Trust and security

You trust us with your servers. Here's how we handle that

A control panel with access to your infrastructure owes you an explanation of how that access works. Briefly, and without marketing.

Least privilege

The panel gets exactly as much access as the operations you request require. No more.

Transparent actions

Every operation is a task in the journal: you can see who started it, what it did and how it ended.

Your data stays yours

Sites, databases and backups live on your servers and storage. Disconnect from the panel — everything keeps working.

How we handle access

Six rules the panel follows when working with your servers

Keys under encryption

SSH keys are stored only in encrypted form, and the decryption keys don't sit next to the data. A database leak alone doesn't grant access to your servers.

Automatic rotation

The panel's management key is replaced regularly and automatically — without your involvement and without downtime.

A dedicated user, no root

The panel works through its own system user. Root login and password login are disabled during initial server setup.

Only from our addresses

The server accepts management connections only from the panel's fixed addresses — the firewall rules are maintained automatically.

Secrets are redacted

Passwords and keys in .env files and configs are redacted when an AI tool reads them. SQL for the assistant runs under separate, restricted database users.

Backups stay with you

Copies go to your own storage and can be encrypted with a key only you hold. We don't keep your backups on our side.

AI under control

The assistant can't do more than you allowed

Scoped tokens, mandatory approvals for dangerous actions, a denylist of destructive commands and an audit of every call — allowed or denied.

More about MCP

Every action in plain sight

Every panel operation is a task in the shared journal: author, contents, status and output. AI and MCP actions are tagged separately and also written to the audit log, with notifications for denied calls.

Access revokes instantly

Revoke an MCP token — access closes immediately. Disconnect a server from the panel — sites, databases and cron jobs keep running: Deploykin deletes nothing and leaves no locks behind.

Found a vulnerability?

Write to us directly — we'll respond fast, fix it and say thanks. We don't pursue good-faith security researchers. The machine-readable contact is in security.txt.

contact@deploykin.com

See for yourself

7 days free. Connect a test server and look at the task journal with your own eyes.

Try for free

We use cookies and the Yandex Metrica web-analytics service (including Session Replay) to improve the site. Details are in the privacy policy.