Platform
From the BGP edge to the end user
NexCMP combines edge routing and DDoS filtering, CloudStack orchestration, prepaid billing, white-label resellers and a self-service portal in one codebase. It runs in production at vnic.cloud.
How a request — and a packet — moves through the stack
Six layers, one platform
Traffic and billing both flow through the same six layers, top to bottom. Jump to any layer for the full feature list.
Layer 1
Edge network
BGP peering, kernel-level packet filtering and attack detection sit at the network edge, in front of everything else.
BGP peering & route policy
Manage BGP peering and route policy on FRR — route maps, prefix lists, community lists and BFD — from one editor.
Manual RTBH blackhole
Request a BGP blackhole (RTBH) upstream for a single attacked IP, with scope, TTL, and withdraw/extend controls.
Automatic RTBH escalation
When detection and AI analysis confirm a volumetric attack past threshold, an upstream blackhole is requested automatically and withdrawn once the attack ends.
Kernel-level XDP filtering
Line-rate packet filtering in the kernel (XDP), scoped only to protected IPs, with global blocklists and per-source rate limiting.
Large-scale IP feed in-kernel
A large malicious-IP feed (millions of ranges) is enforced directly in the kernel via XDP, so blocking doesn't slow down the rest of the firewall.
Public blocklist ingestion
Established public blocklists such as Spamhaus DROP are ingested automatically and applied network-wide via nftables.
Per-IP anomaly detection
Continuous per-IP traffic baselining with adaptive anomaly detection opens and closes attack events and grades their severity automatically.
AI-assisted attack analysis
AI-assisted analysis reviews a rolling window of traffic and log evidence, and can apply temporary blocking rules automatically when confidence is high.
IPv6 /48 auto-protection
Active IPv6 /48 customer blocks inside announced ranges are discovered and protected automatically, with inactive ones cleaned up automatically too.
Real-time alerting
Attack start/end and other operational events trigger real-time alerts to Telegram, webhook or email.
ASN & country blocking
Block rules can target an entire ASN or country, expanded automatically to the underlying IP ranges from public routing-registry data.
Per-IP traffic shaping
Per-IP bandwidth shaping — guaranteed rate, burst and fair queuing — is built end to end; enforcement on live traffic is being staged.
Layer 2
Customer network
Every VM gets its own public IP and firewall, plus a self-service DDoS Shield that puts the layer-1 edge tooling directly in the customer's hands.
Automatic public IPv4
Every VM receives a public IPv4 address automatically from the address pool, with anti-collision allocation and a cooldown before reuse.
1:1 static NAT
Each VM gets a dedicated public IP with 1:1 static NAT, so outbound traffic always leaves under the VM's own address.
Self-service IPv4 firewall
Per-VM firewall rules (protocol, port range, source CIDR) are self-managed from the portal, up to 50 rules per VM, open by default at deploy time.
Self-service IPv6 firewall
Per-VM IPv6 firewall rules follow the same self-service model as IPv4, open by default when IPv6 is enabled.
One-click IPv6 toggle
IPv6 can be switched on or off per VM with one click; previous firewall rules are re-applied automatically, with a short cooldown between toggles.
One-click IP change
A VM's public IP can be changed with one click; firewall rules copy to the new address automatically, with a cooldown between changes.
Automatic DDoS Shield link
A VM's public IP is linked to its own DDoS Shield protection automatically as soon as it's assigned — no manual setup.
Per-IP DDoS dashboard
A detailed per-IP page combines traffic charts, live connections, top sources, events and protection settings in one view.
Self-service block rules
Blocking rules — single IP, CIDR, ASN, country — can be added or removed on any protected IP from the portal, with CSV export and bulk delete.
Self-service RTBH
Customers can request a BGP blackhole (RTBH) on an IP under severe attack, and withdraw or extend it themselves, domestic or international scope.
Web protection rate limits
Per-source rate limits (SYN/s, packets/s) and allowed ports blunt application-layer floods, applying immediately with a 10-minute cooldown per IP.
Live connections & top sources
Live connections and top traffic sources — by country, ASN, port — are visible per protected IP, with a one-click block on each row.
Attack history & IDS alerts
Attack history, a per-IP action audit log, and intrusion-detection alerts (Suricata) are all reviewable per protected IP.
