Skip to content

Security and privacy

  • External content is blocked until you allow it; trusted senders are remembered.
  • HTML is sanitized through DOMPurify; CSP is enforced with a per-request nonce, plus SSRF redirect validation, a sandboxed PDF iframe and IP-spoofing prevention.
  • SPF / DKIM / DMARC indicators surface the most severe SPF result and drop the “via” badge on spoofed mail.
  • Newsletter unsubscribe (RFC 2369) is offered on bulk mail.

Manage certificates, then sign, encrypt, decrypt and verify. Legacy 3DES / PBE is supported, and keys stay isolated per account.

  • OAuth2 / OIDC with PKCE against Keycloak, Authentik or the built-in provider, plus OAuth-only mode, OAuth app passwords and non-interactive SSO for embedded deployments.
  • TOTP two-factor authentication, and password / 2FA management through the admin API.
  • Remember me is optional and rides an AES-256-GCM encrypted httpOnly cookie. User authentication endpoints are rate-limited (10 attempts per IP+username per 15 minutes); admin sessions support token revocation (JTI blacklist) on logout.

Plugins are scanned for dangerous patterns and need admin approval before they run.

Applies to VNClagoon+ 2026.09 and later.

© 2026 VNC - Virtual Network Consult AG. All rights reserved.