Skip to content

System Audit

The System Audit page (/system-audit, admin-only) is an on-demand host security assessment – a distinct thing from the Health page’s “is everything currently running” live status, or Reports’ usage/analytics trends. System Audit answers “is the server configured safely”, producing a point-in-time snapshot (an audit run) you can compare against the previous one.

Three categories, each made up of individual pass/fail checks:

  • System configuration – OS/kernel info, a world-writable file scan of security-sensitive locations, file permissions, and timezone
  • SSH hardening – sshd_config (and drop-ins) directives, host key and authorized_keys file permissions
  • Firewall configuration – ufw/firewalld status and the OpenVPN-managed iptables unit this project’s own installer writes

Every check reports pass or fail individually with plain-language remediation guidance, and some findings offer a one-click Fix Automatically action right on the finding, gated behind the same permission as running the audit itself.

Each audit run produces a 0-100 Security Score:

  • Starts at 100
  • -25 per Critical finding
  • -10 per High finding
  • -4 per Medium finding
  • -1 per Low finding
  • Informational and Passed findings never affect the score

The score is floored at 0, and each run is compared against the previous one so you can see at a glance whether your posture is improving or regressing.

Developed by Cloudlative