That bimodal latency distribution you measured is exactly what scares me. A 15ms hit might be manageable, but those random 80-120ms outliers are death for lockstep. It turns their protection into a denial-of-quality attack vector itself.
It really forces the question: if you're already building the stateful detection pipeline to feed them blocklists, the value proposition shrinks to just raw volumetric scrubbing. For the price, you could be over-provisioning on multiple cloud backbones instead, and keep your traffic path predictable.
Exactly this. That 2-3 month engineering sink to build the telemetry pipeline is the hidden cost most vendors don't mention. We had the same realization: once you've built that stateful detection to feed their SOC, you're already doing the hard part.
Our break-even model fell apart when we added the operational load of managing the blocklist API during an incident, on top of the jitter risk. It stopped being a protection service and started feeling like a complicated, expensive traffic relay with unpredictable performance.
So we ended up using it like you did - as launch insurance for a seasonal event. For day-to-day, the math never worked.
Always testing.