Security

Safe by having less to attack

The safest code is the code that does not run. cmsspot is built on that idea: nothing of it runs on your website, your login has no password to steal, and every site is kept apart from every other. Here is how the layers fit together.

1
Nothing runs on your sitecmsspot connects over SFTP, reads your files as data, and writes back only the fields that changed. There is no plugin, no script and no login page on your domain.
2
No passwords to loseYou log in with a link sent to your email. It works once and expires quickly. There is no password database for anyone to break into, and the login form is rate limited and protected against bots.
3
Every site is isolatedA user only sees the sites they have been given. Each site has its own folder, its own backups and its own log. Server details are encrypted at rest and never shown in the interface or to an AI.
4
Writes are carefulEvery save is checked against the file on the server first, so two people cannot overwrite each other. A backup is taken before anything is written, and PHP files are syntax checked so a broken page never goes live.
5
Content is treated as contentWhat you type in a field is stored as text, never as code. Pasted HTML is cleaned, scripts are removed, and nothing from a field can run on the server.
6
Connections are guardedcmsspot only connects to public addresses, remembers each server's identity, and refuses to send anything if that identity changes. Too many attempts from one place are stopped.
7
AI access on your termsAn assistant gets a token for one site at one of three levels, from read-only to full file access. You choose folders and files it may never see, and you can revoke it at any time. Everything it does is logged.
8
The interface defends itselfStrict browser policies, protection against cross-site requests, and a security log that records failed logins, rejected tokens and changes to access, so an administrator can see what happened.

What this means for a client

A client logs in with a link, sees only their own site, and edits fields. They cannot reach the server, cannot see the connection details, and cannot break the layout. If they leave, their access is removed in one click and nothing else changes.

What this means for an agency

You keep the SFTP credentials in cmsspot, encrypted, and never have to hand them to a client. Every change the client or an AI makes is backed up first. When a site is finished, there is nothing to patch and nothing to monitor, because nothing of cmsspot is on it.

What we leave out of this page

On purpose, this page does not list exact limits, file names, or how each check is built. Those details help an attacker more than they help you. If you have a specific question about how cmsspot handles something, write to us and we will answer it directly.

Found something?

If you believe you have found a security issue in cmsspot, write to contact@cmsspot.com before you publish it. We take reports seriously and reply quickly.

Get started

Hand a site over without handing over the keys

Give a client editing, keep the server to yourself.