In development

QuroPanel is under active development. Follow the roadmap and join the first public testing group.

QuroPanel
Follow development

Platform

One control plane, eight workspaces.

QuroPanel keeps root operations, reseller management, customer hosting, billing, deployment, security and support in separate workspaces that share one identity, one permission engine, one audit trail and one resource registry.

Architecture

Why the boundaries matter

A hosting panel that is compromised can take the whole server with it. Privilege separation is the feature, not the interface.

Public web interface
      ↓
Unprivileged API
      ↓
Authorisation and policy engine
      ↓
Typed job
      ↓
QuroAgent  (signed, over mTLS)
      ↓
Allowlisted system operation

There is no endpoint that accepts an arbitrary command. Every privileged operation is a named job with typed parameters, a fixed executable path, a timeout, an audit event and an idempotency key.

Follow the build

The roadmap shows what is specified, what is being built and what is still only planned.

View the roadmap

Contribute

Drivers, integrations, translations and documentation are all places to start.

How to contribute

Report a security issue

Responsible disclosure, with a stated response commitment.

Disclosure policy