Two-factor authentication
TOTP with any authenticator app and eight single-use recovery codes. A policy can make it mandatory for admins, accounts or both.
Two-factor authenticationSigned releases · isolated accounts
Every Vanta Panel release is signed with an Ed25519 key, and both the installer and the auto-updater verify that signature and the package’s SHA-256 before installing anything. On the server, each hosting account is its own Linux user, and on a fresh install every new account runs PHP in its own PHP‑FPM pool.
Signed releases
Before it installs anything, the installer checks that the package matches the SHA-256 in the release manifest and that a detached Ed25519 signature over the version, URL and hash verifies against the Vanta Panel key pinned inside the installer. If either check fails it stops, and nothing is installed. The panel’s updater makes the same checks and never downgrades.
root@vps:~# curl -fsSL https://get.vantapanel.com | sudo bash ==> Fetching release manifest… ==> Downloading Vanta Panel v5.41… ==> Verifying release signature… ==> Signature OK — authentic Vanta Panel release. ==> Handing over to the Vanta Panel installer… ==> Installing packages
The installer downloads the release manifest: the version, the package URL, its SHA-256 and a detached signature.
The downloaded package must match the hash in the manifest, or the install stops.
A hash only proves the download matches what the server said. The signature over version|url|sha256 proves Vanta Panel published it, because only the release key can make it.
A release that fails prints RELEASE SIGNATURE IS INVALID and exits; nothing from the release is installed. Installation guide
Ed25519, base64, exactly as it is pinned near the top of the installer. Read the install script
jregvMSJcKrLBL0IAx4gnrq3kFmdyIpR8JjhAi6dnJg=This downloads the current release, checks its hash and signature, and stops before the installer runs, with “Bootstrap OK … stopping before install as requested”. Nothing from the release is installed; if curl, unzip or openssl is missing, the bootstrap installs it first.
curl -fsSL https://get.vantapanel.com | sudo VP_BOOTSTRAP_ONLY=1 bashPut VP_BOOTSTRAP_ONLY=1 after sudo, as above. Placed before curl, it never reaches the installer.
The current release, from update.json, the manifest every panel checks for updates
40e9f24cbd22aa1dd17a23c3156856659135b993970a3b9c6fad62b2703dc72cIf the installer ever prints RELEASE SIGNATURE IS INVALID, stop.
Do not install that release by any other route. Report it to security@vantapanel.com straight away.
Isolation
Each hosting account is its own Linux user with its own home directory, and on a fresh install every new account runs PHP in its own PHP‑FPM pool as that user. Apps run as systemd services under the same user, and the shared Kafka broker gives each account its own login and topic prefix.
Creating an account makes a Linux user, a home directory under /home and an Apache virtual host; a create that fails part-way is rolled back. Creating an account
Isolated PHP runs as the account’s user, with open_basedir set to its home and /tmp, shell functions such as exec, system and proc_open disabled, and private session and upload directories. Existing accounts move over with Isolate all. PHP versions and isolation
Node.js, Python and Java apps run as systemd services under the account’s user, not the web server’s; Java units also set NoNewPrivileges, PrivateTmp and ProtectSystem. Java apps
Each enabled account gets its own SCRAM login, ACLs on its own topic and consumer-group prefix, and 1 MB/s quotas. The broker listens on 127.0.0.1 only. Apache Kafka
IP Blocker, Directory Privacy with bcrypt-hashed passwords, and Hotlink and Leech Protection, applied through the account’s own .htaccess. Security tools
One Redis instance on 127.0.0.1:6379 with no password: nothing outside the server can reach it, but every account on the server can. Enabling it per account only shows the connection details in vPanel, so use a key prefix per site and store cache and sessions only, never secrets. Redis
The panels
Two-factor sign-in, per-address brute-force throttling and idle timeouts on both vWHM and vPanel, an optional IP allow-list in front of vWHM, and a server firewall with fail2ban that the installer switches on. Privileged changes made in vWHM or through the API are written to an audit log.
TOTP with any authenticator app and eight single-use recovery codes. A policy can make it mandatory for admins, accounts or both.
Two-factor authenticationAfter 8 failed sign-ins in 15 minutes from one address, that address is refused until the window clears. vWHM and vPanel are counted separately.
Brute-force throttlingA vWHM session ends after 1 hour idle and a vPanel session after 3 hours. Changing a password signs out every other session.
Sessionsufw denies incoming traffic by default and opens only the ports the panel serves; fail2ban bans SSH and FTP brute force. The panel will not let you deny SSH, HTTP or HTTPS to everyone.
Limit /vwhm to your own addresses. The check runs before the sign-in form is shown, and a list that would shut out your current address is refused.
Privileged changes made in vWHM or through the REST API, each with when, who, what, the target and the source IP. Reads and page views are not logged.
The audit logUpdates
The installer turns on automatic security updates for the operating system. Vanta Panel’s own updater, when automatic updates are on (the default), installs a newer release once a day, but only one that passes the same signature and checksum checks; it backs up the current install first and emails you the result. Running the install command again also upgrades in place.
At most once every 24 hours, only to a strictly newer version, and only if the Ed25519 signature and the SHA-256 both verify; otherwise the update is refused and the running version stays. You can switch to review-then-install. Updating Vanta Panel
The current install is copied to /opt/vantapanel.bak.<timestamp> first, a failed update is restored automatically, and your websites are not restarted. How updates are applied
The installer enables unattended-upgrades for security updates only, applied daily, and never reboots the server on its own; reboots stay on your schedule. Read the installer’s settings
Running the install command again upgrades in place and keeps your data, your admin account and your database password. Upgrading
Privacy
Three reports: one install report when the installer finishes, a daily check-in with the version, plan, account count, a machine fingerprint and each account’s username and domains, and, for paid licences only, a licence check at most every 12 hours. The panel also contacts get.vantapanel.com to check for updates and, on free installs, to fetch its sponsored-banner settings. None of these includes email, passwords, mailbox contents or site files; the first two reports can be switched off.
VP_NO_INSTALL_PING=1 after sudo:curl -fsSL https://get.vantapanel.com | sudo VP_NO_INSTALL_PING=1 bash/etc/machine-id); paid installs add the licence key.sudo touch /etc/vantapanel/no-telemetryupdate.json from get.vantapanel.com at most every 30 minutes in the background, and again when the vWHM dashboard loads. The request carries the panel version in its User-Agent and, like any request, the server’s IP address. Where updates come fromads.json from get.vantapanel.com at most about once an hour and show sponsored banners whose images load from the advertiser’s servers. The default page placed on a new site fetches the same file from the visitor’s browser until the site’s own index file replaces it. A paid licence removes the banners from the panels. Open ads.jsonNever sent: email, passwords, mailbox contents or site files. Privacy Policy
Disclosure
Email security@vantapanel.com privately, and please do not open a public GitHub issue. Include the affected version, what you found, the steps to reproduce it and any proof of concept. We acknowledge every report, keep you informed and credit you once a fix is released, if you would like.
Want to encrypt your report?
Say so in a first email, without the details, and we will coordinate a way to send them.
Give us a reasonable time to investigate and ship a fix before anything is made public.
Do not access, modify or destroy data that belongs to other people while you test.
At a glance
The key facts in one place: what Vanta Panel is, how it installs, what it costs, how releases are signed and whom to contact.
curl -fsSL https://get.vantapanel.com | sudo bashThe install command fetches one readable shell script, and the free tier is the same signed build as every other.
curl -fsSL https://get.vantapanel.com | sudo bash