandwidth, not a renegotiation.

FAQ

Questions we get in every evaluation

For a straightforward site: change a CNAME and you are live in under ten minutes. For a large media or gaming estate we run a staged cutover — 1% of traffic, then 10%, then 50% — with a side-by-side RUM comparison at every step, so you roll forward on evidence rather than faith. Most enterprise migrations complete inside two weeks, and we do the config translation from your current vendor.

Yes, and we recommend it for anything revenue-critical. Multi-CDN is a first-class setup here: use your own traffic manager, or ours, to split by region, performance or weight. Our real-time logs export in a format your existing steering layer can consume on day one.

Unmetered on every plan, including the free Developer tier. Attack traffic is not billed as egress and there is no surge fee for being targeted. We would rather you leave protection on permanently than switch it on after the outage has already started.

SOC 2 Type II, ISO 27001 and ISO 27018, PCI DSS Level 1 for the delivery path, and GDPR-aligned processing with a standard DPA and EU/UK data residency options. Studio-grade content protection is certified for multi-DRM workflows. Reports are available under NDA.

Through licensed in-country partner capacity, with ICP filing assistance included in the onboarding. It is configured as a region in the same dashboard and reported in the same logs, so you do not end up running a second, separate CDN operation just for one market.

Put your first terabyte on the edge tonight

Free tier, no card, no sales call. Or bring us a p95 number you are unhappy with and we will benchmark against it.