Local end to end

CNX keeps DNS resolution, content delivery, and certificate trust for Cambodia-hosted mobile services on a domestic path — with hardware-attested access and sealed compute for what needs to go further.


Most Cambodia-hosted services still route through foreign infrastructure by default — not by necessity. DNS sits on a foreign registrar's nameservers; the application itself is served through a global CDN's edge network. Neither is unusual — it's the default path most platforms end up on. But it means a user in Phnom Penh, reaching a service hosted in Cambodia, leaves the country twice before a page loads: once to resolve the name, once to fetch the content. Every one of those crossings is exposure to congestion or an outage on a link nobody at CNX or the customer controls — congestion on a regional subsea cable shows up to that user as a slow or failed load, for a request that never needed to leave Cambodia's own network.

CNX Delivery moves that path local — two things working together: DNS decides where your app connects, CDN/WAF is what gets you the API. Authoritative DNS hosted on CNX's own infrastructure answers with the nearest domestic address; a domestic WAF and CDN cache servers carry and inspect every request from there — all of it protected end to end by CNX's own PKI.

For any business whose service is delivered primarily through a mobile app — banking, telecom, insurance, and government services among them — the app is the channel carrying everything that matters. In critical industries, that channel needs a local path end to end: no out-of-country detour for a call that starts and ends inside Cambodia.

Can Cambodia absorb a global DDoS attack the way a hyperscale CDN does? No — and it doesn't need to. Modern anycast and network segmentation let local content delivery run on its own path with no international exposure at all. A global attack on CNX's infrastructure has nowhere to go, because the Cambodian service segment simply isn't reachable from outside the country. Traffic from outside Cambodia is served separately — through an isolated bulkhead segment, or through the customer's own global CDN partners.

DNS Shield answers based on CNX's own routing data rather than GeoIP guesswork. Inside Cambodia, every connection is protected by mTLS, on a 100GE domestic access network with the headroom to absorb whatever reaches it.

Platform

Domestic latencyUnder 10 ms
Origin connectivityDedicated PNI, dark fiber
International trafficIsolated network segment
InspectionOpenAPI schema + OWASP CRS
Certificate trustDedicated private CA, HSM-rooted
TransportQUIC/HTTP-3 and TCP+TLS
Carrier dataZero-rating available on request

CDN / WAF

Domestic anycast edge with schema validation and the OWASP Core Rule Set, a dedicated interconnect to origin, and QUIC/HTTP-3 support — the delivery and inspection layer Delivery runs on.

PKI

A dedicated certificate authority, rooted in hardware, under Cambodian jurisdiction. The trust anchor everything else in this category verifies against.

Mutual TLS

How the app and the server verify each other, end to end — enforced at the WAF, issued by PKI. Neither piece does this alone.

mTLS

Sealed compute & hardware-attested access

For workloads and access paths that need to go further than delivery and mTLS — confidential compute environments, and device-level attestation designed toward NIST AAL requirements.

Sealed Compute
Built on the exchange

Delivery runs on the same domestic fabric as every other CNX service — your IX port and PNI to origin, and DNS Shield for the zone itself, both already live products in their own right.

Exchange DNS Shield