SECURITY

We ask for SSH access. Here is what that means.

Handing a tool the keys to your servers is a real decision, and it deserves specifics rather than a badge. This page describes what Depfloy stores, how it is encrypted, what it can reach on your machines, and what is left when you stop paying.

What Depfloy stores
SSH keys and sudo passwords

Encrypted at rest with AES-256-CBC and an HMAC, using a random IV per value. They are decrypted only when a job needs to open a connection to your server.

Environment variables

Encrypted at rest the same way. They are written to your server as part of a deploy; the copy Depfloy holds exists so the next release can be configured without you re-entering it.

Configuration and history

Which servers exist, which projects run on them, deploy history, backup schedules and the activity log. This is the part Depfloy genuinely holds.

What stays on your servers
Your application data

Databases, uploads and files live on your servers. Depfloy connects to them; it does not copy them.

Your backups

The runner streams a dump from your server straight to the destination you configured — your S3 bucket, your R2, your SFTP host. Depfloy is not a hop in that path and keeps no copy.

Your traffic

Visitors reach your server directly. Nothing about serving your site routes through Depfloy, which is also why an outage here is not an outage for your sites.

ACCESS

Two checks, not one.

Anything that reaches your servers passes through both the role of the person asking and, for API and agent traffic, the abilities of the token being used. Neither one alone is enough.

Role

Owner, Admin, Manager, Developer or Viewer — and a scope that can pin a member to specific servers or projects rather than the whole organization.

How roles work →
Token abilities

An API token carries the abilities picked when it was created, and they are enforced on every request. A read-scoped token cannot deploy even if its owner could.

Administrative server access

Depfloy uses its own server user and elevated privileges for provisioning and management. Connect servers only when you are authorized to grant that administrative access.

LEAVING

Nothing breaks when you go.

Depfloy is not in the request path. It configured nginx, issued the certificates, wrote the cron entries and started the workers — and all of that keeps running on your machine without us. Cancelling costs you the dashboard, not the sites.

What survives on the server
  • ·nginx site configuration and TLS certificates
  • ·The current release and the previous ones on disk
  • ·Cron entries and supervised background workers
  • ·Databases, caches and search indexes
  • ·Your own SSH access, exactly as it was

Certificate renewal is the one thing that needs a plan, since that is a scheduled job Depfloy manages for you.

FAQ

Security questions

What happens if I stop paying? +
Your servers keep running exactly as they were configured — nginx, certificates, cron entries, workers and all. Depfloy is the thing that set them up and manages changes; it is not in the path of a request. You lose the dashboard, not the sites.
Does Depfloy have root on my server? +
Depfloy uses SSH and elevated privileges to provision and manage your server. Treat connecting a server as granting administrative access. Your own root access remains available.
Can I see what was done and by whom? +
Yes. Deploys, server changes, environment edits and permission changes are recorded in the activity log with the member who made them, filterable by person and date.
How are API tokens scoped? +
A token carries abilities chosen when it is created, and those abilities are enforced on every request in addition to the role of the user who owns it. A request has to pass both checks — the role must allow it and the token must carry it.
Is two-factor authentication available? +
Yes, with an authenticator app and recovery codes, configured from your profile.
What can an AI agent do through the MCP server? +
Only what the user it acts for could do. Every tool call is checked against both the role permissions and the token abilities, so an agent connected with a read-scoped token cannot deploy no matter what it is asked to do.

Start with one server.

7 days free, no credit card. Connect a machine that does not matter yet and see exactly what Depfloy does to it.