Security and data protection

Last updated 7 Oct 2026

Your sites open nothing

Sites connect by sending events out to onepanelforall. No port, endpoint or database is opened to us. The optional database agent runs on your server, makes only outgoing HTTPS requests and uses a read-only database user you create.

Every event is signed

Server events are signed with HMAC-SHA256 using the site's secret, with a timestamp and a single-use nonce, so they cannot be forged or replayed. The site's secret is shown once and can be rotated at any time. The browser script uses a public key that only works from the site's own domains.

Secrets are never collected

The script never reads password, card, hidden or file fields. The agent and the panel refuse columns whose names look like passwords, hashes, tokens, keys or card data, and the panel drops values that look like credentials even when they arrive in other columns.

Encryption and storage

All traffic uses HTTPS (TLS). Data is stored on servers in the European Union. Settings such as mailbox passwords and payment keys are stored encrypted. Databases are backed up daily and the backups are checked.

Access control

Every organization's data is isolated from the others. People get a role (owner, admin, member, viewer) per organization, every change is written to an audit log, and the platform's administration is behind an additional sign-in layer.

Retention and deletion

Each plan sets how long data is kept; older data is deleted automatically. A person's data can be deleted on request, and deleting an organization deletes all of its data.

Providers we use

Provider What for
Cloudflare network protection, HTTPS, email routing
Contabo servers in the European Union
Stripe or NETOPIA Payments card payments (we never see card numbers)
SmartBill invoices
Google Firebase phone notifications

Reporting a problem

Write to [email protected] with the subject "Security" or see /.well-known/security.txt.