Security
Isolation first, then defense in depth
Per-site containers mean one compromised site cannot reach another. On top of that: Unicorn Shield stopping abuse at the edge, malware scanning across the whole fleet, a firewall with guard rails, and sign-in that a stolen password is not enough to get through.
Isolation by default
Every site in its own container
Each site runs in its own container, with its own user, its own PHP-FPM, and its own limits on CPU, memory, disk, and processes. Nothing is shared between tenants, so a site that gets compromised is a contained problem rather than everyone’s problem.
- Its own user, its own ports, and its own resource limits
- No shared PHP-FPM pool, so one site cannot read another through it
- File access is jailed per tenant, including bulk moves and copies
- The panel itself holds only the access it needs, not the run of the host
Edge & network
Stop abuse before it reaches a tenant
Unicorn Shield
Watches for the attacks that actually arrive: WordPress login attempts, SSH brute force, panel sign-in attempts, and malicious request patterns at the proxy. Offenders are banned at the firewall rather than merely logged.
See and change who is banned
Every banned address is listed with the country it came from, and you can ban or lift one by hand. Bans survive a restart, and the list is pruned so it matches what the firewall is really holding.
Repeat offenders stop early
An address that keeps failing is banned at the firewall, so a brute-force run stops reaching the site or the database after the first few attempts.
Firewall with guard rails
Write your own rules without being able to lock yourself out: the panel’s own rules are protected, a custom SSH port is detected and kept open, IPv6 counterparts are added for you, and one command gets you back if a rule goes wrong.
Malware
One view of every infected
file in the fleet
Every scanner reports in
Each host running the scanner contributes its findings to one list, so you look in a single place rather than server by server. ClamAV and Linux Malware Detect both supported.
Act on it where you found it
Quarantine, restore, whitelist, or delete a finding without leaving the view, whether you came from the fleet list or from one site’s own tab.
Scans that show their work
Live progress with elapsed time and the hits found so far, so a scan that is taking a while never looks like a scan that has hung.
Signing in
A stolen password is not enough
Passkeys
Sign in without a password at all, using the device you already unlock with your face or your fingerprint.
2FA that covers password reset
Second factor is asked for on reset too, so someone with access to the email inbox still cannot take the account.
Sessions bound to the browser
The session is tied to the browser it was created in, and that is checked on every request, so a stolen cookie replayed from somewhere else fails rather than working quietly.
Nothing leaked on failure
Sign-in errors never reveal whether an address has an account, and repeated attempts hit a cooldown.
Re-authentication for security changes
Turning off 2FA or changing passkeys asks for the password again, so a borrowed logged-in session cannot weaken the account.
Collaborators, on your terms
Someone helping run a site gets the tools the owner has, without the ability to destroy anything. How many collaborators an account can add is set by its package.
Access & API
Keys, not shared credentials
Per-account API keys
An account’s key carries exactly the access that account has in the panel, so an integration cannot reach further than the person who made it.
A key per server
Cross-server calls carry their own per-server keys with their own scopes, rather than every host sharing one master credential.
Short-lived tokens
File downloads and single sign-on into the admin tools are gated by tokens that expire, rather than a link that works forever.
License locked to the install
A key binds to the first panel that validates it, so a leaked key cannot be quietly reused on a second panel. Moving to new hardware is a one-line unlock from support.
Data & visibility
Where your secrets sit,
and what you can see
Backup secrets locked down
Credentials for remote destinations like S3 and BunnyCDN are encrypted at rest with AES-256-GCM before they reach the database, and are never handed back to the browser once saved. Cross-server transfers ride the same authenticated pipe as every other panel call: no shared filesystem, and no SSH between hosts.
Activity you can see
Sign-in history on your own account, activity per server in the Servers view, and a notifications drawer for events across your accounts. The full command log lives on disk for operators who want the deeper trail.
Contain the blast radius by design.
Per-site containers, Unicorn Shield, fleet-wide malware scanning, a firewall with guard rails, and passkey sign-in.