We hold root credentials. Here's how we earn that.
ServerAlly connects to your production servers with real access — that's the whole point, and it's the biggest question you should be asking us. This page is the answer, and every claim on it traces to something we actually tested.
Your credentials
Login details are encrypted with AES-256-GCM before they're stored, and they are never displayed again — not to you, not to anyone — after you save them. Ally connects over the standard secure protocols: SSH, WinRM, or the panel's own API.
The safety model
Ally investigates read-only first, asks before any step it can't undo, moves files to quarantine instead of deleting them, and re-checks its own work before it reports success. Dangerous commands are blocked before they can run — 404 automated safety tests guard every command.
Un-trickable by design
Everything Ally reads on your server — files, logs, "helpful" notes — is treated as information, never as instructions. In live red-team tests we planted hacker instructions three different ways, including a faked "the owner pre-approved this." Ally refused every time and flagged it as an incident.
People & permissions
Teammates get access to specific servers with a role — view, operate, or admin. People with view-only access can never run commands. Ever.
The boring specifics
| Credentials at rest | Encrypted with AES-256-GCM before storage |
| Credentials on screen | Never shown back after you save them |
| Connection transport | SSH · WinRM · the hosting panel's own API |
| Dangerous commands | Blocked before they run — 404 automated safety tests guard every command |
| Risky steps | Always wait for your explicit approval |
| File removal | Quarantine first — a reversible mv, never a destructive rm |
| "Done" | Only after an independent re-check — the ✓ Verified badge |
| Content on your server | Read as data, never followed as instructions |
| This website | Zero external requests — no analytics, no CDNs, no trackers |
We pointed it at real, compromised servers.
Pre-launch, we don't have customer logos. We have something better: documented behavior on live, actively-infected production machines.
Judge it by its behavior.
Add a test server, ask for something risky, and watch it stop and ask you first.