Skip to content
Vimonto Deploy

Security and teams

Give everyone the access they need, and no more

Every server is hardened from the first minute: SSH keys only, a firewall that denies by default, fail2ban and daily security updates. On top of that, five roles, teams that limit who sees which servers, and an audit log of every change.

Server security

Hardened by provisioning, on every server

  • SSH keys only

    Password and keyboard-interactive logins are off, and root may only log in with a key. Each server has its own Ed25519 key pair for Vimonto Deploy.

  • Firewall that denies by default

    ufw blocks all incoming traffic except SSH, and HTTP and HTTPS on servers with Nginx. Database and cache ports open to the private network only.

  • fail2ban

    Addresses that keep failing to log in over SSH are blocked for a while. It follows SSH when you move it to another port.

  • Unattended upgrades

    Security updates are installed every day and old packages are cleaned up weekly, without you logging in.

  • Known host keys

    The server's SSH host key is stored on first contact. If it ever changes, Vimonto Deploy refuses to connect instead of trusting the new one.

  • Website isolation

    Sites for different clients run as their own Linux user with their own PHP-FPM pool, so one site cannot read another's files or .env.

Firewall rules and SSH keys from the browser

The Network page adds ufw rules for one port or a range, TCP, UDP or both, from anyone or from an address or CIDR range. Deny rules go above allow rules, so blocking one address on port 443 leaves everyone else through. The SSH rule cannot be removed, so you never lock out the platform.

Keep SSH keys in three places: your own account keys, organization keys that go on every server for the system user and root, and keys for one server. When someone leaves, deleting an organization key removes it from every active server.

  • Ed25519, ECDSA and RSA keys of 2048 bits or more, including security keys
  • Change the SSH port: the new port is tested before the old one closes
  • Sudo and database passwords are shown once, then deleted for good
  • Secrets are stored encrypted and never returned by the API

Network and firewall in the docs

Roles

Everyone sees, roles decide who changes

Every member can view the organization. The role decides what they may change; unlimited members are included in every plan.

  • Owner

    Everything, including appointing owners and deleting the organization. An organization always keeps at least one.

  • Administrator

    Everything except managing owners and deleting the organization: members, integrations and settings.

  • Manager

    Creates, deletes and transfers servers, manages sites, teams and the organization's SSH keys.

  • Developer

    Full access to existing servers and sites, the terminal, recipes and backups, but cannot create or delete servers.

  • Viewer

    Sees every server, site, deploy and task and gets notifications, but cannot change anything.

Teams for clients and projects

A team is a group of members with the servers they work on, for example one per client. Set a member to Only their teams' servers and the rest of the organization disappears for them: the server and site lists, activity, the audit log, notifications, recipes and the API only show their servers, and other servers answer "not found".

Nobody can widen their own access, and owners and administrators always see every server. A server that a limited member creates joins their teams, so they never lose sight of it.

Teams in the docs

Accountability

A record of who did what

  • Audit log

    Every change and action by people, in the browser or through the API, with old and new values. Kept for 365 days and exportable as CSV.

  • Browser terminal

    A shell through a single-use ticket valid for 30 seconds, with the permission checked twice. Who, as which user and how long is logged; keystrokes never are.

  • Activity

    Every background task with its steps and output, visible to the team while it runs and kept for 90 days.

  • Two-step sign-in

    An authenticator app, passkeys or codes by email after your password, with recovery codes for when you lose your phone. A passkey can also sign you in without a password.

  • Required for everyone

    Owners and administrators can require an authenticator app or a passkey for every member of the organization.

  • SSH logins

    Every successful SSH login on your servers, with the user, IP address and key, kept for 90 days.

Privacy

Made and hosted in the EU

Vimonto Deploy is made and hosted in the EU. Your servers run wherever you create them: you choose the provider and the region, including regions in Germany, Finland and the Netherlands.

Under Account settings → Privacy you download everything Vimonto Deploy keeps about you as one JSON file, and delete your account yourself. Passwords, tokens and private keys are never in the export. After deletion, audit entries stay for your organizations but show Deleted user, and their IP addresses go after 365 days.

Your data in the docs

Questions about security and teams

Can I give someone read-only access?

Yes. Invite them as a Viewer. They see every server, site, deploy and task, but cannot change anything or open a terminal.

Can I limit a freelancer to one client's servers?

Yes. Put them in a team with those servers and set their server access to Only their teams' servers. Their role still decides what they may change there.

Do extra members or teams cost extra?

No. The plan is per organization, with unlimited members and teams. See pricing.

Does the audit log record what I type in the terminal?

No. Opening a terminal is recorded, with the server and the login user, but keystrokes and output are never stored.

Can someone edit or delete audit log entries?

No. Entries cannot be edited or deleted in the app. They are removed after 365 days, or with the organization.

Your next deploy could be live before your coffee is.

Create an organization, connect a server and push. That is all.