Security & System Architecture
Your server. Protected by default. Designed to give you complete data sovereignty and operational peace of mind without buzzwords.
Architectural Safeguards
How Overmanager protects your agents, automation pipelines, and API credentials.
Control Plane vs. Data Plane
Overmanager isolates management logic (Serverpod 4 + PostgreSQL) entirely from user workloads. Your private VPS is a standalone instance provisioned on Contabo (European data centers) running Ubuntu 24.04 with independent kernel memory.
Strict Docker Containerization
Each workload (OpenClaw, Hermes, and n8n) executes in separate containers with isolated namespaces, restricted cgroups, and dedicated local volumes. One agent cannot interfere with or inspect another container's runtime memory.
Perimeter Firewall & Least Privilege
Default installations close all unnecessary ports via UFW. Internal databases and webhook listeners run on local loopback or behind reverse proxies with automated Let's Encrypt TLS certificates.
Zero Third-Party Telemetry
Your API keys for OpenAI, Anthropic, or Google are stored strictly on your dedicated server environment variables. Overmanager never routes your prompts or outputs through intermediary analytics proxies.
Best Practices for AI Agent Security
While Overmanager hardens the underlying virtual server and operating system, following these operational hygiene rules maximizes protection:
- Use unique, restricted-scope API keys for experimental agent autonomous workflows.
- Enable the optional Auto Backup add-on before testing experimental third-party agent scripts.
- Do not expose database ports or internal services directly to 0.0.0.0 without authentication.
- Rotate administrative passwords and SSH keys regularly via the web terminal.