We describe security by how the panel works, not by a feature list.
The panel was designed with KVKK-compliant data processing in mind: client data never mixes between resellers, provider keys are shown to no one, and every action is logged. Everything below is active in the panel today.
Enter the 6-digit code from your authenticator app.
| Time | User | Action |
|---|---|---|
| 14:31 | ayse@ornekajans | Hosting account created |
| 14:32 | ayse@ornekajans | DNS records written · Cloudflare |
| 14:33 | mert@ornekajans | Hosting password viewed |
| 14:35 | ayse@ornekajans | Delivery · WhatsApp link created |
| 14:40 | mert@ornekajans | Signed in · 2FA |
Active safeguards
In four areas, by their technical names.
Identity and sessions
Mandatory 2FA
Two-factor authentication with TOTP is mandatory for admin accounts.
argon2id
Panel user passwords are stored hashed with argon2id.
Login rate limiting
Failed login attempts are rate-limited; repeated attempts are temporarily blocked.
CSRF protection
Every request that changes data is verified with a CSRF token.
Secrets and data
AES-256-GCM
Provider credentials and hosting passwords are stored encrypted; the key is not kept in the database.
Provider keys stay hidden
WHM, Cloudflare and domain provider keys are used only on the server side; resellers and team members cannot see them.
Reseller isolation
Every query is limited to the accessing user's scope of permissions; one reseller cannot see another reseller's records.
Encrypted backups
Panel database backups are taken encrypted.
KVKK-compliant data processing
Personal data is collected only to the extent needed for the service, kept separately per reseller, and access is logged.
Permissions and auditing
Role permissions
Team members work within their role permissions; they cannot see settings or reseller management. They can reveal a hosting password, and every reveal is logged.
Append-only audit log
Who did what, when, on which record; entries are only ever appended.
One-time cPanel login
cPanel is accessed not with a stored password but with a one-time session each time.
Origin behind Cloudflare
The panel's own server runs behind Cloudflare; the origin IP is not publicly exposed.
Account, payment and approval
Bot protection
The login screen is protected against automated login attempts with Cloudflare Turnstile.
Secure card payment
Card payments are processed through the payment institution's secure infrastructure; bank transfer (EFT) is also available.
e-Invoice / e-Archive
Approved invoices are issued as official e-Invoices or e-Archive invoices through an integrated e-invoicing system; only the fields required for invoicing are collected.
Approved critical actions
DNS fixes, restores from backup and draft invoices are not applied without your approval.
What don't we claim?
Trust starts with claims that can be verified.
- We don't use unverified claims such as uptime percentages, "24/7" or a certification we don't hold.
- We describe the logs as "append-only", not "immutable"; that is the technically accurate term.
- This page lists only the safeguards that are active in the panel today.
Questions about security
For all questions, see the FAQ page or message us on WhatsApp.
Is my data secure?
The panel runs behind Cloudflare, and the login screen is protected against bot attacks with Cloudflare Turnstile. 2FA is mandatory for admin accounts, and the team works with role-based permissions. Provider credentials and hosting passwords are encrypted with AES-256-GCM, every action is kept in an append-only log, and each reseller's data is kept separate. Details on the security page.
How does the panel help with my KVKK obligations?
The panel was designed with KVKK-compliant data processing, taking into account the data security obligations under KVKK (Law No. 6698): personal data is collected only to the extent needed for the service, each reseller's data is kept separately, secrets are encrypted, and access is written to the audit log. You are the data controller for your clients' data; WebJoiner acts as data processor on your instructions, and this relationship is governed by the data processing annex of the Reseller Agreement. We make no claim of certification or official approval. The privacy notice is on the KVKK page.
What can my team see?
Team members handle setup and management within their role permissions; they can reveal hosting passwords, and every reveal is written to the audit log. They cannot see WHM, Cloudflare or domain provider keys, settings or reseller management.
Can my client data mix with other resellers' data?
No. Each reseller's clients, services and records are kept separately; a reseller sees only their own clients.
How are passwords stored?
Panel user passwords are hashed with argon2id. Hosting passwords and provider credentials are stored encrypted with AES-256-GCM.
How do I log in to my client's cPanel?
With one click from the hosting list. The panel opens a single-use session each time; no password needs to be shared.
Let us answer your technical team's questions in a call.
Send us your application, and we'll open your panel together in an intro call.