Scody Cloud
xPanel

Security that produces evidence, not just a green checkmark

xPanel's security model separates what the platform enforces on every account by default from what you configure for your own team and workloads. Both are documented plainly here — no fabricated certifications, no invented audits.

Enforced by the platform

What you don't have to configure

These apply to every account on xPanel regardless of settings.

Signed event bus

Every operation performed through xPanel — a change request, a reconciliation action, an administrative login — is emitted as a signed event, so its origin and integrity can be verified after the fact.

Tamper-evident evidence ledger

Signed events are written to an append-only ledger. Altering a past entry breaks its signature chain, so the ledger can be trusted as a record of what actually happened.

Per-account isolation and quotas

Each account is isolated at the platform level with enforced CPU, memory, storage and process limits, so one account cannot exhaust resources meant for another.

Platform-level firewalling

Network-level filtering sits in front of every node, independent of what an individual account configures, to block traffic patterns the platform itself doesn't allow through.

Yours to set

What you configure

xPanel gives you the controls; how you use them for your team and applications is your decision.

Role-based access control

You define who on your team can view, change or administer which accounts and nodes. The platform enforces the roles you set; it doesn't choose them for you.

Multi-factor enforcement

MFA is available on every account and can be required for your team. Whether it's optional or mandatory for a given role is your policy to set.

Application-level access

SSH keys, database credentials and API tokens for your sites are yours to issue, rotate and revoke.

Have a security or compliance question?

Tell us what you need to verify about how xPanel handles access and evidence, and we'll answer directly.