Security policy

How to report a vulnerability in ZoPanel, what is in scope, how quickly we respond, and our safe-harbor commitment to good-faith researchers.

Draft — to be reviewed by legal counsel before publication.

ZoPanel manages servers that host other people's websites and e-mail, so we treat security reports as our highest priority. If you believe you have found a vulnerability, we want to hear from you, and we will work with you to fix it.

How to report a vulnerability

Use either channel:

  • Support ticket: open a ticket on the support page with the category Technical and a subject starting with "Security:". Tickets from a signed-in account let us follow up with you directly.
  • E-mail: write to security@zopanel.net.

Please include:

  • the ZoPanel version (zopanel version or Settings → License) and operating system;
  • the component affected (for example the web panel, an API endpoint, the installer, a billing module, the website or the license server);
  • step-by-step instructions to reproduce, with the account role you used (administrator, reseller or customer);
  • what an attacker could achieve, in your assessment;
  • whether you want to be credited, and under what name.

Please do not put full exploit details in public tickets, forums, issue trackers or social media before a fix is released.

Scope

In scope

  • The zopanel program: the web panel and its API, the root agent and the boundary between them, per-account isolation (files, processes, PHP, databases, mail, Docker apps), the web terminal, file manager, backups and restores, and imports.
  • The installer and the update mechanism, including update signatures and rollback.
  • The provisioning API and the WHMCS, Blesta, HostBill and Paymenter modules.
  • License verification, where a flaw affects the security of customers' servers.
  • The zopanel.net website, customer accounts, checkout and the license server.

Examples of what we especially want to know about: a hosting customer reading or changing another customer's data; any path from a customer, reseller or API token to root or to administrator rights; a reseller exceeding their own plan through the panel; authentication or 2FA bypass; remote code execution; injection into server configuration.

Out of scope

  • Vulnerabilities in third-party software (nginx, PHP, MariaDB, Postfix and so on) that are not caused by how ZoPanel configures them. Please report those to their maintainers; tell us too if ZoPanel should ship a mitigation.
  • Findings that need root access, physical access, or an administrator account to harm only that same administrator's server.
  • Volumetric denial of service, load testing, spam, or social engineering of our staff or customers.
  • Missing security headers or best-practice suggestions without a demonstrable impact.
  • Websites and applications hosted by our customers on ZoPanel servers.

How to test

  • Test only on servers you own or are authorised to test. Install ZoPanel on your own VPS; the Free plan is enough for most research.
  • Do not access, change or delete data that is not yours. If you reach other people's data by accident, stop, do not keep it, and tell us.
  • Do not degrade our website or license server for others; automated scanning of zopanel.net must be gentle.

Our response targets

These are targets, not contractual guarantees:

Step Target
Acknowledge your report Within 1 business day
Initial assessment and severity Within 5 business days
Fix for critical issues Released as soon as possible, aiming for 7 days
Fix for high-severity issues Aiming for 30 days
Fix for medium and low issues In a scheduled release, aiming for 90 days

We keep you informed while we work on the fix, agree a disclosure date with you, and describe the fix in the changelog once released. Fixes reach servers through the signed built-in updater.

Safe harbor

If you act in good faith and follow this policy, we will:

  • consider your research authorised, and not pursue or support legal action against you for it;
  • not report you to law enforcement for activity that follows this policy;
  • work with you to understand and resolve the issue quickly;
  • credit you publicly if you wish.

Good faith means: you report the issue to us promptly, avoid privacy violations, data destruction and service disruption, do not exploit the issue beyond what is needed to demonstrate it, and give us reasonable time to fix it before disclosure. This safe harbor covers our own claims only; we cannot authorise testing of systems that belong to others. If in doubt, ask us first.

We do not currently run a paid bug bounty programme.

Security design

For how ZoPanel is built to limit the impact of a flaw — an unprivileged web panel, a root agent that accepts only a fixed list of actions and checks every parameter again, a systemd sandbox for every account and Docker apps in user namespaces — see our security features.