Staff access
Give each member of staff their own account.
Permissions limit what each account can manage. Password resets, authenticator apps, passkeys and optional office IP restrictions provide additional sign-in controls.
Security
Staff, customers, billing systems and server agents use separate access paths. Each one is limited to the work it needs to perform.
Trust boundaries
Access does not carry across from one part of the service to another.
Access boundaries
A customer login cannot reach staff tools. A billing connection cannot administer the dashboard. A server job cannot become a general remote command.
Staff access
Permissions limit what each account can manage. Password resets, authenticator apps, passkeys and optional office IP restrictions provide additional sign-in controls.
Customer access
Customers can sign in directly or use a short-lived link from your billing system. They can manage the profiles and locations assigned to their account, but cannot reach staff or server administration.
Billing connections
Each connection has its own API token. Direct customer login uses a separate signing secret when enabled. Write requests are signed or restricted to the public IP address of your billing server and can only perform supported account actions.
VPN servers
Agent requests are HMAC-authenticated and sent over HTTPS. Short-lived tokens, replay protection and capability checks restrict VPN, health and maintenance jobs. The agent does not provide a general remote shell.
Support information
Generated support information can include software versions, service health and recent activity needed to diagnose a problem. Sensitive values are excluded or redacted.
Report a problem
Email the affected URL, steps to reproduce the problem and the likely impact. Do not include customer data or live credentials.