• Pricing
  • Performance
PricingPerformance
Sign InSign Up
  • Pricing
  • Performance
PricingPerformance
Sign InSign Up
Sign InGet Started

Empowering businesses with enterprise-grade cloud solutions at competitive prices. Built for reliability and simplicity. Designed for growth.

ISO 2700199.9% Uptime

Stay Updated

All systems operational

Products

  • Virtual Machines
  • Windows Servers
  • Kubernetes
  • Object Storage
  • Functions
  • Raff Apps

Databases

  • Managed Databases
  • PostgreSQL
  • MySQL
  • Valkey
  • ClickHouse
  • Kafka

Platform

  • VPC
  • Load Balancers
  • Volumes
  • Backups
  • Security
  • IAM
  • Pricing

Developers

  • Documentation
  • API Reference
  • CLI & SDKs
  • Terraform Provider
  • Release Notes

Learn

  • Learn Hub
  • Tutorials
  • Guides
  • Comparisons
  • Windows Server Hub
  • Blog

Company

  • About
  • Contact
  • FAQ
  • Performance
  • Sign In
  • Sign Up

© 2026 Raff Technologies. All rights reserved.Privacy PolicyTerms of ServiceService Level AgreementAcceptable Use Policy
On by default · no add-ons

Cloud security that's on before you ask.

Every workload on Raff ships protected: automatic node-level DDoS protection on every public IP, stateful security groups, isolated VPCs, IAM with granular per-action permissions, and a full audit log. All included, nothing to buy.

Deploy protectedSee every layer
DDoS protection on every public IPNo security SKUs, ever
security · new deploymentprotected
your workload
ddos shield · node-levelsecurity groupsvpc isolation
✓ DDoS shield active · every public IP · automatic
✓ Security group applied · web-default
✓ Network isolated · vpc: prod
✓ MFA enforced · audit log recording
● Protected nothing to configure · $0.00 extra
security add-ons to buy
zero
Defense in depth

Four layers of cloud security, all included.

Security you have to remember to buy is security you'll forget to buy. On Raff every layer is part of the platform, not a line on a quote.

Edge

DDoS protection

Automatic node-level mitigation on every public IP. Always on, nothing to enable, no per-attack bill.

How it works
Network

Isolation & firewalls

Every VPC is a fully isolated network, and stateful security groups decide exactly what reaches each VM.

Security groups
Access

IAM & MFA

Roles with granular per-action permissions, project-scoped access, API keys with expiry, and authenticator-app MFA.

Explore Raff IAM
Visibility

Audit log

Every action recorded with actor, IP and result, including denied attempts. Visible in your dashboard.

See the audit trail
Edge layer

DDoS protection you never think about.

Every Raff VPS and service is DDoS-protected by default. Mitigation happens automatically at the node level, so an attack on your IP is our problem to absorb, not your outage to explain.

  • Node-level mitigation: attacks are filtered where your workload runs, automatically
  • Covers every public IP on the platform, VMs, clusters, databases and apps alike
  • Always on from the second you deploy, with no rules to write and nothing to enable
  • Included free on every plan, with no per-attack or per-GB scrubbing charges
  • Keep your unexposed services off the internet entirely with a free VPC

The best attack surface is none: put your database on a private network and there is no public IP to attack.

What you do when an attack starts
step 1
Nothing.
step 2
There is no step 2. Mitigation is automatic.
your bill afterwards
unchanged

No marketing terabits here: we publish what the protection does, not invented capacity numbers.

Network layer

A cloud firewall you configure in plain rules.

Stateful security groups control what reaches every VM. Start from a template, or write exactly the rules you mean, in the dashboard or in Terraform.

Stateful rules

Allow the request and the reply is handled for you. TCP, UDP and ICMP, with port ranges.

Per-VM attachment

Attach groups to exactly the NICs that need them. One group can guard a whole fleet.

Templates to start

Web server, SSH only, Database. Clone one, adjust it, done in under a minute.

