Security & privacy
The basic principle is simple: Saka only manages. Your data stays on your server.
Saka does not store your data
Saka Panel does not store or relay user data. Website files, database contents, replication streams, backups, AI keys, and the assistant's chat history and memory all live on your server. Load balancer traffic does not pass through Saka either.
What Saka stores (metadata)
| Stored by Saka Panel | Not stored by Saka Panel |
|---|---|
| Account (email, password hash) | Database passwords |
| Server list, IP, OS, latest status | AI API keys, Telegram bot tokens, OpenClaw gateway tokens |
| Names and members of database clusters and load balancers | App log contents |
| Task history (command, a summary of inputs without secrets, result) | Database contents, files, backups |
| Alert history, Telegram notification connection | Metrics history (kept for 30 days on your server) |
| API tokens (stored encrypted, only the last 4 characters are shown) | WireGuard private keys |
Secret inputs used when installing an app only pass through to the agent. The history only records a summary, with secret values masked (•••).
Passwords are read from the server
- Databases: the password is generated when the cluster is created, passed once to the data servers, and then not stored. The Tampilkan sandi (Show password) button reads it directly from a data server at that moment. MCP never hands out passwords.
- AI keys: stored only on your server, in a file readable only by root. The model list is requested from the AI provider by the server, so the key never leaves it.
- Logs: read directly from the server on request, not recorded by Saka.
TLS & networking
- The agent connects outbound to Saka Panel over a secure WebSocket. No control or panel port is opened on the server.
- The agent is downloaded with a SHA-256 checksum check. When it updates itself, it only accepts releases signed with an Ed25519 key that is not stored on Saka's servers (the public key is built into the agent). Updates without a valid signature are rejected, so even a compromised Saka Panel cannot push a fake agent.
- Databases: TLS is required (PostgreSQL
hostsslwith SCRAM, MariaDBrequire_secure_transport). Traffic between locations goes over encrypted WireGuard. - Ready-to-install apps: ports only on
127.0.0.1. Dashboards open through an outbound tunnel with a one-time ticket, on a subdomain separate from the panel. - New ports are opened only when you create a database cluster (database ports and the private network between locations) or a load balancer (80/443 on the balancers, 53 for LB DNS), and only when the Saka firewall is on.
Firewall
The firewall is turned on only when you ask, after Saka shows you the ports currently in use. SSH is always left open. Afterwards, the agent makes sure apps can still reach the internet; if they cannot, the firewall is turned off again. On load balancer target servers, the app port is opened only for the balancer IPs. Details in The Readiness card.
Database fencing
A database node that is not fit to accept writes closes its own database port to outside traffic (TCP RST), checked every 2 seconds. This stops apps from writing to the wrong node and makes clients move to a healthy node. Details in Databases: Fencing.
A limited agent
- The agent only runs a fixed set of commands (install apps, create swap, firewall, databases, load balancers, and so on). It does not run arbitrary shell commands from Saka Panel.
- MCP and the API use tokens that can be revoked at any time. Delete actions need confirmation, and through MCP they always take two steps. See MCP security principles.
- OpenClaw is installed with command approval on and ClawHub off.
- Sign-up and sign-in are rate-limited per IP to slow down password guessing.
Stopping using Saka
Saka never stops your apps because a server is disconnected or the agent is removed. To leave cleanly (removing everything Saka installed), use Lepas server (Release server). Details in Release a server.
If Saka Panel goes down
| While Saka Panel cannot be reached | |
|---|---|
| Websites, apps, OpenClaw | Keep running on your server. |
| Databases | Keep running, and still fail over automatically if one server goes down (the primary is elected among your own servers). |
| Load balancers | Keep running. Saka is not in the traffic path or the DNS path. |
| OpenClaw automatic updates | Keep running, handled by the agent itself. |
| Panel, API, MCP | Temporarily unavailable. |
| Telegram notifications | Temporarily not sent. |
| If it stays disconnected for a long time, or the agent is removed | Apps and databases keep running; Saka never stops them. |