Security Audit
How I protect my infrastructure — and yours
Overview
If I'm going to ask clients to trust me with their security, I should be transparent about how I secure my own infrastructure. This page outlines the security measures in place across the Open Security platform. I practice what I preach.
The 6-Layer Security Model
Every request to the Open Security platform passes through six layers of security before it reaches any application:
Cloudflare WAF & DDoS Protection
All traffic is proxied through Cloudflare. Web Application Firewall rules filter malicious requests. DDoS mitigation happens at the edge before traffic ever reaches the server.
Cloudflare Zero Trust (OTP)
Admin panels and management interfaces are behind Cloudflare Access with one-time password authentication. No VPN needed — identity verified at the edge.
Apache IP Restriction
The web server only accepts connections from Cloudflare's IP ranges. Direct access to the server IP is blocked — you can't bypass Cloudflare.
Docker Localhost Binding
All Docker containers bind to localhost only. Services are never exposed directly to the internet — they're only accessible through the reverse proxy chain.
UFW Firewall
Host-level firewall with a default-deny policy. Only ports 80, 443, and SSH are open. Everything else is dropped.
Application Authentication
Each application (Grafana, Wazuh, n8n) has its own authentication layer with strong passwords and role-based access control.
Client Isolation
Multi-tenant security is critical. Each client's data is isolated through multiple mechanisms:
- Separate Grafana organizations per client — you only see your own dashboards
- Separate Wazuh agent groups — your security data stays in your group
- Hardcoded dashboard queries — even if you tried, you can't query another client's data
- Viewer-only roles — clients can see their dashboards but can't modify anything
Open-Source Tools
I exclusively use open-source security tools. This means the code is publicly auditable, there are no hidden backdoors, and I'm not dependent on a single vendor:
- Wazuh — SIEM, intrusion detection, file integrity monitoring, vulnerability detection
- Grafana — Security dashboards and visualization
- Tactical RMM — Remote monitoring and management of endpoints
- n8n — Workflow automation for alerts and integrations
Encryption
- In transit — TLS everywhere. All connections between clients, Cloudflare, and the server are encrypted. Internal service communication uses encrypted channels.
- At rest — Server storage is encrypted. Database contents and log data are protected on disk.
Website Privacy
This website does not use any third-party analytics, tracking pixels, or marketing scripts. No Google Analytics, no Facebook pixel, no hotjar. The only third-party service involved in serving this site is Cloudflare for CDN and security. I respect your privacy even before you're a client.
Infrastructure
- Hosted on Hetzner dedicated servers in EU data centers
- All services run in Docker containers for isolation and reproducibility
- Regular automated backups
- OS and container images kept up to date with security patches
Responsible Disclosure
Found a vulnerability? I appreciate responsible disclosure. Please report any security issues to [email protected]. I'll acknowledge receipt within 24 hours and work with you to understand and resolve the issue. I won't take legal action against good-faith security researchers.