How we protect your account and your data
How we protect your account and your data: sign-in security, staff access, snapshots and backups, protection from attacks, and how to report a security problem.
What keeps your account safe, who at Coritan can reach it, how you keep copies of your servers and how to tell us about a security problem.
Keep your account yours
A second step at sign-in, sessions you can see and end, and keys that do only what you allow.
- Two-factor authentication. With it on, signing in takes your password and a six-digit code from an authenticator app on your phone. Someone who learns your password still cannot sign in. We send no codes by text message or email. Ten recovery codes let you in if you lose the phone. Turn on two-factor authentication
- Sessions you can end. The Security tab of Settings lists every browser and script signed in to your account, with its address and when it was last active. Sign out one of them, or every device but the one you are using, and within 10 seconds it can no longer reach your account. Changing your password does the same. Sign out and end sessions
- Passwords and connections. We store a one-way hash of your password (bcrypt), so nobody at Coritan can read it. coritan.com tells browsers to reach it over HTTPS only, so what you send us is encrypted on the way. Change your password
- API keys. Create a key for each script, with only the permissions it needs and the addresses it may be used from. We email you when a key is created, and you can revoke a key at any time. The Coritan API does not accept these keys yet. Until it does, a script signs in with a session of its own, which the Sessions card lists. Manage API keys
Who at Coritan can reach your account
Our staff work in an admin console of their own, with separate accounts and safeguards of its own.
- The admin console answers only at its own address, admin.coritan.com. Staff sign in there with staff accounts, which are separate from customer accounts.
- Its sign-in checks that a person is signing in, with Cloudflare Turnstile, and stops an address that keeps getting the password wrong.
- Each member of staff has a role, and the role decides what they can see and change.
- The console records the changes staff make in an audit log.
Keep copies of your servers
Snapshots and backups hold a copy of a server’s files, and you decide when to take one and when to restore it.
- Snapshots. Take a snapshot of a server whenever you like, or on a schedule. It belongs to your account, so it stays after you delete the server, and you can restore it onto that server or another of yours. Lock a snapshot so that nobody deletes it by mistake. Snapshots and backups compared
- Automatic backups. A Container Apps server can have a backup taken each day, with the last 7 kept. They come with the Pro plan and up. On the Free plan, you can add them to a paid server. Take a server snapshot
- A snapshot before we remove a server. When we remove a server because it was cancelled or not paid for, we take a snapshot of it first, so you can get the server back. When you cancel a server, you can choose not to keep one.
Snapshots and backups do not hold a server’s databases. Back up a database
Protection from attacks
DDoS Shield filters attack traffic where it enters our network, before it reaches your server.
DDoS Shield checks the traffic sent to your floating IPs at the points where it enters our network, so it drops an attack before the attack reaches your server. It covers every floating IP from the moment we assign it, and nothing needs switching on when an attack starts.
A Container Apps server without a floating IP is reached on the shared address of its machine, which DDoS Shield does not filter. Attach a floating IP to put the server behind it.
DDoS Shield · Get help with an attack now
Report a security problem
Tell us about a weakness you found in Coritan, or about abuse that comes from our network.
- For a security problem in Coritan itself, start a conversation on the Support page of the dashboard. If you cannot sign in, email support@coritan.com. Say what you found and the steps that show it.
- For spam, an attack or other abuse from an address or a service on Coritan, email abuse@coritan.com.
- For a question about your personal data, email privacy@coritan.com.
Leave passwords, recovery codes and card numbers out of every message.
Frequently asked questions
What if I lose the phone with my authenticator app?
Sign in with one of the ten recovery codes you saved when you turned on two-factor authentication. Each code works once. Without the phone and without a code, only Coritan support can let you back in.
How do I sign out a device I no longer have?
Open the Security tab of Settings, find the device on the Sessions card and sign it out. Within 10 seconds, it can no longer reach your account.
Does Coritan back up my servers?
On the Pro plan and up, Container Apps servers get an automatic backup each day. On the Free plan, you can add them to a paid server. You can also take a snapshot whenever you like, and we take one before we remove a server. Neither holds a server’s databases.
Where do I report spam or an attack coming from Coritan?
Email abuse@coritan.com with the address or the service it comes from.