Security & patching

What "managed" actually means here, written down so you can hold us to it.

In short

Every instance is single-tenant, pinned to a reviewed release, backed up nightly off-box and patched on a published schedule: critical advisories within 24 hours, high severity within 72. Internet-facing agent tools carry minimum versions, and secrets live outside the application image.

Self-hosted AI tools are a genuinely awkward security category. They are internet-facing, they hold credentials for other systems, several of them execute code by design, and the projects move fast enough that a release can be weeks old and already vulnerable. Flowise carried a critical remote code execution advisory (CVE-2025-59528) in versions before 3.0.6 — an instance running an older build with a public URL is an open door.

That is the actual product here. Anyone can start a container; the work is keeping it correct six months later.

Our commitments

AreaCommitment
Critical advisoryPatched within 24 hours of a fixed release
High severityWithin 72 hours
Version policyPinned to a reviewed release; minimum versions for agent tools
TenancyOne customer per instance
BackupsNightly, off-box, encrypted
TransportTLS on every endpoint, certificates renewed automatically
SecretsStored outside the application image, not in environment dumps or logs

What we ask of you

  • Use a strong admin password and enable the application’s own two-factor option where it has one.
  • Treat model API keys as credentials — rotate them if a team member leaves.
  • Tell us before exposing an agent tool that can execute code to the public internet without authentication.

Reporting a vulnerability

If you find a problem in our infrastructure, email [email protected] with enough detail to reproduce it. We will confirm receipt within one business day. Please do not test against other customers’ instances.

Questions

Security questions

How quickly do you patch?
Critical advisories within 24 hours of a fixed release being available, high severity within 72 hours. Where no fix exists we mitigate — usually by restricting network access to the affected component — and tell you what we did.
Do you pin versions?
Yes. Instances run a reviewed release rather than whatever :latest resolves to that morning, so an upstream regression cannot arrive unannounced. Internet-facing agent tools carry minimum versions: Flowise, for example, is never deployed below 3.0.6.
Where are backups stored?
Off the instance, nightly, encrypted. Restores are a support request. We keep a rolling window rather than an indefinite archive — if you need longer retention, ask.
Can you read my data?
Host-level access exists for support and backup operations. We do not read application data as a matter of course, we never train on it, and we never share it. What that means in legal terms is in the privacy policy.
Is the instance isolated from other customers?
Yes. One customer per instance, with its own storage and its own network policy. That is both a security position and a licence requirement for several applications we host.

Put your AI stack on your own box

Pick an app, pick a size, and have it running today. Month to month, cancel whenever.