Corporate and government
Built for the audit, not bolted on after.
Each feature maps to an ISO 27001 Annex A control. Berth produces the evidence your auditor asks for, per customer and per period.
Hosting control panel
Berth runs web, mail, DNS, databases and backups on your own Debian or AlmaLinux servers. Move over from Plesk, cPanel or DirectAdmin in one night, with a rollback ready.
One-line install at launchDebian 13 · AlmaLinux 10 / 9 · amd64 and arm64 · signed packages
Moves you over from
Migration
Berth keeps the layout your sites already live in: /var/www/vhosts, Maildir, the same users and IDs. Nothing has to be rewritten, and nothing on the old server is touched.
Over a read-only SSH key, or from a regular Plesk backup file. Sites, databases, mail with flags, DNS zones and plans.
See what moves and how big it is before you start. Parity checks compare every site, mailbox and record.
The bulk moves days ahead. On the night itself only the changes since the last sync go over.
Keep the IP and your customers change no DNS at all. If the IP does change, Berth hands you the exact records per domain. A rollback stays ready.
Everything in the box
Not the basics every panel has, but the parts you normally buy separately, bolt on, or go without.
Every week Berth restores a random subscription into a sandbox and checks the site and data. Encrypted, offsite to S3 with object lock, optionally with the customer's own key.
Uptime per page with keyword checks, response times, server load and a watchdog with office hours. Alerts by mail or Telegram, and a public status page for your customers.
The internet.nl checks per domain — DNSSEC, DANE, DMARC, HSTS, TLS — explained in plain words, with a button that fixes what the panel can fix.
Weekly ClamAV scans of every webspace with quarantine, and a ModSecurity firewall per domain with exceptions. No separate security licence.
All installs in one list, with known vulnerabilities, automatic updates, hardening, one-click login and staging copies with their own domain and database.
Run an app from any image without root, as the subscription's own user, and publish it on a subdomain or a path. Stop it and the original site is back.
CPU, memory and IO limits per subscription, so one busy site cannot slow down the rest. Plus a private Valkey object cache and a page cache per site.
The daily reports from Google, Microsoft and others are collected and grouped by sending source, so you see who sends mail in your name and whether it passes.
Deploy on every push with a read-only deploy key and webhook. A browser terminal as the site user, opened only after a fresh second-factor check.
And the basics, done carefully: nginx and Apache, a PHP version per site, mail with webmail, DNS with automatic DNSSEC, Let's Encrypt and any ACME CA, MariaDB and PostgreSQL, FTP, cron, a REST API and the berth command.
Made in the EU
Berth is developed entirely within the European Union, by a Dutch team, under European law. No investors across the ocean, no data leaving for a cloud you did not choose.
Corporate and government
Each feature maps to an ISO 27001 Annex A control. Berth produces the evidence your auditor asks for, per customer and per period.
Under the hood
Berth never patches a config file in place. It renders the whole desired state, checks it with each service's own validator, and swaps it in atomically. A bad change never reaches a running server.
Pricing
Berth is in early access. Prices are set at launch; early-access partners get a launch price that stays.
One server, your own sites and customers.
Unlimited domains, resellers and the provisioning API.
Corporate and government, in your own network.
Early access is open for hosting companies, agencies and organisations that run their own servers.