Security

Security across your dashboard and VPN servers.

Staff, customers, billing systems and server agents use separate access paths. Each one is limited to the work it needs to perform.

StaffIndividual accounts and permissions
CustomersAccess limited to their own service
BillingRestricted and authenticated requests
ServersRecognised jobs only

Trust boundaries

Each connection has one job.

Access does not carry across from one part of the service to another.

StaffDashboard access
VPN DashboardPermissions and audit trail
Server agentRecognised jobs only
BillingService actions only
Customer areaOwn service only
VPN profilesAssigned access

Access boundaries

Separate controls for each part of the service.

A customer login cannot reach staff tools. A billing connection cannot administer the dashboard. A server job cannot become a general remote command.

01

Staff access

Give each member of staff their own account.

Permissions limit what each account can manage. Password resets, authenticator apps, passkeys and optional office IP restrictions provide additional sign-in controls.

02

Customer access

Customers can only reach their own VPN service.

Customers can sign in directly or use a short-lived link from your billing system. They can manage the profiles and locations assigned to their account, but cannot reach staff or server administration.

03

Billing connections

Billing requests are authenticated and restricted.

Each connection has its own API token. Direct customer login uses a separate signing secret when enabled. Write requests are signed or restricted to the public IP address of your billing server and can only perform supported account actions.

04

VPN servers

The agent only accepts recognised jobs.

Agent requests are HMAC-authenticated and sent over HTTPS. Short-lived tokens, replay protection and capability checks restrict VPN, health and maintenance jobs. The agent does not provide a general remote shell.

Support information

Generated support information is redacted.

Generated support information can include software versions, service health and recent activity needed to diagnose a problem. Sensitive values are excluded or redacted.

  • Private keys and VPN configurations are excluded
  • Billing tokens and sign-in secrets are excluded
  • Server credentials are excluded
  • Customer password values are excluded

Report a problem

Found a security issue?

Email the affected URL, steps to reproduce the problem and the likely impact. Do not include customer data or live credentials.

Report by email