We ask for SSH access. Here is what that means.
Handing a tool the keys to your servers is a real decision, and it deserves specifics rather than a badge. This page describes what Depfloy stores, how it is encrypted, what it can reach on your machines, and what is left when you stop paying.
Encrypted at rest with AES-256-CBC and an HMAC, using a random IV per value. They are decrypted only when a job needs to open a connection to your server.
Encrypted at rest the same way. They are written to your server as part of a deploy; the copy Depfloy holds exists so the next release can be configured without you re-entering it.
Which servers exist, which projects run on them, deploy history, backup schedules and the activity log. This is the part Depfloy genuinely holds.
Databases, uploads and files live on your servers. Depfloy connects to them; it does not copy them.
The runner streams a dump from your server straight to the destination you configured — your S3 bucket, your R2, your SFTP host. Depfloy is not a hop in that path and keeps no copy.
Visitors reach your server directly. Nothing about serving your site routes through Depfloy, which is also why an outage here is not an outage for your sites.
Two checks, not one.
Anything that reaches your servers passes through both the role of the person asking and, for API and agent traffic, the abilities of the token being used. Neither one alone is enough.
Owner, Admin, Manager, Developer or Viewer — and a scope that can pin a member to specific servers or projects rather than the whole organization.
How roles work →An API token carries the abilities picked when it was created, and they are enforced on every request. A read-scoped token cannot deploy even if its owner could.
Depfloy uses its own server user and elevated privileges for provisioning and management. Connect servers only when you are authorized to grant that administrative access.
Nothing breaks when you go.
Depfloy is not in the request path. It configured nginx, issued the certificates, wrote the cron entries and started the workers — and all of that keeps running on your machine without us. Cancelling costs you the dashboard, not the sites.
- ·nginx site configuration and TLS certificates
- ·The current release and the previous ones on disk
- ·Cron entries and supervised background workers
- ·Databases, caches and search indexes
- ·Your own SSH access, exactly as it was
Certificate renewal is the one thing that needs a plan, since that is a scheduled job Depfloy manages for you.
Security questions
What happens if I stop paying? + −
Does Depfloy have root on my server? + −
Can I see what was done and by whom? + −
How are API tokens scoped? + −
Is two-factor authentication available? + −
What can an AI agent do through the MCP server? + −
Start with one server.
7 days free, no credit card. Connect a machine that does not matter yet and see exactly what Depfloy does to it.