Signed releases · isolated accounts

Security you can check, not take on trust.

Every Vanta Panel release is signed with an Ed25519 key, and both the installer and the auto-updater verify that signature and the package’s SHA-256 before installing anything. On the server, each hosting account is its own Linux user, and on a fresh install every new account runs PHP in its own PHP‑FPM pool.

Signed releases

How are Vanta Panel releases verified?

Before it installs anything, the installer checks that the package matches the SHA-256 in the release manifest and that a detached Ed25519 signature over the version, URL and hash verifies against the Vanta Panel key pinned inside the installer. If either check fails it stops, and nothing is installed. The panel’s updater makes the same checks and never downgrades.

root@vps: ~ — installer output, abridged
root@vps:~# curl -fsSL https://get.vantapanel.com | sudo bash
==> Fetching release manifest…
==> Downloading Vanta Panel v5.41…
==> Verifying release signature…
==> Signature OK — authentic Vanta Panel release.
==> Handing over to the Vanta Panel installer…
==> Installing packages
Abridged installer output: the signature is verified before the package is unpacked.
  1. 1. Fetch the manifest

    The installer downloads the release manifest: the version, the package URL, its SHA-256 and a detached signature.

  2. 2. Check the SHA-256

    The downloaded package must match the hash in the manifest, or the install stops.

  3. 3. Verify the Ed25519 signature

    A hash only proves the download matches what the server said. The signature over version|url|sha256 proves Vanta Panel published it, because only the release key can make it.

  4. 4. Only then install

    A release that fails prints RELEASE SIGNATURE IS INVALID and exits; nothing from the release is installed. Installation guide

The release public key

Ed25519, base64, exactly as it is pinned near the top of the installer. Read the install script

jregvMSJcKrLBL0IAx4gnrq3kFmdyIpR8JjhAi6dnJg=

Verify a release without installing it

This downloads the current release, checks its hash and signature, and stops before the installer runs, with “Bootstrap OK … stopping before install as requested”. Nothing from the release is installed; if curl, unzip or openssl is missing, the bootstrap installs it first.

curl -fsSL https://get.vantapanel.com | sudo VP_BOOTSTRAP_ONLY=1 bash

Put VP_BOOTSTRAP_ONLY=1 after sudo, as above. Placed before curl, it never reaches the installer.

The current release, from update.json, the manifest every panel checks for updates

Version
v5.41
Released
Package SHA-256
40e9f24cbd22aa1dd17a23c3156856659135b993970a3b9c6fad62b2703dc72c

If the installer ever prints RELEASE SIGNATURE IS INVALID, stop.

Do not install that release by any other route. Report it to security@vantapanel.com straight away.

Isolation

How are hosting accounts isolated?

Each hosting account is its own Linux user with its own home directory, and on a fresh install every new account runs PHP in its own PHP‑FPM pool as that user. Apps run as systemd services under the same user, and the shared Kafka broker gives each account its own login and topic prefix.

  • A Linux user per account

    Creating an account makes a Linux user, a home directory under /home and an Apache virtual host; a create that fails part-way is rolled back. Creating an account

  • A PHP‑FPM pool per account

    Isolated PHP runs as the account’s user, with open_basedir set to its home and /tmp, shell functions such as exec, system and proc_open disabled, and private session and upload directories. Existing accounts move over with Isolate all. PHP versions and isolation

  • Apps under the account’s own user

    Node.js, Python and Java apps run as systemd services under the account’s user, not the web server’s; Java units also set NoNewPrivileges, PrivateTmp and ProtectSystem. Java apps

  • Kafka logins and ACLs per account

    Each enabled account gets its own SCRAM login, ACLs on its own topic and consumer-group prefix, and 1 MB/s quotas. The broker listens on 127.0.0.1 only. Apache Kafka

  • Controls for your customers

    IP Blocker, Directory Privacy with bcrypt-hashed passwords, and Hotlink and Leech Protection, applied through the account’s own .htaccess. Security tools

  • Redis is shared, not isolated

    One Redis instance on 127.0.0.1:6379 with no password: nothing outside the server can reach it, but every account on the server can. Enabling it per account only shows the connection details in vPanel, so use a key prefix per site and store cache and sessions only, never secrets. Redis

The panels

What protects the panels?

Two-factor sign-in, per-address brute-force throttling and idle timeouts on both vWHM and vPanel, an optional IP allow-list in front of vWHM, and a server firewall with fail2ban that the installer switches on. Privileged changes made in vWHM or through the API are written to an audit log.

  • Two-factor authentication

    TOTP with any authenticator app and eight single-use recovery codes. A policy can make it mandatory for admins, accounts or both.

    Two-factor authentication
  • Brute-force lockout

    After 8 failed sign-ins in 15 minutes from one address, that address is refused until the window clears. vWHM and vPanel are counted separately.

    Brute-force throttling
  • Sessions that expire

    A vWHM session ends after 1 hour idle and a vPanel session after 3 hours. Changing a password signs out every other session.

    Sessions
  • Firewall and fail2ban

    ufw denies incoming traffic by default and opens only the ports the panel serves; fail2ban bans SSH and FTP brute force. The panel will not let you deny SSH, HTTP or HTTPS to everyone.

    Firewall and brute-force protection
  • Admin IP allow-list

    Limit /vwhm to your own addresses. The check runs before the sign-in form is shown, and a list that would shut out your current address is refused.

