Skip to content

Security

Security that is on by default

Each site is isolated, live code cannot be edited in place, and every change in your account is recorded with who made it.

  • Read-only live code

    In Git mode, code reaches live only through a merge from staging. A plugin or a person cannot rewrite live files.

  • Bot protection and IP deny

    Pick Off, Normal, or Strict, let verified bots and your own paths through, and block addresses at the edge and the server.

  • Free SSL certificates

    Every domain gets a certificate that renews before it expires, with retries while the current one keeps working.

  • Daily backups

    Daily snapshots kept 14 to 30 days by plan, plus a snapshot before risky changes. Restore files, the database, or both.

  • Sign in and roles

    Sign in with Google or GitHub behind a Cloudflare check. Connect SAML or OIDC single sign-on, and give each person one of seven roles.

  • Activity log

    Every change records who made it, from where, and whether it worked, for the account and for each site.

Report a problem

  • Report a vulnerability to [email protected]
  • Test only your own account and sites
  • We publish security.txt and a disclosure policy
  • Secrets never sit in code, tickets, or logs

Start with one site. Add more when you need them.

Sign in with Google or GitHub, choose a plan, and your first site is on staging in minutes.