Every workload on Raff ships protected: automatic node-level DDoS protection on every public IP, stateful security groups, isolated VPCs, IAM with granular per-action permissions, and a full audit log. All included, nothing to buy.
Security you have to remember to buy is security you'll forget to buy. On Raff every layer is part of the platform, not a line on a quote.
Automatic node-level mitigation on every public IP. Always on, nothing to enable, no per-attack bill.
How it worksEvery VPC is a fully isolated network, and stateful security groups decide exactly what reaches each VM.
Security groupsRoles with granular per-action permissions, project-scoped access, API keys with expiry, and authenticator-app MFA.
Explore Raff IAMEvery action recorded with actor, IP and result, including denied attempts. Visible in your dashboard.
See the audit trailEvery Raff VPS and service is DDoS-protected by default. Mitigation happens automatically at the node level, so an attack on your IP is our problem to absorb, not your outage to explain.
The best attack surface is none: put your database on a private network and there is no public IP to attack.
No marketing terabits here: we publish what the protection does, not invented capacity numbers.
Stateful security groups control what reaches every VM. Start from a template, or write exactly the rules you mean, in the dashboard or in Terraform.
Allow the request and the reply is handled for you. TCP, UDP and ICMP, with port ranges.
Attach groups to exactly the NICs that need them. One group can guard a whole fleet.
Web server, SSH only, Database. Clone one, adjust it, done in under a minute.
Security groups are first-class in the public API and the Terraform provider.
Rules basics in cloud firewall rules explained and firewall best practices.
No security page should pretend the platform does everything. Here is the honest split, so nothing falls between two chairs.
Everything on the left is included with every plan, backed by a 99.9% uptime SLA. Everything on the right ships with the tools to do it: security groups, free VPCs, IAM and MFA.
Security here is not a product you attach afterwards. Everything below ships inside the same protections.
Every plan ships with automatic DDoS protection on all public IPs, stateful security groups, isolated VPCs, IAM with granular per-action permissions, MFA and a full audit log. There are no paid security add-ons on Raff.
Yes. Automatic node-level DDoS protection covers every public IP on the Raff platform, on every plan. There is no per-attack charge, no per-GB scrubbing fee and nothing to configure.
Mitigation runs automatically at the node level, where your workload lives. An attack on your IP is filtered without any action from you, and your bill does not change afterwards.
Yes: stateful security groups with TCP, UDP and ICMP rules, attachable per VM, with ready-made templates for web servers, SSH and databases. Manage them in the dashboard, the API or Terraform.
AWS includes basic DDoS cover but bills separately for WAF, GuardDuty and extended audit trails. Raff includes DDoS protection, firewalls, IAM and full audit logs in every plan at $0. AWS offers a larger security product catalog overall.
Raff runs on ISO 27001 certified infrastructure in Vint Hill, Virginia, backed by a 99.9% uptime SLA in writing.
Yes. Every network is a fully isolated VPC per tenant: separate IP space, separate traffic. Nothing you don't expose is reachable, from the internet or from other Raff customers.
DDoS protection, firewalls, isolation, IAM and audit logs on every plan, at no extra cost. 15,000+ builders run on Raff in our us-east region, backed by a 99.9% uptime SLA in writing.