Security

Isolation first, then defense in depth

Per-site containers mean one compromised site cannot reach another. On top of that: Unicorn Shield stopping abuse at the edge, malware scanning across the whole fleet, a firewall with guard rails, and sign-in that a stolen password is not enough to get through.

Isolation by default

Every site in its own container

Each site runs in its own container, with its own user, its own PHP-FPM, and its own limits on CPU, memory, disk, and processes. Nothing is shared between tenants, so a site that gets compromised is a contained problem rather than everyone’s problem.

  • Its own user, its own ports, and its own resource limits
  • No shared PHP-FPM pool, so one site cannot read another through it
  • File access is jailed per tenant, including bulk moves and copies
  • The panel itself holds only the access it needs, not the run of the host

Edge & network

Stop abuse before it reaches a tenant

Unicorn Shield

Watches for the attacks that actually arrive: WordPress login attempts, SSH brute force, panel sign-in attempts, and malicious request patterns at the proxy. Offenders are banned at the firewall rather than merely logged.

See and change who is banned

Every banned address is listed with the country it came from, and you can ban or lift one by hand. Bans survive a restart, and the list is pruned so it matches what the firewall is really holding.

Repeat offenders stop early

An address that keeps failing is banned at the firewall, so a brute-force run stops reaching the site or the database after the first few attempts.

Firewall with guard rails

Write your own rules without being able to lock yourself out: the panel’s own rules are protected, a custom SSH port is detected and kept open, IPv6 counterparts are added for you, and one command gets you back if a rule goes wrong.

Malware

One view of every infected
file in the fleet

Every scanner reports in

Each host running the scanner contributes its findings to one list, so you look in a single place rather than server by server. ClamAV and Linux Malware Detect both supported.

Act on it where you found it

Quarantine, restore, whitelist, or delete a finding without leaving the view, whether you came from the fleet list or from one site’s own tab.

Scans that show their work

Live progress with elapsed time and the hits found so far, so a scan that is taking a while never looks like a scan that has hung.

Signing in

A stolen password is not enough

Passkeys

Sign in without a password at all, using the device you already unlock with your face or your fingerprint.

2FA that covers password reset

Second factor is asked for on reset too, so someone with access to the email inbox still cannot take the account.

Sessions bound to the browser

The session is tied to the browser it was created in, and that is checked on every request, so a stolen cookie replayed from somewhere else fails rather than working quietly.

Nothing leaked on failure

Sign-in errors never reveal whether an address has an account, and repeated attempts hit a cooldown.

Re-authentication for security changes

Turning off 2FA or changing passkeys asks for the password again, so a borrowed logged-in session cannot weaken the account.

Collaborators, on your terms

Someone helping run a site gets the tools the owner has, without the ability to destroy anything. How many collaborators an account can add is set by its package.

Access & API

Keys, not shared credentials

Per-account API keys

An account’s key carries exactly the access that account has in the panel, so an integration cannot reach further than the person who made it.

A key per server

Cross-server calls carry their own per-server keys with their own scopes, rather than every host sharing one master credential.

Short-lived tokens

File downloads and single sign-on into the admin tools are gated by tokens that expire, rather than a link that works forever.

License locked to the install

A key binds to the first panel that validates it, so a leaked key cannot be quietly reused on a second panel. Moving to new hardware is a one-line unlock from support.

Data & visibility

Where your secrets sit,
and what you can see

Backup secrets locked down

Credentials for remote destinations like S3 and BunnyCDN are encrypted at rest with AES-256-GCM before they reach the database, and are never handed back to the browser once saved. Cross-server transfers ride the same authenticated pipe as every other panel call: no shared filesystem, and no SSH between hosts.

Activity you can see

Sign-in history on your own account, activity per server in the Servers view, and a notifications drawer for events across your accounts. The full command log lives on disk for operators who want the deeper trail.

Contain the blast radius by design.

Per-site containers, Unicorn Shield, fleet-wide malware scanning, a firewall with guard rails, and passkey sign-in.