Platform
One control plane, eight workspaces.
QuroPanel keeps root operations, reseller management, customer hosting, billing, deployment, security and support in separate workspaces that share one identity, one permission engine, one audit trail and one resource registry.
The workspaces
QuroAdmin
Server and fleet administration
Manage servers, services, accounts and clusters without mixing root tools into the customer panel.
QuroReseller
Reseller and master reseller management
Give resellers control over customers, packages and branding while keeping provider limits intact.
QuroControl
Customer hosting control panel
A familiar hosting workspace for websites, domains, files, mail, databases, backups and security.
QuroCommerce
Billing, orders, domains and provisioning
Handle products, orders, recurring billing, domains, provisioning and customer accounts in the same resource model.
QuroDeploy
Git deployment, applications and WordPress
Build and deploy Laravel, PHP, Node.js, Python, Vue, Nuxt, React and static applications.
QuroShield
Security, monitoring and incident response
Bring firewall events, malware findings, vulnerabilities, Cloudflare and incident actions into one security view.
QuroSupport
Tickets, knowledgebase and operations
Keep tickets connected to the customer, service, invoice, server and incident that caused the conversation.
Architecture
Why the boundaries matter
A hosting panel that is compromised can take the whole server with it. Privilege separation is the feature, not the interface.
Public web interface
↓
Unprivileged API
↓
Authorisation and policy engine
↓
Typed job
↓
QuroAgent (signed, over mTLS)
↓
Allowlisted system operation
There is no endpoint that accepts an arbitrary command. Every privileged operation is a named job with typed parameters, a fixed executable path, a timeout, an audit event and an idempotency key.
Follow the build
The roadmap shows what is specified, what is being built and what is still only planned.
View the roadmapContribute
Drivers, integrations, translations and documentation are all places to start.
How to contributeReport a security issue
Responsible disclosure, with a stated response commitment.
Disclosure policy