Skip to content
NexCMPNexCMP

Platform

From the BGP edge to the end user

NexCMP combines edge routing and DDoS filtering, CloudStack orchestration, prepaid billing, white-label resellers and a self-service portal in one codebase. It runs in production at vnic.cloud.

How a request — and a packet — moves through the stack

Six layers, one platform

Traffic and billing both flow through the same six layers, top to bottom. Jump to any layer for the full feature list.

Layer 1

Edge network

BGP peering, kernel-level packet filtering and attack detection sit at the network edge, in front of everything else.

  • BGP peering & route policy

    Manage BGP peering and route policy on FRR — route maps, prefix lists, community lists and BFD — from one editor.

  • Manual RTBH blackhole

    Request a BGP blackhole (RTBH) upstream for a single attacked IP, with scope, TTL, and withdraw/extend controls.

  • Automatic RTBH escalation

    When detection and AI analysis confirm a volumetric attack past threshold, an upstream blackhole is requested automatically and withdrawn once the attack ends.

  • Kernel-level XDP filtering

    Line-rate packet filtering in the kernel (XDP), scoped only to protected IPs, with global blocklists and per-source rate limiting.

  • Large-scale IP feed in-kernel

    A large malicious-IP feed (millions of ranges) is enforced directly in the kernel via XDP, so blocking doesn't slow down the rest of the firewall.

  • Public blocklist ingestion

    Established public blocklists such as Spamhaus DROP are ingested automatically and applied network-wide via nftables.

  • Per-IP anomaly detection

    Continuous per-IP traffic baselining with adaptive anomaly detection opens and closes attack events and grades their severity automatically.

  • AI-assisted attack analysis

    AI-assisted analysis reviews a rolling window of traffic and log evidence, and can apply temporary blocking rules automatically when confidence is high.

  • IPv6 /48 auto-protection

    Active IPv6 /48 customer blocks inside announced ranges are discovered and protected automatically, with inactive ones cleaned up automatically too.

  • Real-time alerting

    Attack start/end and other operational events trigger real-time alerts to Telegram, webhook or email.

  • ASN & country blocking

    Block rules can target an entire ASN or country, expanded automatically to the underlying IP ranges from public routing-registry data.

  • Per-IP traffic shaping

    Per-IP bandwidth shaping — guaranteed rate, burst and fair queuing — is built end to end; enforcement on live traffic is being staged.

Layer 2

Customer network

Every VM gets its own public IP and firewall, plus a self-service DDoS Shield that puts the layer-1 edge tooling directly in the customer's hands.

  • Automatic public IPv4

    Every VM receives a public IPv4 address automatically from the address pool, with anti-collision allocation and a cooldown before reuse.

  • 1:1 static NAT

    Each VM gets a dedicated public IP with 1:1 static NAT, so outbound traffic always leaves under the VM's own address.

  • Self-service IPv4 firewall

    Per-VM firewall rules (protocol, port range, source CIDR) are self-managed from the portal, up to 50 rules per VM, open by default at deploy time.

  • Self-service IPv6 firewall

    Per-VM IPv6 firewall rules follow the same self-service model as IPv4, open by default when IPv6 is enabled.

  • One-click IPv6 toggle

    IPv6 can be switched on or off per VM with one click; previous firewall rules are re-applied automatically, with a short cooldown between toggles.

  • One-click IP change

    A VM's public IP can be changed with one click; firewall rules copy to the new address automatically, with a cooldown between changes.

  • Automatic DDoS Shield link

    A VM's public IP is linked to its own DDoS Shield protection automatically as soon as it's assigned — no manual setup.

  • Per-IP DDoS dashboard

    A detailed per-IP page combines traffic charts, live connections, top sources, events and protection settings in one view.

  • Self-service block rules

    Blocking rules — single IP, CIDR, ASN, country — can be added or removed on any protected IP from the portal, with CSV export and bulk delete.

  • Self-service RTBH

    Customers can request a BGP blackhole (RTBH) on an IP under severe attack, and withdraw or extend it themselves, domestic or international scope.

  • Web protection rate limits

    Per-source rate limits (SYN/s, packets/s) and allowed ports blunt application-layer floods, applying immediately with a 10-minute cooldown per IP.

  • Live connections & top sources

    Live connections and top traffic sources — by country, ASN, port — are visible per protected IP, with a one-click block on each row.

  • Attack history & IDS alerts

    Attack history, a per-IP action audit log, and intrusion-detection alerts (Suricata) are all reviewable per protected IP.

