How FeatherPanel
handles security.
FeatherPanel holds credentials, server access, and infrastructure commands. Encryption choices in MythicalCore and permissions on API routes are part of that job.
Found a vulnerability?
Please disclose responsibly. Do not post publicly. Email security@featherpanel.comwith a detailed description. We aim to acknowledge within 24 hours.
Built-In Security
Protections built
into MythicalCore.
These controls ship with FeatherPanel. They are not a paid add-on.
XChaCha20 Encryption
All sensitive data at rest is encrypted using XChaCha20-Poly1305 via MythicalCore. This is the same cipher family used by modern VPN protocols and NaCl-based cryptographic systems.
TLS 1.3 in Transit
All communication between the panel, daemon, and clients is enforced over TLS 1.3. Legacy protocol versions are rejected. HSTS is applied on all official cloud deployments.
CSRF Protection
Every state-mutating request in FeatherPanel is protected by cryptographically signed CSRF tokens. Cross-origin requests cannot modify panel state.
CloudFlare Turnstile
Login and sensitive forms are protected by CloudFlare Turnstile, a privacy-respecting bot challenge that avoids classic CAPTCHA puzzles.
Two-Factor Authentication
TOTP-based 2FA is available for all panel accounts. Administrators can enforce 2FA across their entire user base via panel settings.
Full Audit Logging
Every administrative action (server creation, config change, user modification, API call) is recorded in an audit log with timestamp and actor.
Hardening Details
Controls at more
than the network edge.
Network, app, and daemon each apply their own checks. A network breach does not automatically grant app access, and the reverse is also true.
- Secrets stored separately from panel configuration, never in version control
- Daemon communication authenticated with signed tokens, not shared passwords
- Role-based access control scopes all user permissions at the database level
- SQL injection protection via parameterized queries throughout MythicalCore
- File manager sandboxed to server directory; no arbitrary filesystem traversal
- Outbound webhook payloads signed with HMAC-SHA256 for recipient verification
Security Log
Recent security
work we published.
We document security improvements publicly: what changed and why.
v1.0 Security Audit
Internal security review conducted prior to public release. Critical paths reviewed for injection, auth bypass, and privilege escalation.
CSRF Hardening Pass
Additional CSRF token scope narrowing applied to all API routes following community security review.
TLS Policy Enforcement
TLS 1.0/1.1 sunset enforced across all official cloud deployments. Self-hosted docs updated with hardening guide.
Short-lived daemon tokens
Daemon authentication moved to short-lived signed tokens so panel and node no longer share long-lived secrets.
Responsible Disclosure
Report vulnerabilities
privately first.
If you find a security issue in FeatherPanel, MythicalCore, or related MythicalSystems infrastructure, email us before posting publicly.
Email security@featherpanel.com with a clear description of the issue, how to reproduce it, and any supporting material. We will acknowledge your report within 24 hours and provide a resolution timeline within 72 hours.
We do not pursue legal action against researchers who disclose responsibly and in good faith.