Layer 3
Compute & storage
A single scoped CloudStack client drives every VM, volume, backup and snapshot behind a resumable job pipeline.
Scoped CloudStack API client
A single, tightly-scoped CloudStack API client handles every compute, network and storage command — deploy, power actions, scaling, snapshots, volumes, backups, console, IP/firewall — with separate read-write and read-only credentials.
Resumable deploy pipeline
New VMs provision through an automated, resumable pipeline — IP allocation, SSH key setup, instance creation, firewall and NAT — with automatic rollback if a step fails.
Full VM lifecycle control
Start, stop, force-stop, reboot, reinstall, reset password, change IP, toggle IPv6, change billing cycle and delete — each backed by an auditable job.
State reconciliation
A background reconciliation loop keeps platform records in sync with real infrastructure state every few minutes, repairing drifted IP/NAT assignments automatically.
Vertical scaling
Vertical scaling adjusts a running VM's vCPU, RAM and disk in place, manually or automatically by load; horizontal auto-scaling behind a load balancer is intentionally not offered.
Attachable data volumes
Extra data disks attach to a running VM, billed by GB-hour independent of the VM's own storage; detaching keeps the data — and the charge — until deleted.
CloudStack-native backups
VM backups run on CloudStack's native Backup & Recovery engine, billed by actual GB-hour retained, with scheduling and retention handled automatically.
VM snapshots
VM-level snapshots capture and roll back a machine's full state on demand or on a schedule, separate from backup.
Browser VNC console
A browser-based VNC console lets customers and support view and interact with a VM's screen directly, no client software required.
Live VM metrics
Live CPU, memory, network and disk charts per VM are sourced directly from the hypervisor, viewable over 30-minute to 12-hour ranges.
Self-updating catalog
A catalog of VM plans and OS templates stays in sync with the underlying infrastructure, refreshed every 15 minutes.
Deposit-based quotas
Resource limits scale automatically with how much a customer has genuinely deposited, curbing abuse without manual approval steps.
Resilient job engine
A background job engine drives every long-running operation — deploy, scaling, backup, snapshots — with automatic retry, timeout protection and safe recovery after a worker restart.
Layer 4
Billing
An append-only ledger and five payment rails turn infrastructure usage into prepaid, hourly-precise charges.
Append-only ledger
A double-entry, append-only wallet ledger underlies every charge, refund and top-up; balances are always the sum of immutable ledger rows, never a mutable counter.
Prepaid wallet
A prepaid USD wallet with a unified dashboard — balance, deposit history, orders and payment status — in both the web app and the API.
Automatic invoicing
Every charge and top-up generates an invoice automatically, with a printable invoice view.
Custom per-resource pricing
VM plans price precisely per resource — CPU, RAM, disk — instead of fixed tiers only; price drops apply automatically to VMs already running.
Stripe
Card payments (and Alipay) via Stripe, with automatic wallet top-up on low balance, refunds and dispute handling.
PayPal
PayPal Orders v2 in live mode, with server-side capture verification that never trusts a client-reported payment status.
USDT (TRC20)
USDT deposits over Tron/TRC20, reconciled continuously against exchange records and matched to the cent.
SePay bank transfer
Bank transfer top-up for Vietnamese customers via SePay, with auto-generated VietQR codes and an exchange rate locked at order time.
Automatic FX rate
A single, automatically updated USD/VND exchange rate is shared across the platform and every reseller, with guardrails against sudden bad-data rate jumps.
Top-up vouchers
Redeemable top-up voucher codes can be issued to customers or resellers, and by resellers to their own customers, with strict per-site isolation.
Affiliate program
A referral program pays a commission percentage on what referred customers deposit, with a dashboard for clicks, referrals, commissions and payout requests.
Layer 4 · Channels
Resellers & channels
White-label resellers run their own branded storefront, their own wholesale wallet, and their own pricing ladder on the same platform.
Multi-tenant by domain
The main site and every reseller's own domain are served by the same platform, fully isolated by host.
Full white-label branding
Resellers run their own domain with their own logo, colors, landing copy and legal pages — no other branding visible anywhere, including page source.
Automatic domain SSL
Resellers connect their own domain and get automatic SSL issuance and renewal, with no manual certificate management.
