Docs / Security & privacy

Security & privacy

The basic principle is simple: Saka only manages. Your data stays on your server.

Saka does not store your data

Saka Panel does not store or relay user data. Website files, database contents, replication streams, backups, AI keys, and the assistant's chat history and memory all live on your server. Load balancer traffic does not pass through Saka either.

What Saka stores (metadata)

Stored by Saka PanelNot stored by Saka Panel
Account (email, password hash)Database passwords
Server list, IP, OS, latest statusAI API keys, Telegram bot tokens, OpenClaw gateway tokens
Names and members of database clusters and load balancersApp log contents
Task history (command, a summary of inputs without secrets, result)Database contents, files, backups
Alert history, Telegram notification connectionMetrics history (kept for 30 days on your server)
API tokens (stored encrypted, only the last 4 characters are shown)WireGuard private keys

Secret inputs used when installing an app only pass through to the agent. The history only records a summary, with secret values masked (•••).

Passwords are read from the server

TLS & networking

Firewall

The firewall is turned on only when you ask, after Saka shows you the ports currently in use. SSH is always left open. Afterwards, the agent makes sure apps can still reach the internet; if they cannot, the firewall is turned off again. On load balancer target servers, the app port is opened only for the balancer IPs. Details in The Readiness card.

Database fencing

A database node that is not fit to accept writes closes its own database port to outside traffic (TCP RST), checked every 2 seconds. This stops apps from writing to the wrong node and makes clients move to a healthy node. Details in Databases: Fencing.

A limited agent

Stopping using Saka

Saka never stops your apps because a server is disconnected or the agent is removed. To leave cleanly (removing everything Saka installed), use Lepas server (Release server). Details in Release a server.

If Saka Panel goes down

While Saka Panel cannot be reached
Websites, apps, OpenClawKeep running on your server.
DatabasesKeep running, and still fail over automatically if one server goes down (the primary is elected among your own servers).
Load balancersKeep running. Saka is not in the traffic path or the DNS path.
OpenClaw automatic updatesKeep running, handled by the agent itself.
Panel, API, MCPTemporarily unavailable.
Telegram notificationsTemporarily not sent.
If it stays disconnected for a long time, or the agent is removedApps and databases keep running; Saka never stops them.