CloudPloy

Security

Least privilege for humans and agents.

Scoped tokens, container isolation, SSL by default, and credit checks before spend. We don't invent enterprise checklists we don't ship.

Scoped API tokens

Tokens are limited to read, deploy, provision, or destroy. Hand an agent only the ability it needs. Rotate or revoke from team settings.

SSH and secrets stay on your side of BYO

When you bring your own server, you own the box and the cloud account. We connect for deploys and management; we do not mark up or resell that compute.

Container isolation

Apps run in isolated containers on the server. One bad release does not own the whole machine by default.

Automatic SSL

Let's Encrypt certificates are issued and renewed for custom domains you attach.

Spend checks before provision

provision_server checks plan limits and credit balance. estimate_cost and get_account exist so an agent can confirm cost before it spends.

Credit zero behavior

Servers we provisioned are stopped when balance hits zero, then destroyed after a 7-day grace if you do not top up. BYO servers are never destroyed for credit reasons.

Where do I report a vulnerability?

Email legal@cloudploy.com or hello@cloudploy.com with "security" in the subject. Do not open a public issue with exploit details.

Is MCP safe for autonomous agents?

Safer than a god-mode SSH key. Scope the token tightly. Prefer read + deploy for day-to-day; reserve provision and destroy for humans or tightly supervised agents.