We host the platform, you keep your servers
App Deployer orchestrates your deployments from a platform we operate; your servers and application data stay with you. The SSH connection is the only boundary between the two, and it's designed to stay closed by default.
- SSH credentials (password or key) are encrypted, never stored in plain text.
- No standing access: the connection is only opened at deployment time.
- Access and actions are scoped per workspace, with a full audit history.
Encrypted, ephemeral SSH connections
Your connection credentials (password or private key) are encrypted at rest in our database. They are only decrypted at the precise moment a deployment starts, for the time it takes to run the pipeline on your server, and the connection is closed immediately after. There is no persistent SSH session kept open outside these execution windows.
Environment variables and secrets
Every environment (Production, Staging...) of a deployment target has its own set of variables, encrypted on the platform side and isolated from one another: a secret configured for Staging is never accessible from Production, and vice versa. Variables flagged as secret are masked in the UI once saved.
Role-based access control
Access to an application and its environments is governed by roles scoped to the workspace (owner, manager, deployer, viewer), not by a global account-wide access level. A member can only trigger a deployment, edit a pipeline, or view variables if their role explicitly allows it.
Full audit trail
Every deployment and every configuration change (pipeline, variables, members) is logged: who did what, when, and through which trigger (manual or webhook). This log can be reviewed at any time to trace an incident or meet an internal audit requirement.