InfraNestInfraNest

Security

Security overview

InfraNest doesn't just manage your infrastructure — it continuously checks that it's set up securely, and the platform itself is built securely.

Get a clear, plain-language picture of how secure your infrastructure is — and how InfraNest keeps your account and data safe. This article is for anyone who wants to understand or improve their security posture, no technical background required.

Overview

  • InfraNest continuously checks that your infrastructure is set up securely, and the platform itself is built with strong security practices.
  • Findings are explained in plain language, ranked by severity, and come with one-click fixes wherever possible.
  • Security checks are spread across five areas: certificates, DNS and email, domains, servers, and firewalls.
  • Beyond auditing your setup, InfraNest also protects your account with sign-in security, encryption, and strict data isolation.

Review your security advisors

InfraNest audits your security in five places. Each one only shows checks it can actually action, explains why a finding matters, and offers a fix along with a rolled-up score.

  1. Go to Certificate health to review weak keys, old signatures, mismatches and chain problems on your certificates.
  2. Go to Check DNS and email security to review SPF, DMARC, DKIM, MX, DNSSEC and CAA settings for each DNS zone.
  3. Go to Keep a domain secure to review transfer lock, WHOIS privacy, DNSSEC, auto-renew and nameserver settings.
  4. Go to Keep a server secure to review firewalls, exposed ports, backups and other server-level settings.
  5. Go to Manage firewalls to review the Firewall advisor's findings on risky inbound rules.

Each advisor lists its findings ranked by severity, with a short note on why it matters and, where possible, a fix you can apply in one click.

Understand how InfraNest keeps your account safe

  1. Sign in using either email/password or SSO, and turn on two-factor authentication along with email verification for extra protection.
  2. Expect to confirm your identity again for sensitive actions — this re-authentication step helps prevent unauthorised changes even if your session is compromised.
  3. Set up roles and permissions under Team so each person only has access to what they need.
  4. Store provider credentials, webhook secrets and tokens knowing they're encrypted and never shown again once saved.
  5. Rely on your organisation's own encryption key to protect your secrets — no other customer's key can read them, and deleting your organisation for good destroys that key, making all stored secrets permanently unreadable, including in any backup.
  6. Check the Audit Log any time to see a record of every action taken in your account.

NoteYour organisation's data is strictly isolated from other organisations — it's never mixed or shared.

WarningDeleting your organisation destroys your unique encryption key permanently. This makes all stored secrets unreadable forever, including in backups — there's no way to undo this.

Tips

  • Check your security advisors regularly, not just once — new findings can appear as your infrastructure changes.
  • Turn on two-factor authentication as soon as possible; it's one of the simplest ways to protect your account.
  • Use roles and permissions to limit access rather than giving everyone full control.

Start in seconds

Bring your whole infrastructure into one modern dashboard.

Free plan · No credit card required · Set up in minutes