Kept on, and yours to keep
Backups, patching, and certificates are handled for you, every day, without a ticket. Portability is the other half — your stack lives as code, so it's never stuck here.
Backups
Automated, retained, and proven by restoring them — not a checkbox that's never been tested.
Daily backups
Every account is backed up automatically, every day — no opt-in, no configuration required.
Retention
Kept for 7 days by default. Extended backup retention (30-day) extends that to a 30-day window — daily backups kept for 30 days instead of 7.
Tested restores
Backups are periodically restored to confirm they work — recovery is proven, not assumed.
See what a tested restore actually is →
Patching
OS and runtime security patching runs on a managed cadence — urgent issues don't wait for it.
- Routine patching
- Regular managed cadenceOS and runtime security patches are applied on a standing schedule — no ticket, no downtime you have to plan around.
- Urgent CVEs
- ExpeditedCritical vulnerabilities are triaged and patched outside the normal cadence, as soon as a fix is available.
- Your action required
- NonePatching is part of every plan — there is nothing to schedule, approve, or remember on your end.
TLS & DNS
Certificates and records are managed as part of the platform — one less system to operate yourself.
Managed TLS
Certificates are issued and renewed automatically. Every site and instance is HTTPS by default — no expiry surprises, no manual renewal.
DNS management
Records are managed for you as part of the stack — pointed, propagated, and kept correct without a separate console to babysit.
Who owns what, the record sheet, and the certificate lifecycle →
The security headers every request gets by default, and what's left as a choice →
Everything as code
The anti-lock-in differentiator: your stack is defined in a repo you hold, not a console only we can see.
- 1
It's in a repo
Infrastructure and configuration are defined as code, committed alongside the app — not clicked together in a console only we can see.
- 2
No proprietary lock-in
The stack is built from standard, portable pieces — no bespoke format or hidden state that only runs here.
- 3
Leave any time, stack intact
Take the repo and the config with you. Nothing about leaving requires a rebuild from scratch.
See the handover procedure →
SLA posture
Uptime targets and service credits are the posture — the binding commitment is a separate, contractual document.
Uptime targets, backed by service credits
The grid is built and monitored to a stated uptime target, with credits owed if it's missed. The exact targets and credit schedule are laid out in full in the SLA — this page is the summary, that page is the commitment.
See it in context
- Status
Live status of the grid — the operational record behind the posture on this page.
- Support
How to reach a human, and how fast — the response side of reliability.
- SLA
The binding availability commitment — the contractual complement to this page.
- Portability
The anti-lock-in claim on this page, backed with the actual pack manifest and procedure.
- Recovery
The "tested restores" claim above, backed with the manifest, the procedure, and the retention ladder.
- Monitoring
The watch list behind "monitoring & alerts" — what fires, what fixes itself, and who gets woken.
- Patching
The "OS and runtime patching" claim above, backed with the full layer inventory, the severity table, and what a window actually does.
- Domains
The "TLS & DNS" claim above, backed with the ownership split, the record sheet, and the certificate lifecycle.
- Platform
How the stack fits together, end to end.
- Access
Who actually holds a key: the four principals, the capability matrix, and the CodeHerder agent's limits.
- Delivery
The response headers behind this page's TLS & DNS claim, plus the URL rules and the cache — the full delivery layer.
- Under attack
The network perimeter — firewall, DDoS mitigation, and rate limiting — the one topic this page never had its own section for.
Ready to start?
Tell us what you're running — one fixed monthly rate, within a business day.