Security
Scoped tokens, container isolation, SSL by default, and credit checks before spend. We don't invent enterprise checklists we don't ship.
Tokens are limited to read, deploy, provision, or destroy. Hand an agent only the ability it needs. Rotate or revoke from team settings.
When you bring your own server, you own the box and the cloud account. We connect for deploys and management; we do not mark up or resell that compute.
Apps run in isolated containers on the server. One bad release does not own the whole machine by default.
Let's Encrypt certificates are issued and renewed for custom domains you attach.
provision_server checks plan limits and credit balance. estimate_cost and get_account exist so an agent can confirm cost before it spends.
Servers we provisioned are stopped when balance hits zero, then destroyed after a 7-day grace if you do not top up. BYO servers are never destroyed for credit reasons.
Email legal@cloudploy.com or hello@cloudploy.com with "security" in the subject. Do not open a public issue with exploit details.
Safer than a god-mode SSH key. Scope the token tightly. Prefer read + deploy for day-to-day; reserve provision and destroy for humans or tightly supervised agents.