01Where the data is kept

Everything the panel collects stays on your server: security events, metrics, reports and settings are kept in a MySQL database and in the data/ directory, which sits outside the web root.

We do not receive your logs, events, IP addresses or metrics. The panel lives on your server, and the data does not come to us.

The panel interface loads nothing from other servers: fonts, icons, charts and the attack map ship with it. The panel has no visit counters or analytics.

Security events are kept for 90 days and then deleted automatically.

02What the panel sends outside

Below is the full list of connections the panel itself opens. Almost all of them work only if you have set them up.

Telegram if configured you entered a bot and a chat

Notification text

Mail: your SMTP server or Resend if configured

An email with a notification or a report

Webhook: Slack or any address of yours if configured

An event in JSON

Browser push notifications via the browser’s delivery service (Google, Mozilla, Apple) if enabled on your device

Notification text encrypted for your browser. The delivery service cannot read it

Fleet summary to the client portal my.arciveo.com off by default turned on in the settings

Server name and address; OS, PHP and panel versions; security score and tool status; CPU, memory and disk load; event counts. Also successful SSH logins over the last 24 hours (user and IP), up to 15 attacker addresses and the latest critical event

Subdomain lookup via crt.sh on the SSL certificates page when the page opens at most once every 6 hours

The name of your main domain. crt.sh shows public certificate logs that anyone can already see

Certificate expiry check dashboard and SSL page

A regular TLS connection to your own domains

The license is checked on your server by its digital signature: the panel does not contact us to find out whether it is valid. The panel itself neither looks for nor downloads updates.

The protection tools update their own databases, from their own servers and on their own schedule: ClamAV signatures, Suricata and CrowdSec rules, the ipsum list of malicious addresses. These are the tools’ own connections; the panel takes no part in them. By default CrowdSec shares attack signals with its community; this is configured in CrowdSec itself.

03Access to the panel

Password login and a second factor: a hardware key or a passkey (WebAuthn: YubiKey, Touch ID, Windows Hello, passkey). WebAuthn keys work over HTTPS only.

IP restriction, if you turn it on: the panel opens only from allowed addresses, and everyone else is refused before the login page.

Password-guessing protection: after 5 wrong attempts from one address, login from it is closed for 15 minutes.

Request forgery protection: every button that changes something checks a secret token of your session. Another site cannot press it on your behalf, even while you are logged in to the panel.

04Rights on the server

The panel runs as the web server user, without root rights.

Through sudo it is allowed a short list of commands from /etc/sudoers.d/monitor. Almost all of them only read the state of the tools: UFW, fail2ban, CrowdSec, ipset, auditd, Monit, AppArmor and others. The panel can change only two things: ban and unban an address in fail2ban, and add or remove port rules in UFW, when you press the button on the module page. The list contains no shell, no arbitrary commands and no package installation.

The web server cannot write to the panel code: it can write only to the data, cache and log directories.

The panel does not run the commands from its how-to-fix hints itself: you copy them and run them in a terminal.

05If the license has expired

The server is protected by the tools themselves: fail2ban, UFW, Suricata, CrowdSec, ClamAV, AIDE. The panel shows their work and suggests what to fix. When the license expires, the detailed module pages close and the report gets shorter, while the tools keep working as before. The server is not left unprotected.

06How to report a vulnerability

If you have found a vulnerability in the panel, write to support@arciveo.com. The contact is also listed in security.txt.

Everything described here has been checked against the code of Arcivéo Security Monitor 1.0, October 2026.