Safe probes
Blocking localhost, private and special IP ranges, metadata endpoints and DNS rebinding.
UPnator limits trust between services, blocks unsafe public-probe targets and requires extra confirmation for sensitive operations.
Blocking localhost, private and special IP ranges, metadata endpoints and DNS rebinding.
mTLS limits execution traffic to authenticated platform components.
TOTP, passkeys, enterprise OIDC and fresh step-up for sensitive operations.
Organization roles, scoped API keys, expirations and action history limit the impact of mistakes.
If inbound traffic is denied by default, allowlist UPnator source addresses only on the monitored port. The complete current list is maintained in the documentation.
The renderer receives a signed snapshot and serves it without access to PostgreSQL or NATS. Public communication stays separated from the control plane.
Secure owner and admin accounts first.
Grant permissions according to actual responsibility.
Open only the monitored port to all three source IPv4 addresses.
Do not consider setup complete without confirmed delivery.
Set expirations and rotate service-account keys.
Regularly review security, team and automation changes.
Describe the environment and required trust boundaries. We will respond with a concrete architecture.