Skip to content

Security

Boundaries that hold, including for agents

Hostacker is designed so that automation can be trusted with real infrastructure: scoped credentials, enforced budgets, explicit approvals and a complete audit trail.

This page describes Hostacker's intended security posture. Phase 1 is a front-end preview with no accounts, credentials or customer data, so none of these controls are active yet.

Controls

What protects your infrastructure

  • Scoped credentials

    API keys carry explicit scopes and can be limited to a project or environment. Keys are shown once and stored hashed.

  • Private by default

    Managed databases and internal services attach to a private network. Public exposure is an explicit choice, never a default.

  • Encryption in transit and at rest

    TLS terminates on managed endpoints with certificates we rotate. Volumes and backups are encrypted at rest.

  • Audit logging

    Every mutation records the actor, the surface it came from — dashboard, CLI, API or agent — the resource and the resulting cost.

  • Spending controls

    Budgets and approval thresholds apply to automation as strictly as to people, which is what makes agent access defensible.

  • Least privilege for agents

    Agent permissions are granted per action. Read-only is the default and destructive operations start disabled.

Least privilege

Permissions are granted, not assumed

The same permission model applies to humans, CI systems and AI agents. Nothing gets blanket access because it happens to hold a key.

Vulnerability disclosure
Send reports to security@hostacker.com. We acknowledge within one business day and will keep you updated until the issue is resolved. Please do not test against other customers' resources.
Data location
You choose a Hostacker region and your workload stays in it. Backups are stored in the same region unless you explicitly enable cross-region retention.
Subprocessors
Hostacker operates on sourced infrastructure. A current subprocessor list, with the regions each one serves, is published before commercial launch.
Incident communication
Service-affecting incidents are published on the status page with updates until resolution, followed by a written post-incident summary.
MCP Permissionshostacker

Servers

  • ReadAllowed
  • RestartAllowed
  • ResizeApproval required
  • DeleteDisabled

Billing

  • ReadAllowed
  • PurchaseApproval required

Questions about our security model?

We would rather answer them now than in a procurement questionnaire later.