Something is about to be given the keys to your website.
If that gives you pause, good. It is the right instinct, and this page is the answer to it rather than a page of reassuring adjectives.
What makes this safe to point at a real business.
We build it, not you
The connection, the permissions and the safeguards are set up during your session and tested in front of you. You are not handed instructions and wished luck, and there is no step where a wrong click quietly leaves something open.
It reaches what you name, and nothing else
You tell us which websites, servers and mailboxes are in scope. Those are the only things it has a route to. Your bank, your accounting software and anything you did not include are not protected by a rule that could be changed later; they were simply never connected.
It lives on your computer, in your name
The workspace is on your machine and the accounts stay yours. We are not a middleman holding your keys, which also means there is no Starforge account somebody could take over to reach your website.
Nothing reaches your live site without a person
Every change stops and waits. You see exactly what is different before it is published, and it stays unpublished until you approve it. Not the first time. Every time.
Everything that changes is written down
What changed, when, and who approved it. Including us: if support comes in to help, that goes in the same record, with the reason. Support you cannot see afterwards is a back door however politely it is described.
You can end it, and we show you how first
On setup day we also show you the switch that closes the connection. A connection you cannot end is not one you control, and you should know where that is before you ever need it.
What it cannot do.
Not a promise about how carefully it will behave. A list of things it has no route to.
- Publish anything to your live website on its own
- Reach a website, server or mailbox you did not connect
- Move your domain, or change who owns it
- Spend money, or sign you up to anything
- Delete a backup
- Let us in without you letting us in
Every one gets its own walls.
Connecting a second website does not widen the first connection. Each site, server and mailbox is scoped on its own, so access to one is not access to the rest.
That matters most to anyone holding somebody else’s work. An agency can connect thirty clients without any one of them becoming a route into another, and a client leaving is a credential withdrawn rather than an untangling exercise.
The detail, if you want it.
Nothing above depends on reading this. It is here because some people will want it, and a security page that cannot answer a specific question is not a security page.
How the connection is made
Access is issued as a credential scoped to the specific sites and repositories in your fleet, rather than an account password that would reach everything you own. It is revocable on its own, without disturbing anything else.
How secrets are held
Provider tokens and connection secrets are encrypted at rest with a key belonging to your fleet alone. Secrets are shown once when they are issued and cannot be read back afterwards, including by us.
How your fleet is separated
Your fleet runs on its own server with its own database and its own encryption key. There is no shared customer database, so there is nothing to leak across between one customer and another.
How dangerous actions are gated
Running commands directly against a server is not something a stored credential can do by itself. It needs a window a person opened deliberately, naming the machine and the reason, and the window closes itself.
How traffic is protected
Traffic between your browser and Fleet is encrypted in transit, as is traffic between Fleet and the machines it manages. Certificates are issued and renewed automatically, which is also why your visitors never see a warning.
How backups are treated
Backups are taken on a schedule, checksummed and verified, and a copy can be held on different infrastructure from the thing it protects. A backup stored beside the original is not a backup.
How coding tools connect
Supported development tools connect over a scoped, revocable credential tied to specific sites. They get the context and the deployment path for the work they are authorized to do, and not unrestricted access to everything underneath.
What happens when something goes wrong
You are told what happened, what it affected and what was done about it. We would rather deliver bad news ourselves than have you discover it.
The exit is part of the product.
Your website is on your hosting. Your domain is at your registrar. Your accounts are in your name. Closing the connection does not take any of it with us, because none of it was ever ours.
We would rather show you the door on the way in.
Something here we have not answered?
Ask before you commit, not after. We would rather have the awkward conversation now.