Open Security OPEN SECURITY ← Back to Home

Security Audit

How I protect my infrastructure — and yours

Overview

If I'm going to ask clients to trust me with their security, I should be transparent about how I secure my own infrastructure. This page outlines the security measures in place across the Open Security platform. I practice what I preach.

The 6-Layer Security Model

Every request to the Open Security platform passes through six layers of security before it reaches any application:

01

Cloudflare WAF & DDoS Protection

All traffic is proxied through Cloudflare. Web Application Firewall rules filter malicious requests. DDoS mitigation happens at the edge before traffic ever reaches the server.

02

Cloudflare Zero Trust (OTP)

Admin panels and management interfaces are behind Cloudflare Access with one-time password authentication. No VPN needed — identity verified at the edge.

03

Apache IP Restriction

The web server only accepts connections from Cloudflare's IP ranges. Direct access to the server IP is blocked — you can't bypass Cloudflare.

04

Docker Localhost Binding

All Docker containers bind to localhost only. Services are never exposed directly to the internet — they're only accessible through the reverse proxy chain.

05

UFW Firewall

Host-level firewall with a default-deny policy. Only ports 80, 443, and SSH are open. Everything else is dropped.

06

Application Authentication

Each application (Grafana, Wazuh, n8n) has its own authentication layer with strong passwords and role-based access control.

Client Isolation

Multi-tenant security is critical. Each client's data is isolated through multiple mechanisms:

  • Separate Grafana organizations per client — you only see your own dashboards
  • Separate Wazuh agent groups — your security data stays in your group
  • Hardcoded dashboard queries — even if you tried, you can't query another client's data
  • Viewer-only roles — clients can see their dashboards but can't modify anything

Open-Source Tools

I exclusively use open-source security tools. This means the code is publicly auditable, there are no hidden backdoors, and I'm not dependent on a single vendor:

  • Wazuh — SIEM, intrusion detection, file integrity monitoring, vulnerability detection
  • Grafana — Security dashboards and visualization
  • Tactical RMM — Remote monitoring and management of endpoints
  • n8n — Workflow automation for alerts and integrations

Encryption

  • In transit — TLS everywhere. All connections between clients, Cloudflare, and the server are encrypted. Internal service communication uses encrypted channels.
  • At rest — Server storage is encrypted. Database contents and log data are protected on disk.

Website Privacy

This website does not use any third-party analytics, tracking pixels, or marketing scripts. No Google Analytics, no Facebook pixel, no hotjar. The only third-party service involved in serving this site is Cloudflare for CDN and security. I respect your privacy even before you're a client.

Infrastructure

  • Hosted on Hetzner dedicated servers in EU data centers
  • All services run in Docker containers for isolation and reproducibility
  • Regular automated backups
  • OS and container images kept up to date with security patches

Responsible Disclosure

Found a vulnerability? I appreciate responsible disclosure. Please report any security issues to [email protected]. I'll acknowledge receipt within 24 hours and work with you to understand and resolve the issue. I won't take legal action against good-faith security researchers.