See every change before your servers do.

RespireCloud is a self-hosted control panel for websites, mail, DNS, databases, containers and backups. Every change is a typed action you can preview, the risky ones ask you to confirm it is really you, and all of them land in an audit log nobody can quietly edit.

In development: 29 modules and 769 actions built and tested in our lab. Ask for early access.

Add a domain

domains.create

Nothing applied yet

create domain:shop.example.com + kind=addon account=alice

Then, from alice's plan:

  1. dns Zone with 7 records from the default template
  2. web PHP 8.3 site, checked with nginx -t and php-fpm -t
  3. ssl Certificate for shop.example.com and www
Apply changes
Example: the plan for a new domain, and what the other modules do once you apply it.

The panel

The RespireCloud panel overview: servers with live status, live activity and installed modules, on frosted glass over a violet aurora. The RespireCloud panel overview: servers with live status, live activity and installed modules, on frosted glass over a violet aurora.

The panel overview, captured from a lab install. Walk through every screen.

Built so that a panel bug does not become a server breach.

Most control panels let their web interface run commands as root. RespireCloud splits the panel in two, and the half that faces the internet has nothing to run.

  1. Browser, CLI or API token

    Signs in with a passkey or a scoped token. Every method and path is denied unless an action allows it.

  2. respirecloudd unprivileged user

    Checks permission, plan limits and risk; validates parameters against the action's schema; writes the audit row.

  3. Bus TLS 1.3, per-server keys

    Each server can only receive its own operations. A compromised server cannot see another's.

  4. respirecloud-agent root, minimal

    Runs typed operations from module manifests only. Commands are argument lists, never shell strings.

Changes are previewed, validated and reversible

Configuration is never edited in place. A website change goes through these six steps. Mail, SSH and the firewall are checked the same way by postfix check, sshd -t and nft -c, and a firewall change undoes itself unless you confirm it.

  1. Preview. Ask for a dry run and get the per-file diff before anything happens.

  2. Render. The change becomes a new, complete configuration generation beside the live one.

  3. Validate. nginx -t and php-fpm -t check the exact files that would go live.

  4. Swap. One atomic switch makes the new generation live.

  5. Health check. Every changed site is requested through the server's own nginx.

  6. Keep or roll back. Any failure flips back to the previous generation on its own. The last 30 stay available.

Every account is a real Linux user

Each hosting account gets its own user, its own systemd slice with CPU, memory, IO and process limits, its own PHP-FPM pool, and disk quotas where the filesystem supports them. Isolation is part of the base product, not an extra licence.

Every action is on the record

Who did what, from where, as whom, with the parameters, in a hash-chained log. A check walks the chain and names the first row that does not match. Secrets are redacted before anything is written.

Passkeys first

Sign in with a touch. Passwords and codes are the fallback, two-step sign-in is required for administrators and resellers, and destructive actions ask again.

How RespireCloud is secured

Everything a hosting server needs, as modules.

Each area is a module with its own manifest, permissions and limits. Here is what is built and what is coming, without rounding up.

Coming from cPanel or Plesk?

2026 brought cPanel its seventh price rise in a row and an authentication bypass rated 9.8 that was exploited in the wild (CVE-2026-41940). Plesk prices went up by about a quarter in January. RespireCloud is a fresh start on a smaller, stricter core.

Familiar model
Administrators, resellers, customers and sub-users, with plans and limits, the way hosting businesses already work.
A modern panel
One fast app on desktop and phone, a command palette (Ctrl K) for everything, dark and light themes, and a full API for every action.
Migrations
Importers for cPanel and Plesk backups are planned. Until they ship, talk to us about moving.

Fifteen screens, one guided tour.

From the first setup token to acting as a customer, every step taken from the real panel.

See it on a real server.

We will walk you through RespireCloud on a lab install and talk about what your servers need.