Security & Trust

How FeatherPanel
handles security.

FeatherPanel holds credentials, server access, and infrastructure commands. Encryption choices in MythicalCore and permissions on API routes are part of that job.

Found a vulnerability?

Please disclose responsibly. Do not post publicly. Email security@featherpanel.comwith a detailed description. We aim to acknowledge within 24 hours.

Built-In Security

Protections built
into MythicalCore.

These controls ship with FeatherPanel. They are not a paid add-on.

XChaCha20 Encryption

All sensitive data at rest is encrypted using XChaCha20-Poly1305 via MythicalCore. This is the same cipher family used by modern VPN protocols and NaCl-based cryptographic systems.

TLS 1.3 in Transit

All communication between the panel, daemon, and clients is enforced over TLS 1.3. Legacy protocol versions are rejected. HSTS is applied on all official cloud deployments.

CSRF Protection

Every state-mutating request in FeatherPanel is protected by cryptographically signed CSRF tokens. Cross-origin requests cannot modify panel state.

CloudFlare Turnstile

Login and sensitive forms are protected by CloudFlare Turnstile, a privacy-respecting bot challenge that avoids classic CAPTCHA puzzles.

Two-Factor Authentication

TOTP-based 2FA is available for all panel accounts. Administrators can enforce 2FA across their entire user base via panel settings.

Full Audit Logging

Every administrative action (server creation, config change, user modification, API call) is recorded in an audit log with timestamp and actor.

Hardening Details

Controls at more
than the network edge.

Network, app, and daemon each apply their own checks. A network breach does not automatically grant app access, and the reverse is also true.

  • Secrets stored separately from panel configuration, never in version control
  • Daemon communication authenticated with signed tokens, not shared passwords
  • Role-based access control scopes all user permissions at the database level
  • SQL injection protection via parameterized queries throughout MythicalCore
  • File manager sandboxed to server directory; no arbitrary filesystem traversal
  • Outbound webhook payloads signed with HMAC-SHA256 for recipient verification

Security Log

Recent security
work we published.

We document security improvements publicly: what changed and why.

v1.0 Security Audit

Internal security review conducted prior to public release. Critical paths reviewed for injection, auth bypass, and privilege escalation.

CSRF Hardening Pass

Additional CSRF token scope narrowing applied to all API routes following community security review.

TLS Policy Enforcement

TLS 1.0/1.1 sunset enforced across all official cloud deployments. Self-hosted docs updated with hardening guide.

Short-lived daemon tokens

Daemon authentication moved to short-lived signed tokens so panel and node no longer share long-lived secrets.

Responsible Disclosure

Report vulnerabilities
privately first.

If you find a security issue in FeatherPanel, MythicalCore, or related MythicalSystems infrastructure, email us before posting publicly.

Email security@featherpanel.com with a clear description of the issue, how to reproduce it, and any supporting material. We will acknowledge your report within 24 hours and provide a resolution timeline within 72 hours.

We do not pursue legal action against researchers who disclose responsibly and in good faith.