Key takeaways
- Critical services your users can reach and nobody else can even see. Anapaya PathGuard makes applications accessible to approved users without exposing them to everyone else on the Internet.
- No authorization. No path. No access. Unauthorized users don't get the routing information they need to reach the application in the first place.
- Keep your security stack. Add another layer underneath it. Anapaya PathGuard works alongside your existing firewalls, DDoS protection, authentication, and other security solutions. Nothing needs to be replaced.
- Know your users? Then it could be a fit. Anapaya PathGuard is designed for applications and services where the users are known in advance. E-banking, remote access and payment infrastructure are good examples. A public website isn't.
What does controlled reachability mean?
Controlled reachability means that a critical application or service is reachable only by authorized users without exposing the protected application to the public Internet. With Anapaya PathGuard, authenticated users get the path information to reach the application on the SCION Internet. Unauthorized users get no route at all: no path, no access.
So what does a typical work day look like nowadays? Before the day has even properly begun, many of us have already logged into a service sitting on the public Internet several times. We connect to the company VPN on the commute to work or from home, order lunch through an app, check our bank account, pay a bill and – for those getting away from a screen for a stint – sync a smartwatch before heading out for a run. Each interaction feels routine, even smart. A username, a password, perhaps a two-factor authentication: and we are in. Check.
But there is something we tend not to think about: every service reachable from anywhere on the Internet can be discovered, targeted and attacked.
Cybercriminals scan the Internet constantly (now leveraging AI tools), hunting for exactly this kind of exposed service: VPN gateways, banking backends, IoT endpoints, anything reachable that might also be breakable.
Anapaya PathGuard makes services and applications reachable only by approved users – protecting them so that customers and employees can access safely, while hackers cannot even see them. Today, with Anapaya PathGuard, digital applications and web services don't have to be Internet-facing anymore.
Why are applications becoming harder to secure?
For decades, the answer against Internet-wide scanning of applications and web services has been to build security around them, otherwise known as damage control. As cyberattacks become increasingly automated and scalable, the default reachability on the public Internet of critical applications creates unnecessary risk. Organizations face several challenges at once:
- Escalating attack volume: The number of DDoS attacks and zero-day exploits is growing rapidly. In the first half of 2026, a +519% quarter-over-quarter increase between Q1 and Q2 of network-layer DDoS attacks was detected.
- Asymmetric arms race: Current defensive approaches are inherently reactive. This reactive model creates an asymmetric arms race: attackers need only find a single vulnerability, while defenders must correctly classify every packet, request, and connection at scale: in real-time, without false positives.
- Concentration risk and vendor complexity: To defend a web service, enterprises typically layer multiple security products. Each adds operational complexity, costs, and a potential point of failure. Worse, many of these solutions combine all network security into a single vendor's cloud, creating concentration risk.
- Compliance and data sovereignty: Regulated industries face increasing requirements around data sovereignty, geofencing, and audit trails for network access. Traditional Internet architectures provide limited control over routing paths, making it difficult to guarantee that traffic stays within approved jurisdictions or that access can be cryptographically attributed to specific authorized entities.
Overlay security solutions can control who is allowed into an application, but their Internet-facing gateways and infrastructure can themselves become part of the attack surface. For critical services, the safest attack surface is one unauthorized users cannot reach.
Online doesn't have to mean Internet-facing
Think of an e-banking application that customers can access normally, but which an unauthorized user cannot discover or reach. Or better still: a corporate VPN that employees can connect to from home, while an attacker scanning the Internet cannot even find, much less target. This is the main intent behind developing Anapaya PathGuard operating on the SCION Internet: making services and applications reachable only by approved users and invisible to anyone else.
SCION (Scalability, Control, and Isolation on Next-generation Networks) is a network technology that enables enterprises to create trusted networks with selected, approved participants, built on clear governance.
Anapaya PathGuard changes from default public reachability to controlled reachability: from your application being visible to billions of users on the public Internet, to millions with Anapaya GATE, to only pre-selected, authorized users with Anapaya PathGuard on the SCION Internet.

This is made possible by the fact that Anapaya PathGuard extends SCION natively to the end user's browser, app, and device, and hides the enterprise service behind paths that are inaccessible to unauthorized users. The service is de facto invisible on both the public Internet and the SCION Internet (unless you are allowed to see it).
Together with our CTO, Sam, I will explain the mechanics behind it in our webinar, "Every exposed service is a target: A new approach to protecting critical access with Anapaya PathGuard," on November 10 and 12.
