ADG/Registry Service Provider
ICANN-Evaluated Registry Service Provider

Complete Backend Registry Services for TLD Operators

ADG provides the complete technical infrastructure needed by Top-Level Domain operators — from global DNS Anycast to DNSSEC key management — all of which have passed ICANN's rigorous RSP Program evaluation.

55 Core Services
99.999%99.999% DNS SLA
30+30+ Anycast Nodes
<4h<4 hours RTO
24/724/7 NOC
Understanding RSP

What Is a Registry Service Provider?

A Registry Service Provider (RSP) is a technical backend service provider that manages the day-to-day operations of a Top-Level Domain (TLD). When an organization obtains the right to manage a TLD from ICANN — such as .brand, .company, or even a country-code TLD — they have two options: build the entire technical infrastructure themselves, or partner with an ICANN-evaluated RSP.

The RSP handles all critical technical aspects: DNS resolution answering billions of queries daily, domain provisioning systems (EPP/SRS) for domain registration and management, WHOIS/RDAP services for public domain data queries, DNSSEC cryptographic signing for DNS security, and Data Escrow for registrant data protection.

ICANN maintains a list of evaluated RSPs meeting strict technical standards. As of 2025, only 28 RSPs worldwide have passed this evaluation. PT AIDI Digital Global is one of them — and the only one based in Southeast Asia.

Why Choose an RSP Over In-House Infrastructure?

  • Reduce initial investment and operational infrastructure costs
  • Leverage experienced team expertise in registry operations
  • Accelerate time-to-market — launch a TLD in 60–90 days
  • Guaranteed SLA commitments, including uptime and response times
  • ICANN compliance built-in, including Data Escrow and EBERO readiness
  • Focus on business and domain strategy, not infrastructure management
Core Services

Five Critical Services Operated by ADG

Each service has been independently evaluated by ICANN and meets the highest operational standards of the global registry industry.

Technical Specifications

  • 30+ Anycast nodes across 6 continents (via .id Registry global infrastructure)
  • SLA: 99.999% availability (< 5 minutes downtime per year)
  • UDP & TCP DNS support (RFC 1035, RFC 7766)
  • EDNS0 support with 4096-byte payload
  • DNS query logging & analytics
  • Automated zone management & propagation
  • DDoS protection: 1 Tbps backbone capacity
Architecture

ADG Registry Platform Architecture

Our system is designed with high availability, security-by-design, and compliance-first principles.

Platform Architecture

DNS Anycast
30+ Anycast Nodes
EPP/SRS Engine
Tier 3+ Data Centers
Jakarta & DR Site

High Availability

Every component has full redundancy. Databases use active-passive replication with automatic failover. DNS runs on 30+ independent nodes. EPP has hot standby.

Security-by-Design

All communication uses TLS 1.3 minimum. Cryptographic keys stored in HSM. System access uses MFA and role-based access control. Audit log for every operation.

Compliance-First

Architecture designed to meet ICANN requirements from the start, not as an afterthought. Data Escrow, EBERO readiness, and SLA monitoring are integrated into the core platform.

SLA & Performance

Service Level Agreement Commitments

ADG's SLA is designed to exceed ICANN's minimum standards, providing reliable contractual guarantees for TLD operators.

ServiceICANN MinimumADG SLAADG Target
DNS Resolution99.99%99.999%99.9999%
EPP/SRS99.9%99.99%99.999%
WHOIS (Port 43)99.9%99.99%99.999%
RDAP99.9%99.99%99.999%
DNSSEC Signing100%100%100%
Data Escrow DepositWeeklyDaily incremental + Weekly fullDaily incremental + Weekly full

RPO < 1 Hour

Recovery Point Objective: maximum data loss of 1 hour in worst-case scenario

RTO < 4 Hours

Recovery Time Objective: full service recovery within 4 hours

24/7 NOC

Network Operations Center active around the clock with on-call escalation

Incident Response Times

SeverityDescriptionInitial ResponseUpdate FrequencyResolution Target
P1 — CriticalEntire service down or data loss15 minutesEvery 30 minutes4 hours
P2 — HighSignificant degradation of one critical service30 minutesEvery 1 hour8 hours
P3 — MediumMinor degradation, workaround available2 hoursEvery 4 hours24 hours
P4 — LowCosmetic issue or enhancement request8 hoursDaily5 business days
Pricing Model

Transparent Pricing, Tailored to Your Needs

We believe in pricing transparency. RSP service costs depend on domain volume, TLD complexity, and additional services required.

"ADG's pricing follows the per-domain per-tier model common in the RSP industry, with a one-time setup fee and monthly/annual billing based on active domains. Each tier includes all 5 critical ICANN services — no hidden fees for features that should already be included."

Starter

For New TLDs & Brand TLDs

< 10,000 domains
  • Full 5 core services (DNS, EPP, WHOIS/RDAP, DNSSEC, Escrow)
  • Shared infrastructure
  • Standard SLA
  • Email support + 24/7 NOC
  • Setup fee: per agreement
  • Per-domain per-year: volume-based
Request Quote
Popular

Professional

For Growing TLDs

10,000–100,000 domains
  • Full 5 core services
  • Dedicated infrastructure options
  • Enhanced SLA
  • Dedicated account manager
  • Custom EPP extensions support
  • Priority incident response
Request Quote

Enterprise

For Large Registries & ccTLDs

100,000+ domains
  • Full 5 core services
  • Fully dedicated infrastructure
  • Premium SLA with financial penalties
  • Dedicated NOC team
  • Custom integrations & APIs
  • On-site support available
  • Strategic partnership model
Contact Director
All prices are quoted in USD as the registry industry standard. IDR billing available with agreed-upon exchange rate.
Onboarding

From Signature to Go-Live in 60–90 Days

ADG's onboarding process is designed for efficiency without sacrificing rigor. A dedicated team guides you through every stage.

