Security & System Architecture

Your server. Protected by default. Designed to give you complete data sovereignty and operational peace of mind without buzzwords.

Defense in Depth

Architectural Safeguards

How Overmanager protects your agents, automation pipelines, and API credentials.

Architecture Separation

Control Plane vs. Data Plane

Overmanager isolates management logic (Serverpod 4 + PostgreSQL) entirely from user workloads. Your private VPS is a standalone instance provisioned on Contabo (European data centers) running Ubuntu 24.04 with independent kernel memory.

Runtime Isolation

Strict Docker Containerization

Each workload (OpenClaw, Hermes, and n8n) executes in separate containers with isolated namespaces, restricted cgroups, and dedicated local volumes. One agent cannot interfere with or inspect another container's runtime memory.

Network Defense

Perimeter Firewall & Least Privilege

Default installations close all unnecessary ports via UFW. Internal databases and webhook listeners run on local loopback or behind reverse proxies with automated Let's Encrypt TLS certificates.

Data Sovereignty & BYOK

Zero Third-Party Telemetry

Your API keys for OpenAI, Anthropic, or Google are stored strictly on your dedicated server environment variables. Overmanager never routes your prompts or outputs through intermediary analytics proxies.

Recommended Guidelines

Best Practices for AI Agent Security

While Overmanager hardens the underlying virtual server and operating system, following these operational hygiene rules maximizes protection:

  • Use unique, restricted-scope API keys for experimental agent autonomous workflows.
  • Enable the optional Auto Backup add-on before testing experimental third-party agent scripts.
  • Do not expose database ports or internal services directly to 0.0.0.0 without authentication.
  • Rotate administrative passwords and SSH keys regularly via the web terminal.
Have specific security requirements or vulnerability disclosures? support@overmanager.com