Infrastructure

Infrastructure behind Titan

The production foundation behind Titan's security systems — networking, monitoring, DDoS mitigation and self-hosted platforms.

0

Infrastructure nodes

0%

Monitoring coverage

0.0%

Availability target

0

Active projects

Data center

Production footprint at Firstcolo FRA4, Frankfurt

Our servers and network equipment are housed in Firstcolo FRA4 in Frankfurt am Main, one of the most important internet hubs in Europe.

Firstcolo FRA4 provides a controlled environment for our production and development systems. Redundant power, managed cooling and physical access control are the baseline we build availability guarantees on top of.

The facility is monitored continuously and access is restricted to authorized personnel. Professional facility management lets our team focus on the systems themselves, while physical infrastructure is handled by an experienced data center operator.

Frankfurt location

Hosting in Frankfurt, next to Europe's largest peering hub, keeps latency low for communities across Europe.

Redundant power

UPS units and diesel generators keep our systems online through grid failures.

Physical security

24/7 on-site security, access control and CCTV protect our racks against unauthorized access.

Connectivity

Redundant backbone uplinks and peering with major providers keep our network fast and stable.

Engineering capabilities

What running our own infrastructure means

We do not rent a black box. These are the layers we design, operate and are accountable for — each one a deliberate engineering decision that supports our security mission.

Own infrastructure

Compute, storage and networking we operate ourselves — no reseller between us and the metal.

BGP routing

Routing is coordinated with our upstream over BGP today; announcing our own prefixes follows once the AS is assigned.

Autonomous System

We have applied for a dedicated ASN, which will give us an independent presence on the global routing table.

IPv4 space

Addresses are assigned to services under a documented addressing plan, with our own ranges to follow alongside the AS.

IPv6 native

IPv6 is first-class across our network, not an afterthought bolted onto v4.

DDoS mitigation

Volumetric traffic is scrubbed at the edge before it reaches production, keeping services reachable under attack.

Monitoring

Metrics, logs and alerting across every node, so we see problems before users do.

Automation

Infrastructure is provisioned and configured as code — reproducible, reviewed and version-controlled.

Security

Hardened hosts, least-privilege access and network segmentation are the default, not an upgrade.

Data center

Equipment housed in Firstcolo FRA4, Frankfurt, with redundant power, cooling and physical access control.

High availability

Redundancy at the power, network and service layers keeps critical systems online through failures.

Self-hosted services

The tooling we run day to day is self-hosted, keeping data and dependencies under our control.

Architecture

How traffic flows through our network

A simplified view of the path a request takes — from the public internet, through our edge and mitigation layer, to the services that run our products.

01

Internet

Public traffic reaching the addresses our services run on.

02

Edge & routing

Our routers terminate uplinks and steer ingress; own BGP announcements follow with the AS.

03

DDoS mitigation

Volumetric and protocol attacks are scrubbed at the edge.

04

Core network

Segmented, redundant switching between edge and compute.

05

Compute nodes

Redundant hosts in Firstcolo FRA4 running our workloads.

06

Services

Titan Security systems, Titan AC, CFX Resolver and internal platforms.

Simplified topology. Redundant paths and internal segmentation are omitted for clarity.

Own network — in preparation

We are building our own autonomous system

Our own AS will give us direct control over how traffic reaches our systems and how it is defended. The application is in progress.

We have applied for our own autonomous system (ASN), which will put routing decisions in our hands rather than a provider's. It enables direct peering, faster response to upstream incidents and more effective mitigation of DDoS traffic before it reaches production.

The AS is a long-term investment in independence and resilience: we will not be tied to a single transit provider, and we can scale capacity deliberately as demand on our systems grows. Until it is assigned, our production traffic is routed through our upstream provider.

ASN

In preparation

IPv4 range

In preparation

IPv6 range

In preparation

Peering

On request

Work with us

Whether you operate a community, represent a partner organization, or want to contribute as a member of the association — we would like to hear from you.