1
Weeks 1–2

Pre-Engagement

Discuss requirements, conduct technical assessment, and compile proposal. We understand your TLD — domain policies, target market, registrar partners, and specific technical needs.

Service Agreement
2
Weeks 3–5

Environment Setup

Provision DNS zone on 30+ Anycast nodes, set up EPP/SRS instance, configure WHOIS/RDAP, and generate DNSSEC keys in HSM.

Test Environment Ready
3
Weeks 6–7

Configuration

Configure TLD-specific domain policies: pricing, grace periods, reserved names, premium domains. Onboard registrar partners.

Configuration Complete
4
Weeks 8–10

OT&E Testing

Operational Test & Evaluation — registrars test EPP connections, domain operations, and DNSSEC validation in staging environment.

OT&E Passed
5
Weeks 11–12

ICANN PDT

Coordinate Pre-Delegation Testing with ICANN: verify DNS, EPP, WHOIS/RDAP, DNSSEC, and Data Escrow compliance.

PDT Passed
6
Week 13

Go-Live

DNS delegation to root zone, production cutover, and full monitoring activation. Your TLD is now officially live on the internet.

TLD Live in Root Zone
7
Weeks 14–17

Stabilization

Intensive monitoring, performance fine-tuning, knowledge transfer, and handover to regular operations mode.

Transition Complete

The 60–90 day timeline applies to standard new TLDs. Migration from another RSP requires 90–120 days due to data migration and parallel run. Brand TLDs (.brand) with low volume can be faster (45–60 days).

ICANN Compliance

Full Compliance with ICANN RSP Handbook

ADG has been evaluated and meets all requirements of the ICANN RSP Handbook v1.2.2 (March 2025). Below is the mapping of requirements to our implementation.

ICANN RequirementHandbook SectionADG ImplementationStatus
Governance & OrganizationMAIN.1Formal organizational structure, complete SOP, documented security policies✅ Compliant
Personnel SecurityMAIN.1.11–123-level background checks, penetration testing plan, key ceremony personnel clearance✅ Compliant
EPP/SRS OperationsMAIN.3–4Full EPP RFC compliance, 99.99% SLA, concurrent connection support✅ Compliant
WHOIS/RDAP ServiceMAIN.5Port 43 + RDAP, thick model, data protection-aware redaction✅ Compliant
Data EscrowMAIN.6Daily incremental + weekly full, ICANN-approved agent, PGP encryption✅ Compliant
Data ProtectionMAIN.7Local data protection compliance, breach notification within 72 hours, privacy policy✅ Compliant
Abuse PreventionMAIN.8–9Documented abuse prevention policy, rights protection mechanisms✅ Compliant
Registry ContinuityMAIN.11EBERO plan, service transition plan, business continuity procedures✅ Compliant
Capacity PlanningMAIN.13Capacity planning document, scalability roadmap, load testing✅ Compliant
DNS OperationsDNS.1–430+ Anycast nodes, 99.999% SLA, 1 Tbps DDoS protection✅ Compliant
DNSSEC OperationsDNSSEC.1–4FIPS 140-2 HSM, KSK annual/ZSK quarterly rotation, DPS published✅ Compliant
Use Cases

Who Needs ADG's RSP Services?

New gTLD Operator

Scenario

You have secured a new TLD right from ICANN and need the technical infrastructure to launch it.

How ADG Helps

We provide all 5 critical services, guide you through Pre-Delegation Testing, and bring your TLD live in 60–90 days without you building a single server.

Example: .example, .brand, .industry

Migration from Another RSP

Scenario

You're unsatisfied with your current RSP — SLA not met, slow support, or costs too high.

How ADG Helps

ADG's team executes zero-downtime migration with parallel run, 100% data validation, and rollback plan. We ensure a seamless transition for your registrants.

Example: Seamless migration with parallel testing

ccTLD Backend

Scenario

A country-code TLD operator wants to outsource the backend technical infrastructure to focus on policy and regulation.

How ADG Helps

ADG provides complete backend infrastructure while the ccTLD operator retains full control over domain policies and registrar relationships.

Example: Country-code TLD in Southeast Asia

Brand TLD (.brand)

Scenario

A global company wants to launch a .brand TLD for branding, email, and exclusive digital presence.

How ADG Helps

Brand TLDs have low volume but require high reliability. ADG provides managed services that are cost-effective with accelerated onboarding (45–60 days).

Example: .corporation, .brand, .company
FAQ

Frequently Asked Questions

ADG is the only ICANN-evaluated RSP based in Southeast Asia. We offer unique advantages: geographic proximity and timezone for Asia-Pacific clients, deep understanding of Indonesian regulations (Law 27/2022 on Data Protection, Government Regulation 71/2019), bilingual support (Indonesian/English), and strategic partnership with .id Registry providing access to global DNS infrastructure.

Ready to Get Started?

Discuss your TLD needs with ADG's team. We'll prepare a customized proposal tailored to your specific requirements — no commitment necessary.

Email Inquiry

[email protected]

Direct Contact

Dimaz Maulana — [email protected]

Office Location

Icon Business Park Unit L3, BSD City, Tangerang 15345, Indonesia

Operating Hours

Monday–Friday 09:00–18:00 WIB | NOC 24/7

ICANN-Evaluated30+ Global Nodes99.999% DNS SLA24/7 Support