On by default · no add-ons

Cloud security that's on before you ask.

Every workload on Raff ships protected: automatic node-level DDoS protection on every public IP, stateful security groups, isolated VPCs, IAM with granular per-action permissions, and a full audit log. All included, nothing to buy.

DDoS protection on every public IPNo security SKUs, ever
security · new deploymentprotected
your workload
ddos shield · node-levelvpc isolation
DDoS shield active · every public IP · automatic
Security group applied · web-default
Network isolated · vpc: prod
MFA enforced · audit log recording
● Protected nothing to configure · $0.00 extra
Defense in depth

Four layers of cloud security, all included.

Security you have to remember to buy is security you'll forget to buy. On Raff every layer is part of the platform, not a line on a quote.

Edge

DDoS protection

Automatic node-level mitigation on every public IP. Always on, nothing to enable, no per-attack bill.

How it works
Network

Isolation & firewalls

Every VPC is a fully isolated network, and stateful security groups decide exactly what reaches each VM.

Security groups
Access

IAM & MFA

Roles with granular per-action permissions, project-scoped access, API keys with expiry, and authenticator-app MFA.

Explore Raff IAM
Visibility

Audit log

Every action recorded with actor, IP and result, including denied attempts. Visible in your dashboard.

See the audit trail
Edge layer

DDoS protection you never think about.

Every Raff VPS and service is DDoS-protected by default. Mitigation happens automatically at the node level, so an attack on your IP is our problem to absorb, not your outage to explain.

  • Node-level mitigation: attacks are filtered where your workload runs, automatically
  • Covers every public IP on the platform, VMs, clusters, databases and apps alike
  • Always on from the second you deploy, with no rules to write and nothing to enable
  • Included free on every plan, with no per-attack or per-GB scrubbing charges
  • Keep your unexposed services off the internet entirely with a free VPC

The best attack surface is none: put your database on a private network and there is no public IP to attack.

What you do when an attack starts
step 1
Nothing.
step 2
There is no step 2. Mitigation is automatic.
your bill afterwards
unchanged

No marketing terabits here: we publish what the protection does, not invented capacity numbers.

Network layer

A cloud firewall you configure in plain rules.

Stateful security groups control what reaches every VM. Start from a template, or write exactly the rules you mean, in the dashboard or in Terraform.

Stateful rules

Allow the request and the reply is handled for you. TCP, UDP and ICMP, with port ranges.

Per-VM attachment

Attach groups to exactly the NICs that need them. One group can guard a whole fleet.

Templates to start

Web server, SSH only, Database. Clone one, adjust it, done in under a minute.

API, CLI and Terraform

Security groups are first-class in the public API and the Terraform provider.

security group templates
Web server
TCP 80, 443 in · all out
Clone
SSH only
TCP 22 from your IP · all out
Clone
Database
DB port from app subnet only
Clone

Rules basics in cloud firewall rules explained and firewall best practices.

Straight talk

What we handle, and what stays yours.

No security page should pretend the platform does everything. Here is the honest split, so nothing falls between two chairs.

Raff handles
  • DDoS mitigation on every public IP, automatically
  • Tenant isolation between all networks and workloads
  • Platform patching, hardening and 24/7 operations
  • ISO 27001 certified infrastructure in our us-east region
  • Audit logging of every account action
You handle
  • Set security group rules for what you expose
  • Keep private services on a VPC, not a public IP
  • Use roles and projects instead of sharing accounts
  • Turn on MFA for every member
  • Patch what runs inside your VMs

Everything on the left is included with every plan, backed by a 99.9% uptime SLA. Everything on the right ships with the tools to do it: security groups, free VPCs, IAM and MFA.

FAQ

Questions people ask about cloud security.

Every plan ships with automatic DDoS protection on all public IPs, stateful security groups, isolated VPCs, IAM with granular per-action permissions, MFA and a full audit log. There are no paid security add-ons on Raff.

Yes. Automatic node-level DDoS protection covers every public IP on the Raff platform, on every plan. There is no per-attack charge, no per-GB scrubbing fee and nothing to configure.

Mitigation runs automatically at the node level, where your workload lives. An attack on your IP is filtered without any action from you, and your bill does not change afterwards.

Yes: stateful security groups with TCP, UDP and ICMP rules, attachable per VM, with ready-made templates for web servers, SSH and databases. Manage them in the dashboard, the API or Terraform.

AWS includes basic DDoS cover but bills separately for WAF, GuardDuty and extended audit trails. Raff includes DDoS protection, firewalls, IAM and full audit logs in every plan at $0. AWS offers a larger security product catalog overall.

Raff runs on ISO 27001 certified infrastructure in Vint Hill, Virginia, backed by a 99.9% uptime SLA in writing.

Yes. Every network is a fully isolated VPC per tenant: separate IP space, separate traffic. Nothing you don't expose is reachable, from the internet or from other Raff customers.

Deploy protected. Stay protected.

DDoS protection, firewalls, isolation, IAM and audit logs on every plan, at no extra cost. 15,000+ builders run on Raff in our us-east region, backed by a 99.9% uptime SLA in writing.