WAFRA
Domain Registration, Cloud & dedicated servers,
provisioned automatically
Order Cloud VPS or Dedicated in WAFRA and go live in minutes. Pick your control panel, lock down security, and manage domains — all from one dashboard.
Dashboard Overview
Welcome back, Alex Rivera
Register a New Domain
Search from your dashboard
Quick Shortcuts
Recent Domains
northwind.qa
Expires Jun 28, 2027
aurora-shop.com
Expires Jul 5, 2027
lakeview.io
Expires Apr 26, 2027
Activity
Updated NS for northwind.qa
Created contact Nora Blake
Locked lakeview.io
Click sidebar or shortcuts — fictional demo data
CRA Accredited Registrar
WAFRA IT SOLUTIONS · .qa domains
Officially listed among Qatar’s local accredited registrars for .qa registration and lifecycle management.
Every Cloud VPS & Dedicated plan
Clear plan names, monthly and yearly prices in QAR, and one-time setup fees on Dedicated. Pick a datacenter to load that location’s live catalog.
Multiple datacenters across the globe
Choose a location — the Earth flies there and zooms deep into that country
Selected: Helsinki, Finland
Live in minutes — automatically
No manual server ordering. No waiting days or weeks. Place the order in WAFRA and your Cloud VPS or Dedicated machine provisions itself.
Choose Cloud VPS or Dedicated + location
Pick control panel (HestiaCP or Coolify)
Pay once — provisioning starts automatically
Server agent + secure tunnel come online
Manage from your WAFRA dashboard
Order #4821
Created just now
Hostname srv-a1.demo-cloud.net · 203.0.113.10
HestiaCP in-dashboard. Coolify where it belongs.
Your panel choice changes how you work — WAFRA keeps the right pieces inside the dashboard either way.
Full interactive control inside WAFRA
With HestiaCP you stay in the WAFRA dashboard — websites, DNS, mail, SSL, files, databases, and server actions through our interactive interface. Click the tabs in the preview.
CPU
18%
4 vCPU
RAM
6.2 / 16 GB
39%
Disk
42 / 160 GB
28%
Uptime
12d 3h
Agent on
Deploy in Coolify — ops stay in WAFRA
Open Coolify for apps and containers. Domains, DNS, SSL, mail, backups, security, and the server agent stay managed inside the WAFRA dashboard. Click the tabs below.
Full root shell — our Terminal UI
Same PTY terminal from the server console: reconnect, download logs, clear, and a live interactive bash session as root.
Full interactive root shell (PTY)
Wafra Terminal — interactive shell on srv-a1.demo-cloud.net
root@srv-a1:~# uptime
14:26:08 up 12 days, 1 user, load average: 0.18, 0.22, 0.19
root@srv-a1:~# df -h /
/dev/sda1 160G 42G 110G 28% /
root@srv-a1:~# ▋
Security you can prove, not just claim
Every host runs a virus scanner. The difference is whether you can show an auditor what happened on your server six months ago — and prove it wasn’t edited since.
A log that only lives on your server isn't evidence.
Anyone who compromises a machine can rewrite the logs on it. So security events are sealed into a hash chain and copied into off-box storage with a retention lock that nobody can shorten — including us. If a sealed record is altered after the fact, the break is detectable and locatable.
You can verify the cryptography with standard tools. No WAFRA software required — because proof you have to take our word for isn't proof.
How WAFRA Vault worksCustomer guide, including what we do not claim yet.
What we have proved
No fake event counts. No unmeasured latency SLA.
● immutable off-box copy
Security posture, scored
One screen answers “is anything wrong right now”. A score, and the specific reasons behind it — never a number without an explanation. A protection we can’t currently confirm is shown as unconfirmed, not quietly counted as fine.
6 controls healthy · 1 awaiting report · reasons listed in full
Incidents, not alert noise
Related events are correlated into a single incident with a plain-English explanation, a confidence rating separate from severity, and ordered steps to take. An alert that doesn’t say what to do next is just anxiety with a timestamp.
File changed → login burst from one source → malware found. Three events, one story, with the exact event IDs attached.
Malware scanning you can audit
Nightly scans that actually run — scheduled at OS level so an agent restart can’t silently skip them. Every scan produces a full report: paths covered, files examined, duration, and the complete log. Clean scans included, because proving a scan happened matters.
Detections are quarantined, never deleted — with full chain of custody
Per-site brute-force protection
WordPress logins, XML-RPC and admin paths defended per site, because a store and a brochure site need different rules. Every new rule starts in Monitor mode so you can confirm nothing legitimate gets caught before it blocks anything.
Applied to the server first, recorded second — never claimed before it's true
Every action names a person
Not “admin” — a named individual with a written reason, time-boxed, including when WAFRA staff work inside your account. It appears in your own timeline and your audit digest. You never have to ask us whether someone was in there.
staff · s.ahmad@wafra.net
on behalf of · your account
reason · “Ticket #4821 — checkout 500s”
visible to you · session expired 14:22
Audit digests on your schedule
A signed archive of everything that happened, emailed daily, weekly, monthly — or never. Sent even on quiet weeks, so a missing digest always means a delivery problem rather than an uneventful period.
Compliance answers, with live counts
Controls mapped to ISO 27001, SOC 2, PCI DSS and GDPR — each showing what the framework asks, what we actually do, and how many real events in your account prove it. Gaps are listed with their status rather than left out.
A mapping is a claim. A live count you can export is evidence.
Anti-spam
Protect inboxes at the mail stack: spam scoring, reject policies, and mail-security tools from the same place you manage mailboxes — not a separate appliance login.
Secure tunnelings
The WAFRA agent opens an outbound secure tunnel so management never depends on exposing SSH/admin ports to the public internet by default.
● tunnel · connected
agent ↔ wafra control plane
latency 18ms · encrypted
Server agents
Health, capacity, panel actions, backups, and security jobs run through the agent so the dashboard stays live even when you are not SSH’d in.
Online
Agent
OK
Jobs
12s
Heartbeat
One console, web and mobile
Every pillar here is on your phone too, with the same names in the same order. Organised by what you’re trying to find out, never by which tool produces the answer.
Security Center
Scanning, intrusion bans, audit trail
ClamAV
- Daemon
- Running
- Signatures
- 1d old
- Last scan
- Clean
Fail2Ban
- Service
- Active
- Active bans
- 3
- Jails
- 4
Where the line is. Application-layer abuse, request flooding and credential stuffing we handle directly. Large volumetric attacks are absorbed upstream at the network and CDN edge — no self-hosted stack solves those, and we'd rather tell you that than imply otherwise.
Talk to us about complianceDomains that live with your servers
Search on this page with our live domain engine. Register, transfer, contacts, and renewals stay beside hosting.
When you provision Cloud VPS or Dedicated, DNS zones can be managed next to that server. Buying a domain alone does not include server DNS hosting.
Search a domainOct 12, 2026 · Contacts · Auto-renew
Jan 4, 2027 · Contacts · Auto-renew
Transfer pending · Contacts · Auto-renew
DNS zones ship with your Cloud VPS / Dedicated server — domain registration alone does not include server DNS hosting.
Full-stack web development — backends that hold, UIs that ship
WAFRA builds complete products: strong APIs and data layers, secure auth and integrations, and polished frontends — then we host them on your Cloud VPS or Dedicated so DNS, SSL, and ops stay in one dashboard.
- APIs, databases, and business logic engineered to last
- Full-stack apps — not frontend-only shells
- Deployed on WAFRA hosting with domains ready to go
Architect
Data model, APIs, auth, integrations
Build full stack
Backend + frontend as one product
Launch on WAFRA
Hosted on your server · DNS in dashboard
Talk to sales or support
Reach the right team directly — no form required.
Clear answers
Provisioning, panels, security, and pricing — what buyers ask first.