WAFRA Vault

Security you can prove, not just claim.

Most hosting providers can tell you they run a virus scanner and a firewall. Very few can show you what happened on your server last Tuesday, prove the record has not been edited since, and hand you something your auditor will accept.

This page explains how ours works, in plain language, including where the limits are.

Coverage

What the Vault covers

Six things, each visible in your dashboard on web and mobile once security is enabled for your server. New servers start in a watch-only mode; existing servers stay off until we deliberately enable them — so a platform deploy never surprises a live site.

Posture

A single score for each server, with the specific reasons behind it.

Never a number on its own. If something is wrong you get the reason, and if a protection cannot currently be confirmed it is shown as unconfirmed rather than quietly counted as healthy.

Threat detection

Scheduled and on-demand malware scanning, with real results.

You see what was scanned, what was found, and what was done about it. A finding that was suppressed by a rule is recorded as a suppressed finding, not as a clean scan.

Website protection

Per-site defence against login attacks and request floods.

Configured per site, not per server, because a WordPress store and a static brochure page need different rules. Applying one policy everywhere produces false positives, and false positives teach people to switch protection off.

Attribution

Every action tied to a named actor.

Customer, WAFRA staff member, or automated job. When our staff act on your server, that is recorded as our staff acting on your server — including the reason they gave.

Evidence

A tamper-evident record of everything above.

Chained, sealed, and copied into off-box storage that your server cannot alter. Exportable as a bundle you can hand to an auditor.

Compliance mapping

Controls mapped to recognised framework requirements.

A map from published requirements to what we actually do, with room to show live evidence counts. This is a locator for evidence — not a certification by ISO, SOC, PCI or any auditor.

The part that matters

Why the record holds up

A log that lives only on your server is not evidence. Anyone who compromises that machine can edit it, and an auditor knows this. Three properties are what turn a log into something defensible.

01

It leaves your server on a short schedule

Sealed records are copied into off-box storage your server cannot reach or modify. Someone who later takes full control of your machine still cannot touch what has already left it. We ship frequently on purpose; we do not claim an unmeasured “within seconds” figure as a hard promise.

02

It cannot be deleted, including by us

Off-site storage uses a retention lock in compliance mode. This is enforced by the storage provider rather than by WAFRA software, which is deliberate — a lock we could disable would be a promise, not a control. Neither our staff nor our administrators can shorten or remove it.

03

Any alteration is provable

Each record carries a cryptographic fingerprint that includes the previous record’s fingerprint. Edit anything and the chain breaks at exactly that point. Each day’s chain is anchored into locked storage so the whole sequence cannot be quietly regenerated. You can verify all of it with standard tools, without any WAFRA software.

Why we keep saying “including us”

It is the difference between a security feature and a security guarantee. Anything we retain the ability to switch off is only as strong as our own internal controls — and an auditor assessing you will treat it that way. Locks we cannot lift are worth more to you precisely because they constrain us too.

Transparency

Who can see and do what

Attribution is only meaningful if it covers us as well as you.

You

Full visibility of your own servers and sites: posture, findings, protection settings, the complete event timeline, and evidence export. Nothing about your servers is hidden from you.

WAFRA staff

Access is granted by role rather than held by everyone, and each staff action is recorded against the individual who took it. Elevated access is time-limited and expires on its own rather than waiting to be revoked.

Acting on your behalf

When our staff operate inside your account to support you, the session is marked as exactly that and carries the reason they gave. Your record distinguishes your actions from ours.

Day to day

Using the Vault

Everything below is in your dashboard, on both web and mobile.

Checking on things. Open Security. The posture screen answers “is anything wrong right now” without you needing to interpret anything. If a score is not perfect, the reasons are listed underneath it.

When something happens. Related events are grouped into a single incident rather than arriving as a dozen separate alerts, so you see “someone is trying to break into this site” instead of a list of failed logins. Each incident keeps its own timeline and notes.

Protecting a website. Each site can be set independently. You can put protection in a monitoring mode first, watch what it would have blocked against your real traffic, and only then switch it on. Turning a defence on blind is how legitimate customers get locked out.

Regular summaries. A digest of your security activity can be emailed on a schedule you choose, with the underlying records attached. You can change the frequency or switch it off.

Producing evidence. Choose a server and a date range and export a bundle. It contains the events, the material needed to verify they were not altered, and a summary written to be read by someone who knows nothing about WAFRA.

Customer guide

How to use Security Center on your server

Web: open your server → Security. Mobile: Server → Security. Same pillars, same order, same language.

Posture

The landing view. A score with the specific reasons behind it, and whether each protection is currently confirmed running. “No report” means we cannot confirm it right now — that is deliberately not shown as healthy.

Incidents

Findings that need a person: several events read together. You can add notes and mark investigating or contained. Closing an incident is done by WAFRA security staff, because closing asserts the problem was handled.

Threat detection

Malware scanning with real detail — paths scanned, files examined, duration, full log. Findings are quarantined rather than deleted, with a custody record so a false positive can be restored. A clean scan still produces a full report so you can prove scanning happened.