Layer 3

Compute & storage

A single scoped CloudStack client drives every VM, volume, backup and snapshot behind a resumable job pipeline.

  • Scoped CloudStack API client

    A single, tightly-scoped CloudStack API client handles every compute, network and storage command — deploy, power actions, scaling, snapshots, volumes, backups, console, IP/firewall — with separate read-write and read-only credentials.

  • Resumable deploy pipeline

    New VMs provision through an automated, resumable pipeline — IP allocation, SSH key setup, instance creation, firewall and NAT — with automatic rollback if a step fails.

  • Full VM lifecycle control

    Start, stop, force-stop, reboot, reinstall, reset password, change IP, toggle IPv6, change billing cycle and delete — each backed by an auditable job.

  • State reconciliation

    A background reconciliation loop keeps platform records in sync with real infrastructure state every few minutes, repairing drifted IP/NAT assignments automatically.

  • Vertical scaling

    Vertical scaling adjusts a running VM's vCPU, RAM and disk in place, manually or automatically by load; horizontal auto-scaling behind a load balancer is intentionally not offered.

  • Attachable data volumes

    Extra data disks attach to a running VM, billed by GB-hour independent of the VM's own storage; detaching keeps the data — and the charge — until deleted.

  • CloudStack-native backups

    VM backups run on CloudStack's native Backup & Recovery engine, billed by actual GB-hour retained, with scheduling and retention handled automatically.

  • VM snapshots

    VM-level snapshots capture and roll back a machine's full state on demand or on a schedule, separate from backup.

  • Browser VNC console

    A browser-based VNC console lets customers and support view and interact with a VM's screen directly, no client software required.

  • Live VM metrics

    Live CPU, memory, network and disk charts per VM are sourced directly from the hypervisor, viewable over 30-minute to 12-hour ranges.

  • Self-updating catalog

    A catalog of VM plans and OS templates stays in sync with the underlying infrastructure, refreshed every 15 minutes.

  • Deposit-based quotas

    Resource limits scale automatically with how much a customer has genuinely deposited, curbing abuse without manual approval steps.

  • Resilient job engine

    A background job engine drives every long-running operation — deploy, scaling, backup, snapshots — with automatic retry, timeout protection and safe recovery after a worker restart.

Layer 4

Billing

An append-only ledger and five payment rails turn infrastructure usage into prepaid, hourly-precise charges.

  • Append-only ledger

    A double-entry, append-only wallet ledger underlies every charge, refund and top-up; balances are always the sum of immutable ledger rows, never a mutable counter.

  • Prepaid wallet

    A prepaid USD wallet with a unified dashboard — balance, deposit history, orders and payment status — in both the web app and the API.

  • Automatic invoicing

    Every charge and top-up generates an invoice automatically, with a printable invoice view.

  • Custom per-resource pricing

    VM plans price precisely per resource — CPU, RAM, disk — instead of fixed tiers only; price drops apply automatically to VMs already running.

  • Stripe

    Card payments (and Alipay) via Stripe, with automatic wallet top-up on low balance, refunds and dispute handling.

  • PayPal

    PayPal Orders v2 in live mode, with server-side capture verification that never trusts a client-reported payment status.

  • USDT (TRC20)

    USDT deposits over Tron/TRC20, reconciled continuously against exchange records and matched to the cent.

  • SePay bank transfer

    Bank transfer top-up for Vietnamese customers via SePay, with auto-generated VietQR codes and an exchange rate locked at order time.

  • Automatic FX rate

    A single, automatically updated USD/VND exchange rate is shared across the platform and every reseller, with guardrails against sudden bad-data rate jumps.

  • Top-up vouchers

    Redeemable top-up voucher codes can be issued to customers or resellers, and by resellers to their own customers, with strict per-site isolation.

  • Affiliate program

    A referral program pays a commission percentage on what referred customers deposit, with a dashboard for clicks, referrals, commissions and payout requests.

Layer 4 · Channels

Resellers & channels

White-label resellers run their own branded storefront, their own wholesale wallet, and their own pricing ladder on the same platform.

  • Multi-tenant by domain

    The main site and every reseller's own domain are served by the same platform, fully isolated by host.

  • Full white-label branding

    Resellers run their own domain with their own logo, colors, landing copy and legal pages — no other branding visible anywhere, including page source.

  • Automatic domain SSL

    Resellers connect their own domain and get automatic SSL issuance and renewal, with no manual certificate management.

