Security

Separate credentials and permissions for every connection

Staff, customers, billing modules and VPN server agents authenticate independently. A credential issued for one part of the service cannot be used in another.

StaffIndividual accounts and permissions
CustomersAccess limited to their own service
BillingRestricted and authenticated requests
ServersOnly approved VPN and maintenance tasks

Separate access for each connection

StaffDashboard access
VPN DashboardPermissions and activity history
Server agentApproved tasks only
BillingCustomer service changes only
Customer areaOwn service only
VPN profilesOnly the profiles included with that service

What each account can access

Customer, billing and server credentials can perform only their intended tasks and cannot open staff controls.

Staff

Each person has an account with its own permissions. Password resets, authenticator apps, passkeys and optional office IP restrictions add further controls.

Customers

Customers can sign in directly or through a short-lived billing link. They can manage only the profiles and locations assigned to their service.

Billing connections

Each connection has its own API token. Direct customer login uses a separate signing secret when enabled. Write requests are signed or restricted to the billing server’s public IP address.

VPN servers

The agent accepts only authenticated VPN, health and maintenance tasks supported by VPN Dashboard. Requests expire and cannot be reused, so the connection cannot be used as a general-purpose remote shell.

Diagnostics exclude secrets

A support report can include software versions, service health and recent activity. It leaves out or hides sensitive values:

  • Private keys and VPN configurations
  • Billing tokens and sign-in secrets
  • Server credentials
  • Customer passwords

Report a security issue

Email the affected URL, reproduction steps and likely impact. Do not include customer data or live credentials.

Report by email