Security, from the first line of code

Control panels are a favourite target because one bug can hand over every site on a server. RespireCloud is built so that the part facing the internet has as little power as possible, and everything it does is on the record.

  1. Browser, CLI or API token

    Signs in with a passkey or a scoped token. Every method and path is denied unless an action allows it.

  2. respirecloudd unprivileged user

    Checks permission, plan limits and risk; validates parameters against the action's schema; writes the audit row.

  3. Bus TLS 1.3, per-server keys

    Each server can only receive its own operations. A compromised server cannot see another's.

  4. respirecloud-agent root, minimal

    Runs typed operations from module manifests only. Commands are argument lists, never shell strings.

Lessons we built in

Authentication that only checked some requests
In 2024 an open-source panel was taken over on thousands of servers because its authentication checked only some HTTP methods. RespireCloud denies every method and path unless an action allows it.
User input reaching a shell
The agent runs programs as argument lists from typed operations. There is no shell string for a parameter to escape from.
A stolen session doing damage
High-risk and critical actions need a fresh passkey or code, and you can end any signed-in device from your Security page.
A bad firewall rule locking you out
Every firewall change arms a rollback timer. If you do not confirm it, the previous rules come back.

Layer by layer

The panel

  • Unprivileged web tier; root work only through typed agent operations
  • Deny by default on every method and path
  • Passkeys, Argon2id passwords, authenticator and recovery codes
  • Two-step sign-in required for administrators and resellers
  • Step-up for high-risk actions, session rotation
  • Device list with instant sign-out; scoped, revocable API tokens
  • Hash-chained audit log with verification
  • Single sign-on (OIDC and SAML) (coming soon)
  • Sign-in anomaly alerts (coming soon)
  • An external anchor for the audit chain (coming soon)

Servers

  • Per-server keys on a TLS 1.3 bus; each server sees only its own operations
  • nftables firewall with presets and an anti-lockout rollback timer
  • CrowdSec intrusion prevention, local by default
  • File-integrity baselines and hardening checks
  • Unattended security upgrades with a service health watch
  • SSH hardening validated with sshd -t
  • Rootkit scans (coming soon)
  • Real-time file scanning (coming soon)

Sites

  • Per-account Linux users, slices and PHP-FPM pools
  • open_basedir to the home; no symlinks to other owners' files
  • Snippet allow-lists checked on the panel and again on the server
  • Malware scanning (ClamAV and YARA) with quarantine
  • Web application firewall (Coraza and OWASP CRS) (coming soon)
  • Proof-of-work bot challenge (coming soon)
  • Per-site rate limits and geo rules (coming soon)

Mail

  • DKIM keys made on the server, ARC sealing
  • SPF, DMARC, MTA-STS and TLS-RPT published automatically
  • Login must match the sender; open relay refused
  • Outbound SMTP blocked for hosting accounts at the firewall
  • ClamAV for mail (coming soon)
  • DANE (coming soon)
  • Automatic hold on outbound spikes (coming soon)

DNS and certificates

  • One-click DNSSEC
  • Certificate keys generated on the node
  • ARI-scheduled renewals that never drop a working certificate
  • Secondaries with TSIG (coming soon)
  • CT log monitoring (coming soon)

Data

  • Encrypted restic repositories, one per account and target
  • Immutable backups with S3 object lock
  • Secrets in a vault, redacted from logs and the audit trail
  • Point-in-time database recovery (coming soon)
  • Server-level disaster recovery (coming soon)

Built and lab-tested Coming soon

The Confirm it is you dialog asking for a passkey before deleting a hosting account.

Found a vulnerability?

Email us with the subject "RespireCloud security report". Please do not test against servers you do not own. The technical detail is in the security model.