Cafora Docs
Security

Security Best Practices

Comprehensive security recommendations for your Cafora Minecraft server.

Server Security Checklist

  • Keep server software updated
  • Keep all plugins updated
  • Use a permissions plugin instead of OP
  • Enable whitelist for private servers
  • Configure regular automatic backups
  • Monitor server console for suspicious activity
  • Use strong passwords for your Cafora account
  • Enable 2FA on your Cafora account
  • Review firewall rules periodically
  • Do not share API keys publicly
  • Do not attempt to probe or connect to the origin IP (connections are dropped)

Network-Layer Protection

Cafora handles most of the network attack surface for you at the infrastructure layer:

  • Minecraft and SFTP traffic is scrubbed by TCPShield Sentry
  • Panel and API traffic goes through Cloudflare Tunnel
  • The origin IP does not accept direct Minecraft / SFTP connections

So your focus should be on application-layer security: plugin vulnerabilities, permission configuration, and account credentials. See DDoS Protection.

Incident Response

If you suspect a security breach:

  1. Stop the server immediately
  2. Change your Cafora account password
  3. Review server logs for unauthorized activity
  4. Restore from a known-clean backup
  5. Contact Cafora support

On this page