Your approach is to try to avoid taking down any content proxied behind a single consolidated service, which is controlled by a single organization and is managed under ASNs and IP addresses assigned to you and under your control.
The approach I prefer is to try to improve the problem by decentralizing control of autonomous systems - putting more ASNs, IP blocks and SSL terminators into the hands of independent operators, which makes it harder for governments to single out organizations for things like, for example, mass scale wiretapping via FISA court orders. ASNs are also previously where legal precedent generally accepted that autonomous service providers exist for purposes of handling legal issues, and are the spot where one's strong control over their "Terms of Service" generally begins (though the IP transit provider will usually set a few anti-network-abuse policies (https://he.net/tos.html), including DDoS related ones, realizing that protecting speech has to be balanced with maintaining the health of the internet).
The point I want to make is that the problem with adding "DDoS-for-hire" sites to your list of protected speech is that it directly harms the latter approach of improving decentralization and diversity of ownership in a way that no other service that has existed has ever done before. By making it so that those independent groups require an enormous amount of routing equipment and bandwidth in order to run their own services without risk of DDoS attacks, or being forced to hide their autonomous systems behind another autonomous system (like yours), I strongly believe that not only is your organization directly contributing to the consolidation problem on the net, but that your organization, by enabling these attackers, may even be the leading cause of it.
I have no problem with your anti-censorship policy. I don't think anyone in here does. I would even defend your right to proxy a terrorist web site. But even IP transit providers make exceptions related to DDoS for the health of the internet itself. If it comes down to a choice between protecting DDoS-for-hire sites and protecting the internet itself, which one is the right choice?