Get a clear, plain-language picture of how secure your infrastructure is — and how InfraNest keeps your account and data safe. This article is for anyone who wants to understand or improve their security posture, no technical background required.
Overview
- InfraNest continuously checks that your infrastructure is set up securely, and the platform itself is built with strong security practices.
- Findings are explained in plain language, ranked by severity, and come with one-click fixes wherever possible.
- Security checks are spread across five areas: certificates, DNS and email, domains, servers, and firewalls.
- Beyond auditing your setup, InfraNest also protects your account with sign-in security, encryption, and strict data isolation.
Review your security advisors
InfraNest audits your security in five places. Each one only shows checks it can actually action, explains why a finding matters, and offers a fix along with a rolled-up score.
- Go to Certificate health to review weak keys, old signatures, mismatches and chain problems on your certificates.
- Go to Check DNS and email security to review SPF, DMARC, DKIM, MX, DNSSEC and CAA settings for each DNS zone.
- Go to Keep a domain secure to review transfer lock, WHOIS privacy, DNSSEC, auto-renew and nameserver settings.
- Go to Keep a server secure to review firewalls, exposed ports, backups and other server-level settings.
- Go to Manage firewalls to review the Firewall advisor's findings on risky inbound rules.
Each advisor lists its findings ranked by severity, with a short note on why it matters and, where possible, a fix you can apply in one click.
Understand how InfraNest keeps your account safe
- Sign in using either email/password or SSO, and turn on two-factor authentication along with email verification for extra protection.
- Expect to confirm your identity again for sensitive actions — this re-authentication step helps prevent unauthorised changes even if your session is compromised.
- Set up roles and permissions under Team so each person only has access to what they need.
- Store provider credentials, webhook secrets and tokens knowing they're encrypted and never shown again once saved.
- Rely on your organisation's own encryption key to protect your secrets — no other customer's key can read them, and deleting your organisation for good destroys that key, making all stored secrets permanently unreadable, including in any backup.
- Check the Audit Log any time to see a record of every action taken in your account.
NoteYour organisation's data is strictly isolated from other organisations — it's never mixed or shared.
WarningDeleting your organisation destroys your unique encryption key permanently. This makes all stored secrets unreadable forever, including in backups — there's no way to undo this.
Tips
- Check your security advisors regularly, not just once — new findings can appear as your infrastructure changes.
- Turn on two-factor authentication as soon as possible; it's one of the simplest ways to protect your account.
- Use roles and permissions to limit access rather than giving everyone full control.
Was this article helpful?