Security

Our security design goals

These are the principles AutoToast is being built against. They describe intent, not controls that are already running, and they are not a guarantee.

Design goals — controls not yet implemented

Per-site isolation

Each website runs in its own unprivileged boundary with a unique Linux identity, its own filesystem and its own resource limits.

Least privilege

Each site gets a database user scoped to its own database. Nothing gets broader access than the job requires.

Protected infrastructure credentials

Provider API tokens live in server-side secrets management only. They are never sent to a browser, an AI prompt or a log.

Encrypted off-site backups

Backups of files and databases are encrypted and stored away from the worker node, with restores tested rather than assumed.

Clear audit history

Who or what requested each action, what changed, whether it was approved, and how to roll it back.

Careful WordPress updates

A restore point before risky core, plugin or theme updates, and a verification step afterwards.

Staged changes

Where possible, changes happen in staging first, with a preview and an explicit approval before production.

No open shells

No customer root SSH, and no arbitrary commands accepted from a browser or an AI agent.

Account security today

What is actually running right now is the account layer: sign-up, email verification, password reset, and a database where each person can only read their own profile and the workspaces they belong to.