Website protection

Per-site brute-force and rate limiting. Leave a new site on Monitor for about a week, check the timeline for false positives, then switch to Enforce. WordPress login and XML-RPC abuse are jailed and rate-limited by default; fully disabling XML-RPC is an opt-in for sites that do not use Jetpack or the WordPress apps.

Server access

Addresses that repeatedly fail SSH, panel or mail login are banned automatically. Every ban and unban is recorded. Add your office IP to the allow list so a mistyped password never locks you out of your own server.

Outbound abuse

We watch traffic your server sends out for spam, scanning or botnet patterns — connection metadata only (destination, port, process). We do not read your site content, databases or email.

Evidence & audit

The tamper-evident timeline, email digests on a schedule you choose, and exports for auditors. Turning email off stops the email only — recording continues. A quiet period still sends a digest so a missing email always means delivery trouble, not “nothing happened”.

Compliance mapping

For each control in a published framework: what it asks for, what we do, and how to find evidence. This is not a certification and does not mean a certification body has audited WAFRA.

Common questions, answered straight

Why is my score not 100? Read the reasons under the score — every deduction has a specific cause.

Do you look at my data? Staff access is possible, always logged, always visible in your timeline with the named person and written reason.

Can you delete my logs? Not within the retention period. The off-site copy is under a lock we cannot shorten.

Am I protected from DDoS? Application-level abuse and credential stuffing are handled on the server. Huge volumetric floods are absorbed by network/CDN capacity upstream — no honest host claims unlimited protection there.

Straight answers

What this does not do

Every security page lists strengths. The useful ones also list the edges, because that is what a serious reader checks first.

It does not make your server unbreakable

No provider can promise that, and you should be sceptical of one who does. What this gives you is fast detection, real containment, and a record that survives the incident. A weak password on your own application is still a weak password.

Very large network floods depend on upstream capacity

Application-level abuse, brute-force attempts and request floods are handled directly. Genuinely massive volumetric attacks are absorbed at the network edge by our infrastructure providers. That capacity is real and substantial, but it is theirs, not something we built — and no honest provider claims unlimited protection here.

The record proves what was observed, not everything that occurred

Evidence is tamper-evident from the moment it is created. It cannot show something that was never detected in the first place. Anyone telling you their logging proves nothing was missed is overselling.

Protection is staged deliberately, not switched on everywhere at once

New defences run in a watch-only mode first so we can see what they would have blocked against real traffic before they block anything. Existing servers stay off until we enable them on purpose. This is slower on purpose. A defence deployed at full strength on day one eventually blocks a real customer, and that erodes trust faster than the attack it prevented.

Some controls are still being battle-tested

WordPress and website login protection are live in watch/report mode on servers where security is enabled. Central file-integrity / SIEM coverage for the whole fleet is being enrolled server by server. We will not claim fleet-wide coverage ahead of that enrolment.

Questions

Questions people actually ask

Can WAFRA delete my security records?

No. Records are written to storage with a retention lock in compliance mode. That setting cannot be shortened, lifted or bypassed by anyone — not by our staff, not by our administrators, and not by anyone who compromises our systems. It is enforced by the storage provider, not by our software, which is the entire point: a control we could turn off would not be worth much.

How would I know if a record had been altered?

Each record is sealed with a cryptographic fingerprint that includes the fingerprint of the record before it, forming a chain. Changing any record breaks the chain from that point onward, and the break identifies exactly which record was touched. Each day the chain is anchored into locked storage, so the sequence cannot be quietly rebuilt afterwards.

Do I have to take your word for any of this?

No, and you should not. The verification uses standard cryptographic hashing, so you or your auditor can re-compute it independently with ordinary tools. No WAFRA software is required. Proof you have to take our word for is not proof.

What happens if my server is compromised?

Anyone who takes control of a machine can rewrite the logs on that machine. That is why sealed records are copied into storage your server cannot reach or modify. An attacker who fully owns your server still cannot alter what has already left it — so the record of how they got in can survive them. Shipping runs on a short schedule; we do not publish an unmeasured “within seconds” SLA.

Can WAFRA staff access my server?

Yes, when supporting you — and every such access is recorded with the staff member’s identity, the time, and the reason they gave. Sessions where staff act on your behalf are marked as exactly that, so your record distinguishes what you did from what we did for you. Elevated access is time-limited and expires on its own.

What can I hand to a regulator or an insurer?

An evidence bundle for any server and any date range. It contains the events themselves in both human-readable and machine-readable form, the fingerprints and daily anchors needed to verify none of it was altered, and a summary. It is designed to be understood without any explanation of how WAFRA works internally.

Does any of this slow my server down?

Scanning is scheduled outside peak hours by default and can be rescheduled. Record-keeping is asynchronous — it never sits in the path of a request, and if the off-site copy is briefly unavailable, records queue locally and ship when it recovers rather than blocking anything.

How long are records kept?

Retention depends on the type of record, with security and access records kept longest. Because retention is enforced by a lock, the practical effect is that a record cannot be removed early even by mistake.

Questions we have not answered here

If you are completing a security questionnaire, preparing for an audit, or responding to a customer of your own who is asking hard questions, get in touch. We would rather answer specifics than have you guess from a marketing page.