Wholesale floor, retail ceiling
Resellers set retail prices above a guaranteed wholesale floor; when list prices change, reseller prices auto-clamp back into the valid range.
Wholesale wallet & auto-lock
Each reseller has a separate wholesale wallet; every retail charge settles the wholesale cost automatically, and customer VMs suspend automatically if the wallet goes past its credit limit.
Bring-your-own gateways
Resellers can plug in their own payment gateway credentials so customer payments settle directly to them, not only to the platform operator.
13-step provisioning wizard
A one-click admin wizard provisions a fully working white-label reseller in 13 automated steps — account, wallet, pricing, branding, domain, SSL and welcome email.
Two-tier operator model
The platform owner manages the whole system while each reseller gets a scoped console to manage only their own customers.
Layer 5
Portal, admin & API
A self-service portal, an admin console, and a scoped public API sit on top, each guarded by session gating, TOTP and audit logging.
Embedded customer portal
The customer portal is a single-page app compiled straight into the server binary for a fast, self-contained deploy.
Updated admin console
An updated admin console, rolling out alongside the classic one, uses the same session-gated delivery model so operational dashboards are never exposed unauthenticated.
Public customer API
A public REST API for customers is secured by scoped, revocable API keys, with published OpenAPI docs and a key-management console, covering VM lifecycle, read-only billing, SSH keys and DDoS Shield rules.
TOTP for staff accounts
Two-factor authentication — standard authenticator-app TOTP — is available for admin and reseller-staff accounts.
Bot verification
Login and registration are protected by Cloudflare Turnstile bot verification, configurable by the operator.
Admin IP allowlisting
Admin login can be restricted to an allow-listed set of IP ranges, with built-in protection against locking the operator out.
Audit trail
Every administrative action and VM lifecycle event is recorded in an audit trail, with sensitive fields redacted automatically before storage.
Transactional email
Transactional emails for account, billing and VM lifecycle events send through an operator-configured SMTP relay, with a bilingual template library and automatic retry.
Web push notifications
The installable PWA supports push notifications built on standard Web Push (VAPID) with strict endpoint validation.
Installable PWA
The customer portal installs as a Progressive Web App on desktop and mobile, including on white-labeled reseller sites.
Site-wide announcements
Admins and resellers can publish announcements that customers see on their dashboard.
Auto-update prompt
The web app detects new releases automatically and prompts a refresh, keeping everyone on the latest version without a forced reload.
Architecture
How it's built
A deliberately small footprint, not a sprawling microservice stack.
Two-process binary
The platform runs as a single binary with two cooperating processes: one serves the console and customer API, the other runs VM and billing background work.
Embedded SQLite
Storage runs on embedded SQLite rather than a heavyweight external database service — simple to operate at the current scale.
Hardened systemd sandboxing
Backend services run under systemd with hardened sandboxing — restricted filesystem access, no extra Linux capabilities — as standard operational practice. The web process itself is unprivileged; a separate privileged agent validates and applies network changes (nftables, FRR, XDP).
Honesty
What NexCMP doesn't do yet
One production connector today — Apache CloudStack. Everything below is either not built yet, or built but not yet proven in everyday production use.
One production connector
Apache CloudStack is the only production connector today. Proxmox VE, OpenStack, VMware, OpenNebula and zVirt are roadmap connectors (early access / pre-order).
Single-node control plane
One server process pair with embedded SQLite — no high-availability or multi-instance control plane yet.
Customer two-factor authentication is planned
Two-factor authentication for end customers is planned. TOTP already exists today for operator and reseller-staff accounts.
Not a WAF
No TLS inspection or L7 signature engine. DDoS filtering runs on the edge servers you operate — not a global anycast scrubbing network. Attacks larger than your uplink rely on upstream RTBH.
A few features are still in beta or roadmap
Per-IP traffic shaping is beta — built, not yet enforced on live traffic. The desktop app is beta, with no installer published. Bring-your-own-CloudStack for resellers is roadmap.
Customer portal languages: English and Vietnamese
The customer portal UI ships in English and Vietnamese today. (This website also has a Chinese edition — the product UI does not yet.)
A young public API
A public customer API already exists — scoped API keys, published OpenAPI docs — but there are no official SDKs yet.
See where your infrastructure fits
Tell us what you run today and we'll walk through the layers that apply to it.