How to protect an application with Anapaya PathGuard?
Enterprises can deploy Anapaya PathGuard by following three steps:
- Choosing the application. The enterprise places the selected application behind Anapaya EDGE on premises or cloud with an integration of a PathGuard Gateway. The application is now on the SCION Internet, but its path information is hidden from unauthorized users thanks to the Hidden Path Service (HPS).
- Authenticating the user. Approved remote users connect through a PathGuard Client. Once a user is authenticated, they obtain the path information required to reach the protected application.
- Establishing the protected path. User traffic enters the SCION Internet through a SNAP. On the SCION Internet, the traffic reaches the application using path information made available by the HPS to authorized users only.

The biggest difference with Anapaya PathGuard happens before the traffic reaches the application: unauthorized users do not receive the routing information needed to establish a path to the protected service.
The idea is simple: No authorization. No path. No access.
That means an attacker cannot simply discover the application's IP address and start scanning or sending traffic to it. For unauthorized users, there is simply no route to the application.
How is Anapaya PathGuard different from other solutions?
Most security solutions start working once traffic is already able to reach your infrastructure. Firewalls filter it. DDoS protection identifies and mitigates malicious traffic. Intrusion detection systems analyze it. Authentication systems determine whether a user should ultimately receive access.
Anapaya PathGuard operates one layer beneath all that: it decides whether traffic can reach the protected service in the first place. For services that have a known user base, this means that they can’t be subject to Internet-wide scanning.
Rather than seeing who can detect and respond to malicious traffic faster, organizations can remove an important part of the attacker's opportunity: the ability to reach the target from the get-go.
Anapaya PathGuard adds to the existing security stack. Nothing gets replaced.
The advantages of Anapaya PathGuard for enterprises
With Anapaya PathGuard, enterprises can:
- Increase security: Only approved users can reach the protected service. This removes the service from Internet-wide scanning and reduces the risk of volumetric DDoS attacks.
- Control sovereignty: Choose network providers and avoid paths or jurisdictions that do not meet compliance.
- Simplify secure access: Support browser, client and VPN access while integrating with enterprise identity.
- Improve resilience: SCION multipath and fast failover support continuity during network degradation or provider outages.
For organizations operating critical applications, that means security, resilience, and sovereignty can be addressed at the network layer rather than treated as separate problems.
Which applications can be protected with Anapaya PathGuard?
Any application or service with a known user base is a potential use case for Anapaya PathGuard. Here are the top three:
- E-banking: Good news for banks that want customers to access e-banking from anywhere while reducing the application's exposure to DDoS attacks, scanning, and other cyber threats.
- Remote access: An enterprise needs employees to access internal corporate services from home or while travelling. Instead of exposing its VPN gateway through a public IP address on the Internet, the VPN infrastructure is invisible. Authorized employees authenticate using the organization's existing identity provider and receive access to the hidden path leading to the VPN gateway.
- Payment gateway: Payment providers need a backend processing infrastructure to remain continuously available to authorized merchants, applications, and payment systems. By integrating SCION connectivity into payment applications, payment infrastructure can remain reachable to authorized participants without exposing the protected backend directly to the public Internet.
A public website with unknown users, on the other hand, is a use case for Anapaya GATE.
From protecting public reachability to controlling reachability
The Internet was designed around reachability, which is – in itself – a good thing. But, in a beautiful example of a catch 22, if a service is on the Internet, it can be scanned, targeted and attacked.
Cybersecurity has spent decades building increasingly sophisticated and reactive defenses around that model. Anapaya PathGuard introduces another possibility by shifting the paradigm.
Don't make every critical service reachable by everyone and then decide who gets in. Decide who should be able to reach the service in the first place.
For employees, customers, partners, applications, and devices that are authorized, the service remains digital, remote, and accessible. For everyone else, there is simply no path.
That is what we mean by invisibility to unauthorized users.
Ok, so for the final task of the day – smart watch on, let’s go check our sleep patterns and make sure we’re getting a good night’s rest.
Frequently Asked Questions
Can users access an application that isn't exposed to the public Internet?
Does Anapaya PathGuard replace VPNs?
How does Anapaya PathGuard reduce DDoS exposure?
Can Anapaya PathGuard protect against AI-powered cyberattacks?
What types of applications can use Anapaya PathGuard?
Is Anapaya PathGuard a ZTNA alternative?