This week All our GPUs are sold at cost price — zero margin on the server. See the cost sheets

This week Every GPU sold at cost price

Account & billing

Account and security

How a DediGPU account is protected: password rules, sessions, anti-robot checks and API tokens.

4 min read · updated 2 September 2026

An account is an email address and a password. Because we send no email, some things work differently from the average hosting panel; this page lists them.

Password

At least 10 characters, typed twice at sign-up, hashed with bcrypt. Change it from Settings; changing it signs out every other session. Five failed sign-ins per email address or per IP address in an hour pause sign-in for the rest of the hour.

Lost passwords

There is no password-reset email and no recovery code. We hold an email address, a password hash and a balance — nothing that could prove an account is yours, and nothing we could write to.

A lost password is a lost account. Nobody can reopen it, including us, and the balance on it cannot be moved. Keep the password in a password manager.

Sessions

A session is a random token in a cookie, stored server-side as a hash, valid 30 days, bound to nothing else. Settings → Sessions signs out every other device. Signing out deletes the session.

Anti-robot check

Sign-up and sign-in carry a Cloudflare Turnstile widget. It usually completes without a click; it is the only third-party code on the site and it is loaded only on those pages.

API tokens

One token per account, issued from API and shown once; we store a hash and the last characters. Rotate it from the same page; the old token stops working immediately. Tokens are read-only today: see the API reference.

Event log

Settings → Activity lists sign-ins, orders, top-ups and key changes with the IP address and time. It is kept for twelve months.

Try it on a real server.

One month, at cost, root in under 5 minutes. Support opens with the first server.