DWShells:Security and Backups
Protect your account and important files
Use dashboard 2FA, public SSH keys and realistic backup expectations.
Last verified: 6 October 2026, against the current customer panel and service rules. Your effective dashboard permissions and assigned values take precedence over examples.
← Documentation hub · Visual website guide
Protect access and recovery
| Step | What it means |
|---|---|
| 01 · Dashboard | Enable 2FA and save recovery codes. |
| 02 · Shell | Manage authorised public SSH keys. |
| 03 · Files | Keep independent copies and inspect backup coverage. |
Dashboard two-factor authentication
- Open Security Centre. Select the shell if required and enter the current dashboard password for sensitive actions.
- Start authenticator setup. Follow the setup controls, scan the QR code with your authenticator and enter a current code to enable 2FA. Do not share the QR code or setup secret.
- Save recovery codes. Store them somewhere secure outside this shell. Replacing recovery codes invalidates the older set; security changes can sign out other sessions.
Public SSH keys
Generate and protect a key pair on your own device. In Security Centre, add only the public SSH key and a useful label; confirm using your dashboard password. The matching private key stays on your device. Removing a key prevents future key logins but does not close an already open SSH session. Keep a working recovery method before removing your only key.
What the panel backups cover
Before you continue: Current panel home-directory copies are stored on the shell server, with three recent copies retained. Off-server protection is not verified in the customer interface. These copies do not protect against loss of the server.
Request file recovery
- Inspect the available copies. Open Backups & Restore. Read the backup time, integrity/coverage details and any stale status or warnings.
- Choose the copy and explain the need. Submit a recovery request with the affected paths and the problem. Approval is a review decision, not an immediate restore.
- Wait for actual recovery. Staff stage and inspect an approved copy and arrange manual recovery. Check the request status and completion notes; do not assume approved means your files have been restored.
Keep your own backup
Download important files using SFTP and retain a separate copy outside the VPS. Copy website sources and app configurations before editing or fresh installation. A home copy may omit sockets or unreadable files and can include changing files; it does not promise an application-consistent database or live-session restore.
If you suspect compromise
Contact staff promptly with your username, approximate time and the issue. Never send passwords, private keys, recovery codes or verification links. Review public keys and running applications, and follow staff advice on resetting credentials and ending sessions.
You are protected when
- 2FA is enabled and recovery codes are stored independently.
- You recognise all authorised SSH keys.
- Important files have a separate off-server copy.
- You understand the coverage of a backup before requesting recovery.
Backup request states
| State | Meaning |
|---|---|
| Submitted | Staff review is pending |
| Approved | Awaiting manual recovery; files have not necessarily been restored |
| Completed | Staff have reported manual recovery; read the completion notes and verify the files |
When requesting recovery, give the relevant paths, the approximate time the problem occurred, which copy you need and whether current files should be preserved. Staff must inspect and coordinate the recovery.
Independent backup checklist
- Keep an off-server copy of website sources and essential application configuration.
- Store credentials securely; do not publish backup archives in
public_html. - Check that your copy contains the files you need and can be opened.
- Use application-specific export methods for databases where permitted; a changing home-directory copy does not guarantee a consistent database restore.
Rules and support
This guide describes how to use the service; it does not replace Signup and Rules. Join #DWShells on irc.darkworld.chat using TLS port 6697 for help. Use the customer portal for your actual status and connection details. Never share credentials or recovery links.