Core Panel
Core Panel · Trust Center

Core Panel Security Policy and Vulnerability Reporting

Core Panel manages privileged server operations. Review the current product status and security boundaries before installation, and report suspected vulnerabilities privately.

Deployment status and supported use

The product security policy classifies Core Panel as pre-production software for isolated development virtual machines. No released version is currently supported for public-internet or multi-tenant production use.

Documented missing controls include tenant isolation, per-node agent mTLS enrollment, complete CPU and memory resource controls, and an independent security review. Review System Settings → Production readiness for the current installation; a TLS certificate or successful backup alone does not establish production readiness.

Documented safeguards

The product documentation describes scoped roles, TOTP multi-factor authentication, audit records, protected credential storage, and encrypted panel-wide recovery with clean restore drills. These controls reduce specific risks but do not remove the limitations above.

Keep administrator access on a trusted network and configure TLS before transmitting credentials. Apply least privilege and maintain independent recovery copies and recovery keys.

Report a suspected vulnerability

Use GitHub private vulnerability reporting for the product repository when available. Otherwise email [email protected] with the subject “Security report” to request a private reporting channel. Start with the affected version and a brief impact summary; arrange a secure transfer before sending sensitive exploit material.

Include the affected version or commit, operating system and architecture, reproduction steps using a disposable environment, expected and observed behavior, impact, and possible mitigation. Remove passwords, tokens, private keys, personal data, and customer backups.

Do not post exploitable details in public issues or test systems without ownership or explicit authorization. No response deadline, fix deadline, or reward is promised by this reporting guidance.