Security and operations
Operate ONHOST CMS with private storage, verified payments, restricted administration and maintainable recovery procedures.
## Core controls
ONHOST CMS uses authenticated sessions, CSRF validation, rate limits, private product storage, provider-side payment confirmation, audit records and signed download links. These controls work together; do not bypass them by exposing a release ZIP directly from the public directory or trusting a browser checkout callback.
## Licence package safety
Protected product uploads are checked for unsafe ZIP paths, case-conflicting entries, links and oversized source before packaging. The injector works on a temporary copy, verifies each rewritten PHP source can be parsed, then replaces the stored release atomically. If packaging fails, the original release is retained only until the failed upload is safely removed.
## Backups and recovery
Back up the database and private storage together. Test restoration in a separate environment before relying on a backup. Keep your PHP version, extension list, hosting credentials, provider credentials and deployment method documented for the people responsible for recovery.
## Updates
Apply ONHOST CMS updates through the approved release process. Before updating production, take a backup, review the release notes, verify the target PHP version and run a checkout plus download smoke test after deployment.
## Incident response
If you suspect a credential, payment webhook, licence key or product release has been compromised, rotate the affected secret, review audit logs and suspend only the impacted records while you investigate. Use the module manager to pause a delivery surface when needed, but preserve evidence and avoid destructive changes during an active incident.