    Admin access control
  • Audit log

    Privileged changes made in vWHM or through the REST API, each with when, who, what, the target and the source IP. Reads and page views are not logged.

    The audit log

Updates

How is the server kept up to date?

The installer turns on automatic security updates for the operating system. Vanta Panel’s own updater, when automatic updates are on (the default), installs a newer release once a day, but only one that passes the same signature and checksum checks; it backs up the current install first and emails you the result. Running the install command again also upgrades in place.

  • Panel updates, on by default

    At most once every 24 hours, only to a strictly newer version, and only if the Ed25519 signature and the SHA-256 both verify; otherwise the update is refused and the running version stays. You can switch to review-then-install. Updating Vanta Panel

  • A backup before every update

    The current install is copied to /opt/vantapanel.bak.<timestamp> first, a failed update is restored automatically, and your websites are not restarted. How updates are applied

  • Operating-system security patches

    The installer enables unattended-upgrades for security updates only, applied daily, and never reboots the server on its own; reboots stay on your schedule. Read the installer’s settings

  • One command to upgrade by hand

    Running the install command again upgrades in place and keeps your data, your admin account and your database password. Upgrading

Privacy

What does Vanta Panel send home?

Three reports: one install report when the installer finishes, a daily check-in with the version, plan, account count, a machine fingerprint and each account’s username and domains, and, for paid licences only, a licence check at most every 12 hours. The panel also contacts get.vantapanel.com to check for updates and, on free installs, to fetch its sponsored-banner settings. None of these includes email, passwords, mailbox contents or site files; the first two reports can be switched off.

Install report

When
Once, when the installer finishes.
What it sends
The server’s IP address, the Vanta Panel version and the operating system.
Turn it off
Install with VP_NO_INSTALL_PING=1 after sudo:
curl -fsSL https://get.vantapanel.com | sudo VP_NO_INSTALL_PING=1 bash

Daily check-in

When
Once a day.
What it sends
A random install ID, the version, plan, account count, PHP version and OS name, and each hosting account’s username and domains, used to verify paid licences and detect abuse. Every install also sends a machine fingerprint (a hash of the server’s /etc/machine-id); paid installs add the licence key.
Turn it off
Create one file on the server:
sudo touch /etc/vantapanel/no-telemetry

Licence check Paid licences

When
At most every 12 hours, while a licence key is installed.
What it sends
The key, the server’s public IP and hostname, and a machine fingerprint. The reply is Ed25519-signed and verified by the panel.
Turn it off
Remove the key to return to free-tier limits. If the licensing server cannot be reached, the last verified result keeps working for 7 days. Activating your licence

Also contacted, and not stopped by the opt-out file

Update check
The panel reads update.json from get.vantapanel.com at most every 30 minutes in the background, and again when the vWHM dashboard loads. The request carries the panel version in its User-Agent and, like any request, the server’s IP address. Where updates come from
Sponsored-banner settings Free installs
Without a paid licence, the panels fetch ads.json from get.vantapanel.com at most about once an hour and show sponsored banners whose images load from the advertiser’s servers. The default page placed on a new site fetches the same file from the visitor’s browser until the site’s own index file replaces it. A paid licence removes the banners from the panels. Open ads.json

Never sent: email, passwords, mailbox contents or site files. Privacy Policy

Disclosure

How do you report a vulnerability?

Email security@vantapanel.com privately, and please do not open a public GitHub issue. Include the affected version, what you found, the steps to reproduce it and any proof of concept. We acknowledge every report, keep you informed and credit you once a fix is released, if you would like.

Email security@vantapanel.com

Want to encrypt your report?

Say so in a first email, without the details, and we will coordinate a way to send them.

  • Private disclosure

    Give us a reasonable time to investigate and ship a fix before anything is made public.

  • Research in good faith

    Do not access, modify or destroy data that belongs to other people while you test.

At a glance

What are the key facts about Vanta Panel?

The key facts in one place: what Vanta Panel is, how it installs, what it costs, how releases are signed and whom to contact.

What it is
A self-hosted web hosting control panel (a cPanel/WHM alternative). vWHM is the admin console; vPanel is the customer panel.
Install
curl -fsSL https://get.vantapanel.com | sudo bash
Runs on
Fresh Ubuntu 22.04+ or Debian 12+; x86_64 or arm64; about 2 GB RAM and 3 GB disk; live in about three minutes.
Pricing
Per server per month, in USD: Free $0 (1 account, 1 mailbox and 1 database); Basic $5 (5 accounts, 5 mailboxes and 5 databases); Unlimited $10 (unlimited accounts, mailboxes and databases). Every feature in every tier; never per account.
WHMCS
The WHMCS module is a free download with no separate licence. It works with every tier, and the tier's account limit applies, so hosting companies run it on Unlimited.
Migration
vWHM Import from cPanel (cPanel account backups).
Releases
Ed25519-signed; the installer and the auto-updater verify the signature and the SHA-256 before installing.
Live demo
https://demo.vantapanel.com (vWHM demo/demo, vPanel acme/demo)
Current version
v5.41, released 24 Sep 2026
Contact
support@vantapanel.com; security reports to security@vantapanel.com
Not to be confused with
Vanta Panel is not related to Vanta (vanta.com, compliance software), Vantablack or Vantaa.

Check the signature. Then install.

The install command fetches one readable shell script, and the free tier is the same signed build as every other.

curl -fsSL https://get.vantapanel.com | sudo bash