HSVE
    ~/templates~/portal~/services~/about~/contact~/docs
    statusdiscord ↗account()open_portal()
    HSVE
    ~/templates~/portal~/services~/about~/contact~/docs
    statusdiscord ↗account()open_portal()
    HSVE Docs←
    Portal documentation
    01Getting Started02Connect a Proxmox Site03HSVE Agent04Virtual Machines & Consoles05Snapshots & Backups06Deploy Marketplace Templates07Access & Invitations08Monitoring09Security Architecture10Troubleshooting
    docs/portal/security
    09 · Security model

    Security Architecture

    Understand the outbound-only Agent model, credential boundaries and console relay design.

    Outbound-only Site connectivityCredential boundariesConsole sessionsAuthorisationCustomer-controlled infrastructure data

    Outbound-only Site connectivity

    The Site Agent initiates communication to HSVE Cloud. Normal Portal operation does not require HSVE to initiate an inbound connection to your Proxmox management interface.

    Browser ──HTTPS/WSS──> HSVE Portal / Cloud
                               ▲
                               │ outbound authenticated Agent channel
                               │
                         HSVE Agent
                               │ verified local HTTPS
                               ▼
                           Proxmox VE
    Keep TCP 8006 private

    You do not need to expose the Proxmox web/API port to the public internet for HSVE Portal.

    Credential boundaries

    • Portal enrolment tokens are short-lived and single-use.
    • The Agent has its own HSVE cloud credential stored on the Proxmox host.
    • The Agent uses a dedicated privilege-separated Proxmox API token rather than your normal Proxmox administrator password.
    • Local Proxmox HTTPS certificate validation is enforced; the installer does not silently disable TLS verification.

    Console sessions

    Virtual KVM uses a short-lived Portal session. The browser connects to HSVE Portal, the Agent establishes the Proxmox console path from inside the Site, and the relay exists only for the authenticated console session.

    Optional Windows RDP follows the same private model: Portal's RDP service is not public, TCP 3389 is not exposed to the internet, and the Site Agent connects internally to the selected Windows VM.

    Authorisation

    Site roles are checked for each protected capability. Viewer is read-only, Operator can perform day-to-day operations, Admin can also manage access and Agents, and Owner retains permanent Site ownership/deletion authority.

    Customer-controlled infrastructure data

    Portal coordinates Proxmox operations but does not move backup archives into HSVE Cloud. Proxmox-native backups remain on storage configured by the customer. VM disks and guest data stay in the customer Proxmox environment unless a chosen workflow explicitly moves them.

    ← PreviousMonitoringNext →Troubleshooting

    Ready to use HSVE Portal?

    Open Portal to connect Sites, operate guests and deploy your purchased HSVE Templates.

    open_portal() ↗
    HSVE./book_consultation.sh
    © 2026 HSVE Ltd · Company No. 17394992
    /privacy/terms/docs ↗/status