Staff
Each person has an account with its own permissions. Password resets, authenticator apps, passkeys and optional office IP restrictions add further controls.
Security
Staff, customers, billing modules and VPN server agents authenticate independently. A credential issued for one part of the service cannot be used in another.
Customer, billing and server credentials can perform only their intended tasks and cannot open staff controls.
Each person has an account with its own permissions. Password resets, authenticator apps, passkeys and optional office IP restrictions add further controls.
Customers can sign in directly or through a short-lived billing link. They can manage only the profiles and locations assigned to their service.
Each connection has its own API token. Direct customer login uses a separate signing secret when enabled. Write requests are signed or restricted to the billing server’s public IP address.
The agent accepts only authenticated VPN, health and maintenance tasks supported by VPN Dashboard. Requests expire and cannot be reused, so the connection cannot be used as a general-purpose remote shell.
A support report can include software versions, service health and recent activity. It leaves out or hides sensitive values:
Email the affected URL, reproduction steps and likely impact. Do not include customer data or live credentials.