Security and data protection
Last updated 7 Oct 2026
Your sites open nothing
Sites connect by sending events out to onepanelforall. No port, endpoint or database is opened to us. The optional database agent runs on your server, makes only outgoing HTTPS requests and uses a read-only database user you create.
Every event is signed
Server events are signed with HMAC-SHA256 using the site's secret, with a timestamp and a single-use nonce, so they cannot be forged or replayed. The site's secret is shown once and can be rotated at any time. The browser script uses a public key that only works from the site's own domains.
Secrets are never collected
The script never reads password, card, hidden or file fields. The agent and the panel refuse columns whose names look like passwords, hashes, tokens, keys or card data, and the panel drops values that look like credentials even when they arrive in other columns.
Encryption and storage
All traffic uses HTTPS (TLS). Data is stored on servers in the European Union. Settings such as mailbox passwords and payment keys are stored encrypted. Databases are backed up daily and the backups are checked.
Access control
Every organization's data is isolated from the others. People get a role (owner, admin, member, viewer) per organization, every change is written to an audit log, and the platform's administration is behind an additional sign-in layer.
Retention and deletion
Each plan sets how long data is kept; older data is deleted automatically. A person's data can be deleted on request, and deleting an organization deletes all of its data.
Providers we use
| Provider | What for |
|---|---|
| Cloudflare | network protection, HTTPS, email routing |
| Contabo | servers in the European Union |
| Stripe or NETOPIA Payments | card payments (we never see card numbers) |
| SmartBill | invoices |
| Google Firebase | phone notifications |
Reporting a problem
Write to [email protected] with the subject "Security" or see /.well-known/security.txt.