> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Cloud Shield

> Protect Cloud CDN applications, investigate security events, and manage application security policies.

Cloud Shield adds application protection to an existing Cloud CDN distribution. Protected domains, rules, investigations, and access controls belong to the selected project. Your organization's plan and add-ons determine which controls are available.

<CardGroup cols={2}>
  <Card title="Protect an application" icon="rocket" href="/cloud-shield/quickstart">Attach a distribution and verify protection.</Card>
  <Card title="Manage protection" icon="list-filter" href="/cloud-shield/policies-and-rules">Configure managed policies, exceptions, and traffic rules.</Card>
  <Card title="Investigate traffic" icon="activity" href="/cloud-shield/investigations">Review events, attack activity, IP reputation, and insights.</Card>
  <Card title="Operate your workspace" icon="settings" href="/cloud-shield/workspace">Manage response pages, access, audit events, usage, and exports.</Card>
</CardGroup>

## Product boundaries

| Control | Where you manage it |
| - | - |
| Application protection and security events | Cloud Shield |
| Hostnames, DNS target, visitor TLS, origin TLS | Linked Cloud CDN distribution |
| Certificate inventory and imported certificates | TLS Manager |
| An additional cache between delivery edges and your origin | Cloud CDN Origin Shield |
| Subscription, renewal, and invoices | Organization billing |

Cloud Shield and [Origin Shield](/cloud-cdn/origin-shield) are separate features with separate configuration and billing.

## Plans and entitlements

The service reports your current limits through `GET /shield/service`. Domain and rule limits apply across the organization's projects. Basic supports managed protection; Advanced and Business also support custom and IP firewall rules. Advanced rules and bot management require eligible add-ons. API security, advanced threat intelligence, SIEM integration, access control, and audit logs require their corresponding Business add-ons.

Review the current plan and available controls in **Billing → Subscription**. A visible navigation item does not mean its add-on is active. Contact support to enable an eligible add-on.

## Automation

The public API prefix is `/shield`; the Management Console uses `/cloud-shield` for its pages. Use project-scoped credentials and the [Cloud Shield API guide](/cloud-shield/api) when automating protection.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.