NewSEO audit: compliance scores based on Google, Yandex and Bing guidelines
WebJoiner

We describe security by how the panel works, not by a feature list.

The panel was designed with KVKK-compliant data processing in mind: client data never mixes between resellers, provider keys are shown to no one, and every action is logged. Everything below is active in the panel today.

Active safeguards

In four areas, by their technical names.

Identity and sessions

  • Mandatory 2FA

    Two-factor authentication with TOTP is mandatory for admin accounts.

  • argon2id

    Panel user passwords are stored hashed with argon2id.

  • Login rate limiting

    Failed login attempts are rate-limited; repeated attempts are temporarily blocked.

  • CSRF protection

    Every request that changes data is verified with a CSRF token.

Secrets and data

  • AES-256-GCM

    Provider credentials and hosting passwords are stored encrypted; the key is not kept in the database.

  • Provider keys stay hidden

    WHM, Cloudflare and domain provider keys are used only on the server side; resellers and team members cannot see them.

  • Reseller isolation

    Every query is limited to the accessing user's scope of permissions; one reseller cannot see another reseller's records.

  • Encrypted backups

    Panel database backups are taken encrypted.

  • KVKK-compliant data processing

    Personal data is collected only to the extent needed for the service, kept separately per reseller, and access is logged.

Permissions and auditing

  • Role permissions

    Team members work within their role permissions; they cannot see settings or reseller management. They can reveal a hosting password, and every reveal is logged.

  • Append-only audit log

    Who did what, when, on which record; entries are only ever appended.

  • One-time cPanel login

    cPanel is accessed not with a stored password but with a one-time session each time.

  • Origin behind Cloudflare

    The panel's own server runs behind Cloudflare; the origin IP is not publicly exposed.

Account, payment and approval

  • Bot protection

    The login screen is protected against automated login attempts with Cloudflare Turnstile.

  • Secure card payment

    Card payments are processed through the payment institution's secure infrastructure; bank transfer (EFT) is also available.

  • e-Invoice / e-Archive

    Approved invoices are issued as official e-Invoices or e-Archive invoices through an integrated e-invoicing system; only the fields required for invoicing are collected.

  • Approved critical actions

    DNS fixes, restores from backup and draft invoices are not applied without your approval.

What don't we claim?

Trust starts with claims that can be verified.

  • We don't use unverified claims such as uptime percentages, "24/7" or a certification we don't hold.
  • We describe the logs as "append-only", not "immutable"; that is the technically accurate term.
  • This page lists only the safeguards that are active in the panel today.

Questions about security

For all questions, see the FAQ page or message us on WhatsApp.

Is my data secure?

The panel runs behind Cloudflare, and the login screen is protected against bot attacks with Cloudflare Turnstile. 2FA is mandatory for admin accounts, and the team works with role-based permissions. Provider credentials and hosting passwords are encrypted with AES-256-GCM, every action is kept in an append-only log, and each reseller's data is kept separate. Details on the security page.

How does the panel help with my KVKK obligations?

The panel was designed with KVKK-compliant data processing, taking into account the data security obligations under KVKK (Law No. 6698): personal data is collected only to the extent needed for the service, each reseller's data is kept separately, secrets are encrypted, and access is written to the audit log. You are the data controller for your clients' data; WebJoiner acts as data processor on your instructions, and this relationship is governed by the data processing annex of the Reseller Agreement. We make no claim of certification or official approval. The privacy notice is on the KVKK page.

What can my team see?

Team members handle setup and management within their role permissions; they can reveal hosting passwords, and every reveal is written to the audit log. They cannot see WHM, Cloudflare or domain provider keys, settings or reseller management.

Can my client data mix with other resellers' data?

No. Each reseller's clients, services and records are kept separately; a reseller sees only their own clients.

How are passwords stored?

Panel user passwords are hashed with argon2id. Hosting passwords and provider credentials are stored encrypted with AES-256-GCM.

How do I log in to my client's cPanel?

With one click from the hosting list. The panel opens a single-use session each time; no password needs to be shared.

Let us answer your technical team's questions in a call.

Send us your application, and we'll open your panel together in an intro call.