Limits/Protection to avoid high billing caused by DDoS?

I had implemented rate-limiting on my api-gateway which is hosted outside of netlify. Only the front-end is hosted on netlify. So, I guess I need to do more experiments.
Thanks for your time :slight_smile: