Servers ready in minutes — not days

WAFRA

Domain Registration, Cloud & dedicated servers,
provisioned automatically

Order Cloud VPS or Dedicated in WAFRA and go live in minutes. Pick your control panel, lock down security, and manage domains — all from one dashboard.

Dashboard Overview

Welcome back, Alex Rivera

Register a New Domain

Search from your dashboard

Quick Shortcuts

Recent Domains

northwind.qa

Expires Jun 28, 2027

Active

aurora-shop.com

Expires Jul 5, 2027

Active

lakeview.io

Expires Apr 26, 2027

Active

Activity

Updated NS for northwind.qa

Created contact Nora Blake

Locked lakeview.io

Click sidebar or shortcuts — fictional demo data

CRA Accredited Registrar

CRA Accredited Registrar

WAFRA IT SOLUTIONS · .qa domains

Officially listed among Qatar’s local accredited registrars for .qa registration and lifecycle management.

Plans & pricing

Every Cloud VPS & Dedicated plan

Clear plan names, monthly and yearly prices in QAR, and one-time setup fees on Dedicated. Pick a datacenter to load that location’s live catalog.

Multiple datacenters across the globe

Choose a location — the Earth flies there and zooms deep into that country

Selected: Helsinki, Finland

Provisioning

Live in minutes — automatically

No manual server ordering. No waiting days or weeks. Place the order in WAFRA and your Cloud VPS or Dedicated machine provisions itself.

1

Choose Cloud VPS or Dedicated + location

2

Pick control panel (HestiaCP or Coolify)

3

Pay once — provisioning starts automatically

4

Server agent + secure tunnel come online

5

Manage from your WAFRA dashboard

Agent online · tunnel live · console ready
WAFRA · Provisioning

Order #4821

Created just now

Active
ProductCloud VPS
LocationHelsinki
Plan4 vCPU / 16 GB
PanelHestiaCP
AgentOnline
TunnelLive
Ready in minutes — open server console

Hostname srv-a1.demo-cloud.net · 203.0.113.10

Control panels

HestiaCP in-dashboard. Coolify where it belongs.

Your panel choice changes how you work — WAFRA keeps the right pieces inside the dashboard either way.

HestiaCP

Full interactive control inside WAFRA

With HestiaCP you stay in the WAFRA dashboard — websites, DNS, mail, SSL, files, databases, and server actions through our interactive interface. Click the tabs in the preview.

WAFRA · HestiaCP · srv-a1

CPU

18%

4 vCPU

RAM

6.2 / 16 GB

39%

Disk

42 / 160 GB

28%

Uptime

12d 3h

Agent on

Coolify

Deploy in Coolify — ops stay in WAFRA

Open Coolify for apps and containers. Domains, DNS, SSL, mail, backups, security, and the server agent stay managed inside the WAFRA dashboard. Click the tabs below.

WAFRA · Coolify server ops
app.northwind.qaDNS · SSL
api.northwind.qaDNS · SSL
docs.northwind.qaDNS · SSL
Root access

Full root shell — our Terminal UI

Same PTY terminal from the server console: reconnect, download logs, clear, and a live interactive bash session as root.

Terminal

Full interactive root shell (PTY)

ReconnectDownload LogClear
root@srv-a1.demo-cloud.net — bashconnected

Wafra Terminal — interactive shell on srv-a1.demo-cloud.net

root@srv-a1:~# uptime

14:26:08 up 12 days, 1 user, load average: 0.18, 0.22, 0.19

root@srv-a1:~# df -h /

/dev/sda1 160G 42G 110G 28% /

root@srv-a1:~#

Security

Security you can prove, not just claim

Every host runs a virus scanner. The difference is whether you can show an auditor what happened on your server six months ago — and prove it wasn’t edited since.

WAFRA Vault · tamper-evident by design

A log that only lives on your server isn't evidence.

Anyone who compromises a machine can rewrite the logs on it. So security events are sealed into a hash chain and copied into off-box storage with a retention lock that nobody can shorten — including us. If a sealed record is altered after the fact, the break is detectable and locatable.

You can verify the cryptography with standard tools. No WAFRA software required — because proof you have to take our word for isn't proof.

How WAFRA Vault works

Customer guide, including what we do not claim yet.

What we have proved

retention lockcompliance
delete by usrefused
hash chainverifiable
rollout defaultdetect-safe

No fake event counts. No unmeasured latency SLA.

● immutable off-box copy

Security posture, scored

One screen answers “is anything wrong right now”. A score, and the specific reasons behind it — never a number without an explanation. A protection we can’t currently confirm is shown as unconfirmed, not quietly counted as fine.

Posture score94

6 controls healthy · 1 awaiting report · reasons listed in full

Incidents, not alert noise

Related events are correlated into a single incident with a plain-English explanation, a confidence rating separate from severity, and ordered steps to take. An alert that doesn’t say what to do next is just anxiety with a timestamp.

highPossible site compromise

File changed → login burst from one source → malware found. Three events, one story, with the exact event IDs attached.

Malware scanning you can audit

Nightly scans that actually run — scheduled at OS level so an agent restart can’t silently skip them. Every scan produces a full report: paths covered, files examined, duration, and the complete log. Clean scans included, because proving a scan happened matters.

Last scanClean · 0 threats
Files examined128,441

Detections are quarantined, never deleted — with full chain of custody

Per-site brute-force protection

WordPress logins, XML-RPC and admin paths defended per site, because a store and a brochure site need different rules. Every new rule starts in Monitor mode so you can confirm nothing legitimate gets caught before it blocks anything.

shop.example.comEnforcing
blog.example.comMonitor

Applied to the server first, recorded second — never claimed before it's true

Every action names a person

Not “admin” — a named individual with a written reason, time-boxed, including when WAFRA staff work inside your account. It appears in your own timeline and your audit digest. You never have to ask us whether someone was in there.

staff · s.ahmad@wafra.net

on behalf of · your account

reason · “Ticket #4821 — checkout 500s”

visible to you · session expired 14:22

Audit digests on your schedule

A signed archive of everything that happened, emailed daily, weekly, monthly — or never. Sent even on quiet weeks, so a missing digest always means a delivery problem rather than an uneventful period.

DailyEvery 5 daysWeeklyMonthlyOff

Compliance answers, with live counts

Controls mapped to ISO 27001, SOC 2, PCI DSS and GDPR — each showing what the framework asks, what we actually do, and how many real events in your account prove it. Gaps are listed with their status rather than left out.

ISO 270011,247 events
SOC 2980 events
PCI DSS v4.0612 events

A mapping is a claim. A live count you can export is evidence.

Anti-spam

Protect inboxes at the mail stack: spam scoring, reject policies, and mail-security tools from the same place you manage mailboxes — not a separate appliance login.

Spam filterEnabled
Quarantine12 held
DKIM / SPFPass

Secure tunnelings

The WAFRA agent opens an outbound secure tunnel so management never depends on exposing SSH/admin ports to the public internet by default.

● tunnel · connected

agent ↔ wafra control plane

latency 18ms · encrypted

Server agents

Health, capacity, panel actions, backups, and security jobs run through the agent so the dashboard stays live even when you are not SSH’d in.

Online

Agent

OK

Jobs

12s

Heartbeat

One console, web and mobile

Every pillar here is on your phone too, with the same names in the same order. Organised by what you’re trying to find out, never by which tool produces the answer.

PostureIncidentsThreatsWebsitesAccessEvidenceCompliance
WAFRA · Security Center

Security Center

Scanning, intrusion bans, audit trail

Mail Refresh

ClamAV

Daemon
Running
Signatures
1d old
Last scan
Clean

Fail2Ban

Service
Active
Active bans
3
Jails
4

Where the line is. Application-layer abuse, request flooding and credential stuffing we handle directly. Large volumetric attacks are absorbed upstream at the network and CDN edge — no self-hosted stack solves those, and we'd rather tell you that than imply otherwise.

Talk to us about compliance
Domains

Domains that live with your servers

Search on this page with our live domain engine. Register, transfer, contacts, and renewals stay beside hosting.

Live availability search (embedded above)
CRA-accredited .qa registration
Global TLDs, transfers, and contacts
DNS hosting comes with your server — not with domain-only registration

When you provision Cloud VPS or Dedicated, DNS zones can be managed next to that server. Buying a domain alone does not include server DNS hosting.

Search a domain
WAFRA · Domains
northwind.qaActive

Oct 12, 2026 · Contacts · Auto-renew

aurora-shop.comActive

Jan 4, 2027 · Contacts · Auto-renew

lakeview.ioPending

Transfer pending · Contacts · Auto-renew

DNS zones ship with your Cloud VPS / Dedicated server — domain registration alone does not include server DNS hosting.

Web development

Full-stack web development — backends that hold, UIs that ship

WAFRA builds complete products: strong APIs and data layers, secure auth and integrations, and polished frontends — then we host them on your Cloud VPS or Dedicated so DNS, SSL, and ops stay in one dashboard.

  • APIs, databases, and business logic engineered to last
  • Full-stack apps — not frontend-only shells
  • Deployed on WAFRA hosting with domains ready to go
1

Architect

Data model, APIs, auth, integrations

2

Build full stack

Backend + frontend as one product

3

Launch on WAFRA

Hosted on your server · DNS in dashboard

Support & contact

Talk to sales or support

Reach the right team directly — no form required.

Sales

Plans, quotes, and onboarding

sales@wafra.net+974 7020 2010

Support

Servers, domains, and tickets

support@wafra.net+974 7035 1125
FAQ

Clear answers

Provisioning, panels, security, and pricing — what buyers ask first.