Firewall, SSL, SSH keys, Fail2Ban, process isolation and security headers — configured and working right after you connect a server.
Eight security subsystems, each solving its own task
Presets for typical configurations, custom rules by port, protocol, policy and source IP. System rules are protected from accidental deletion.
Automatic issuance via Let's Encrypt, renewal tracking, alerts 14 days before expiration, and uploading your own certificates.
RSA, ED25519, ECDSA. Bound to a specific user, support for password-protected keys, split into system and user keys.
Configurable ban time, find time, max retries. IP ignore list, bantime increment. Nginx filters: HTTP auth, bot search, limit requests.
Each site runs under a separate system user with an isolated home directory. Compromising one does not affect the others.
Protect individual paths with username/password. Quick setup for staging environments or private sections.
X-Frame-Options, X-Content-Type-Options, Referrer-Policy, hiding X-Powered-By. Enabled with a single toggle.
Notifications on login from a new IP, tracking of known IPs. You always know who connects to the server.
Use ready-made presets or create custom rules: port, protocol (TCP/UDP/ALL), policy (ALLOW/DENY) and source IP. System rules are protected from deletion.
| Port | Protocol | Policy | Source | Type |
|---|---|---|---|---|
| 22 | TCP | ALLOW | Any | system |
| 80 | TCP | ALLOW | Any | system |
| 443 | TCP | ALLOW | Any | system |
| 3306 | TCP | DENY | Any | system |
| 5432 | TCP | ALLOW | 10.0.0.0/24 | custom |
| 6379 | TCP | ALLOW | 127.0.0.1 | custom |
Let's Encrypt выпускается из панели в один клик и дальше продлевается автоматически. Статусы: pending, active, expired, failed — always in view. Alert 14 days before expiration.
Support for RSA, ED25519, ECDSA. Each key is bound to a specific user. Password-protected keys for extra security.
Automatic IP blocking on password brute-force. Bantime increment for repeat offenders. Nginx filters: HTTP auth, bot search, limit requests.
Team keys are stored encrypted and rolled out to servers automatically. A new user gets the right keys immediately, and a bulk install pushes them to all servers at once.
Process isolation, security headers and Basic Auth for private sections
On a schedule, Deploykin scans dependencies for vulnerabilities and watches for unexpected file changes. If something turns up, you get an alert.
Connect a server — firewall, SSL, Fail2Ban and isolation will be configured automatically.
We use cookies and the Yandex Metrica web-analytics service (including Session Replay) to improve the site. Details are in the privacy policy.