Security
In preview
Defence in layers, starting with a web tier that cannot run commands on your servers. Everything else stacks on top of that.
Built and lab-tested
- Privilege separation: the panel runs as an unprivileged user and can only ask the root agent for operations declared in a module manifest, with typed parameters.
- Sign-in with passkeys first, passwords (Argon2id), authenticator codes and recovery codes. Two-factor sign-in is required for administrators and resellers.
- Step-up confirmation for risky actions, a device list with instant sign-out, scoped API tokens and lockout after repeated failures.
- An nftables firewall with presets, rate limits and country rules. Every change arms a rollback timer, so a bad rule cannot lock you out.
- CrowdSec intrusion prevention. Nothing is shared with the CrowdSec network unless you turn it on.
- Malware scanning with ClamAV and YARA, with quarantine and restore.
- File-integrity baselines for system binaries and configuration, hardening checks with a dry-run fix, and a listening-port audit.
- Unattended security upgrades with a service health watch that restarts anything an upgrade knocked over.
- A security score from 0 to 100 with suggested fixes, and a hash-chained audit log you can verify.
Coming soon
- A web application firewall per site (Coraza with the OWASP Core Rule Set) and a proof-of-work bot challenge.
- Geo-blocking and rate limits per site.
- Rootkit scans and real-time file scanning.
Dedicated screens for this area are being built on the RespireCloud design system. Today every action has a generated form in the panel, is one keystroke away in the command palette (Ctrl K), and is callable through the API.