  • Wholesale floor, retail ceiling

    Resellers set retail prices above a guaranteed wholesale floor; when list prices change, reseller prices auto-clamp back into the valid range.

  • Wholesale wallet & auto-lock

    Each reseller has a separate wholesale wallet; every retail charge settles the wholesale cost automatically, and customer VMs suspend automatically if the wallet goes past its credit limit.

  • Bring-your-own gateways

    Resellers can plug in their own payment gateway credentials so customer payments settle directly to them, not only to the platform operator.

  • 13-step provisioning wizard

    A one-click admin wizard provisions a fully working white-label reseller in 13 automated steps — account, wallet, pricing, branding, domain, SSL and welcome email.

  • Two-tier operator model

    The platform owner manages the whole system while each reseller gets a scoped console to manage only their own customers.

Layer 5

Portal, admin & API

A self-service portal, an admin console, and a scoped public API sit on top, each guarded by session gating, TOTP and audit logging.

  • Embedded customer portal

    The customer portal is a single-page app compiled straight into the server binary for a fast, self-contained deploy.

  • Updated admin console

    An updated admin console, rolling out alongside the classic one, uses the same session-gated delivery model so operational dashboards are never exposed unauthenticated.

  • Public customer API

    A public REST API for customers is secured by scoped, revocable API keys, with published OpenAPI docs and a key-management console, covering VM lifecycle, read-only billing, SSH keys and DDoS Shield rules.

  • TOTP for staff accounts

    Two-factor authentication — standard authenticator-app TOTP — is available for admin and reseller-staff accounts.

  • Bot verification

    Login and registration are protected by Cloudflare Turnstile bot verification, configurable by the operator.

  • Admin IP allowlisting

    Admin login can be restricted to an allow-listed set of IP ranges, with built-in protection against locking the operator out.

  • Audit trail

    Every administrative action and VM lifecycle event is recorded in an audit trail, with sensitive fields redacted automatically before storage.

  • Transactional email

    Transactional emails for account, billing and VM lifecycle events send through an operator-configured SMTP relay, with a bilingual template library and automatic retry.

  • Web push notifications

    The installable PWA supports push notifications built on standard Web Push (VAPID) with strict endpoint validation.

  • Installable PWA

    The customer portal installs as a Progressive Web App on desktop and mobile, including on white-labeled reseller sites.

  • Site-wide announcements

    Admins and resellers can publish announcements that customers see on their dashboard.

  • Auto-update prompt

    The web app detects new releases automatically and prompts a refresh, keeping everyone on the latest version without a forced reload.

Architecture

How it's built

A deliberately small footprint, not a sprawling microservice stack.

  • Two-process binary

    The platform runs as a single binary with two cooperating processes: one serves the console and customer API, the other runs VM and billing background work.

  • Embedded SQLite

    Storage runs on embedded SQLite rather than a heavyweight external database service — simple to operate at the current scale.

  • Hardened systemd sandboxing

    Backend services run under systemd with hardened sandboxing — restricted filesystem access, no extra Linux capabilities — as standard operational practice. The web process itself is unprivileged; a separate privileged agent validates and applies network changes (nftables, FRR, XDP).

Honesty

What NexCMP doesn't do yet

One production connector today — Apache CloudStack. Everything below is either not built yet, or built but not yet proven in everyday production use.

  • One production connector

    Apache CloudStack is the only production connector today. Proxmox VE, OpenStack, VMware, OpenNebula and zVirt are roadmap connectors (early access / pre-order).

  • Single-node control plane

    One server process pair with embedded SQLite — no high-availability or multi-instance control plane yet.

  • Customer two-factor authentication is planned

    Two-factor authentication for end customers is planned. TOTP already exists today for operator and reseller-staff accounts.

  • Not a WAF

    No TLS inspection or L7 signature engine. DDoS filtering runs on the edge servers you operate — not a global anycast scrubbing network. Attacks larger than your uplink rely on upstream RTBH.

  • A few features are still in beta or roadmap

    Per-IP traffic shaping is beta — built, not yet enforced on live traffic. The desktop app is beta, with no installer published. Bring-your-own-CloudStack for resellers is roadmap.

  • Customer portal languages: English and Vietnamese

    The customer portal UI ships in English and Vietnamese today. (This website also has a Chinese edition — the product UI does not yet.)

  • A young public API

    A public customer API already exists — scoped API keys, published OpenAPI docs — but there are no official SDKs yet.

See where your infrastructure fits

Tell us what you run today and we'll walk through the layers that apply to it.