API, CLI and Terraform

Security groups are first-class in the public API and the Terraform provider.

security group templates
Web server
TCP 80, 443 in · all out
Clone
SSH only
TCP 22 from your IP · all out
Clone
Database
DB port from app subnet only
Clone

Rules basics in cloud firewall rules explained and firewall best practices.

Set your first rulesPair with a free VPC
Straight talk

What we handle, and what stays yours.

No security page should pretend the platform does everything. Here is the honest split, so nothing falls between two chairs.

Raff handles
  • DDoS mitigation on every public IP, automatically
  • Tenant isolation between all networks and workloads
  • Platform patching, hardening and 24/7 operations
  • ISO 27001 certified infrastructure in our us-east region
  • Audit logging of every account action
You handle
  • Set security group rules for what you expose
  • Keep private services on a VPC, not a public IP
  • Use roles and projects instead of sharing accounts
  • Turn on MFA for every member
  • Patch what runs inside your VMs

Everything on the left is included with every plan, backed by a 99.9% uptime SLA. Everything on the right ships with the tools to do it: security groups, free VPCs, IAM and MFA.

One platform

Part of the Raff cloud.

Security here is not a product you attach afterwards. Everything below ships inside the same protections.

protected by default · $0.00 extra
IAMRoles, granular permissions, API keys and audit logs.
VPCFree private networking with unmetered traffic.
Cloud VMsDDoS-protected VPS with security groups included.
KubernetesManaged clusters inside your isolated network.
Managed DatabasesPrivate by default, public access allowlisted.
Object StorageScoped access keys per bucket and per grant.
FAQ

Questions people ask about cloud security.

Every plan ships with automatic DDoS protection on all public IPs, stateful security groups, isolated VPCs, IAM with granular per-action permissions, MFA and a full audit log. There are no paid security add-ons on Raff.

Yes. Automatic node-level DDoS protection covers every public IP on the Raff platform, on every plan. There is no per-attack charge, no per-GB scrubbing fee and nothing to configure.

Mitigation runs automatically at the node level, where your workload lives. An attack on your IP is filtered without any action from you, and your bill does not change afterwards.

Yes: stateful security groups with TCP, UDP and ICMP rules, attachable per VM, with ready-made templates for web servers, SSH and databases. Manage them in the dashboard, the API or Terraform.

AWS includes basic DDoS cover but bills separately for WAF, GuardDuty and extended audit trails. Raff includes DDoS protection, firewalls, IAM and full audit logs in every plan at $0. AWS offers a larger security product catalog overall.

Raff runs on ISO 27001 certified infrastructure in Vint Hill, Virginia, backed by a 99.9% uptime SLA in writing.

Yes. Every network is a fully isolated VPC per tenant: separate IP space, separate traffic. Nothing you don't expose is reachable, from the internet or from other Raff customers.

View all FAQs

Deploy protected. Stay protected.

DDoS protection, firewalls, isolation, IAM and audit logs on every plan, at no extra cost. 15,000+ builders run on Raff in our us-east region, backed by a 99.9% uptime SLA in writing.

Get startedReview the layers
Set up roles with IAM →Isolate with a free VPC →See all pricing →
Raff Learn

Learn

Guides to help you plan, build, and scale on Raff.

Series

Cloud Security, Identity & Secure Access

Help teams secure cloud workloads through server hardening, firewall exposure control, administrative access, identity governance, secrets management, API protection, and software supply chain security.

  • VPS Setup Checklist: What to Configure After Deployment
  • Cloud Firewall Rules Explained: Inbound, Outbound, and Least Privilege
  • Private vs Public Admin Access: When Each Model Is Appropriate
  • Secrets Management for Cloud Apps: Env Vars, Vaults, Managed Stores
Cloud Security Fundamentals for Developers and Small Teams

Series

Server Hardening

Cover cloud server baseline security, patching, vulnerability reduction, and post-deployment hardening decisions.

  • VPS Setup Checklist: What to Configure After Deployment

Series

Firewall & Network Exposure

Cover firewall rules, inbound and outbound controls, least privilege networking, and cloud exposure reduction.

  • Cloud Firewall Rules Explained: Inbound, Outbound, and Least Privilege