berth

Hosting control panel

A safe berth for every site.

Berth runs web, mail, DNS, databases and backups on your own Debian or AlmaLinux servers. Move over from Plesk, cPanel or DirectAdmin in one night, with a rollback ready.

$ curl -fsSL https://get.berthpanel.app | sh

One-line install at launchDebian 13 · AlmaLinux 10 / 9 · amd64 and arm64 · signed packages

Moves you over from

  • Plesk
  • cPanel
  • DirectAdmin
  • another Berth server

Migration

Move a whole server in one night. Your customers notice nothing.

Berth keeps the layout your sites already live in: /var/www/vhosts, Maildir, the same users and IDs. Nothing has to be rewritten, and nothing on the old server is touched.

  1. 01 · Read

    Read-only copy

    Over a read-only SSH key, or from a regular Plesk backup file. Sites, databases, mail with flags, DNS zones and plans.

  2. 02 · Rehearse

    Trial run, size up front

    See what moves and how big it is before you start. Parity checks compare every site, mailbox and record.

  3. 03 · Sync

    Warm copy, then delta

    The bulk moves days ahead. On the night itself only the changes since the last sync go over.

  4. 04 · Switch

    Take over the address

    Keep the IP and your customers change no DNS at all. If the IP does change, Berth hands you the exact records per domain. A rollback stays ready.

Everything in the box

What other panels sell as extensions is built in.

Not the basics every panel has, but the parts you normally buy separately, bolt on, or go without.

Backups that prove themselves

Every week Berth restores a random subscription into a sandbox and checks the site and data. Encrypted, offsite to S3 with object lock, optionally with the customer's own key.

Monitoring and a status page

Uptime per page with keyword checks, response times, server load and a watchdog with office hours. Alerts by mail or Telegram, and a public status page for your customers.

Security score, fixed in one click

The internet.nl checks per domain — DNSSEC, DANE, DMARC, HSTS, TLS — explained in plain words, with a button that fixes what the panel can fix.

Malware scanner and WAF

Weekly ClamAV scans of every webspace with quarantine, and a ModSecurity firewall per domain with exceptions. No separate security licence.

WordPress toolkit, included

All installs in one list, with known vulnerabilities, automatic updates, hardening, one-click login and staging copies with their own domain and database.

Containers next to your sites

Run an app from any image without root, as the subscription's own user, and publish it on a subdomain or a path. Stop it and the original site is back.

Guaranteed resources

CPU, memory and IO limits per subscription, so one busy site cannot slow down the rest. Plus a private Valkey object cache and a page cache per site.

DMARC and TLS reports, read for you

The daily reports from Google, Microsoft and others are collected and grouped by sending source, so you see who sends mail in your name and whether it passes.

Git deploy and a safe terminal

Deploy on every push with a read-only deploy key and webhook. A browser terminal as the site user, opened only after a fresh second-factor check.

And the basics, done carefully: nginx and Apache, a PHP version per site, mail with webmail, DNS with automatic DNSSEC, Let's Encrypt and any ACME CA, MariaDB and PostgreSQL, FTP, cron, a REST API and the berth command.

See monitoring, tested backups and more in detail →

Made in the EU

Designed and built in the Netherlands.

Berth is developed entirely within the European Union, by a Dutch team, under European law. No investors across the ocean, no data leaving for a cloud you did not choose.

  • Your servers, your jurisdictionBerth runs on your own hardware or with the European provider you pick. Customer data never passes through us.
  • Nothing loaded from elsewhereThe panel ships its own fonts and scripts and calls no third-party services. That is what your privacy statement can rely on.
  • GDPR and NIS2 in the productData export and erasure per customer, IP masking in logs, and incident deadlines that match the NIS2 directive.
  • Open source underneathProven open-source services such as nginx, Postfix, Dovecot and MariaDB. No lock-in on the parts that hold your data.

Corporate and government

Built for the audit, not bolted on after.

Each feature maps to an ISO 27001 Annex A control. Berth produces the evidence your auditor asks for, per customer and per period.

  • Tamper-evident audit trailHash-chained, exportable, streamed to your SIEM over TLS.
  • Passkeys and single sign-onPhishing-resistant MFA per role, sign-in with OIDC and SAML.
  • Four eyes, just in timeApproval for sensitive actions and time-boxed admin rights.
  • NIS2 incident timers24-hour, 72-hour and one-month deadlines with a signed timeline.
  • internet.nl, fixed in placeDNSSEC, DANE, DMARC reject, HSTS and security.txt, with a button to fix what Berth can.
  • Privacy by defaultIP masking in logs, data export per customer, erasure with a certificate.

Under the hood

Validated before it goes live.

Berth never patches a config file in place. It renders the whole desired state, checks it with each service's own validator, and swaps it in atomically. A bad change never reaches a running server.

  • Written in Go. A small privileged agent; everything else runs unprivileged.
  • Plain open-source services you already know: nginx, Postfix, Dovecot, BIND, MariaDB.
  • Signed releases with an SBOM, updates through apt or dnf with rollback.
$ berth domain create shop.example.com --plan business → render /etc/berth/rendered/.staging ✓ nginx -t syntax ok ✓ postfix check ok ✓ named-checkzone shop.example.com ok → swap atomic rename → reload nginx postfix bind ■ certificate issued via ACME, 3 names

Pricing

Per server. No per-account surprises.

Berth is in early access. Prices are set at launch; early-access partners get a launch price that stays.

Server

One server, your own sites and customers.

At launch
  • All modules included
  • Migration from Plesk, cPanel, DirectAdmin
  • Updates and security fixes
Join early access
For hosting companies

Host

Unlimited domains, resellers and the provisioning API.

At launch
  • Unlimited domains
  • Resellers and white label
  • WHMCS and HostBill provisioning
Join early access

Sovereign

Corporate and government, in your own network.

At launch
  • Offline installation bundle
  • SSO, auditor role and evidence packs
  • Assisted server migration
Join early access

Bring your sites in to berth.

Early access is open for hosting companies, agencies and organisations that run their own servers.