Security
Safe by having less to attack
The safest code is the code that does not run. cmsspot is built on that idea: nothing of it runs on your website, your login has no password to steal, and every site is kept apart from every other. Here is how the layers fit together.
What this means for a client
A client logs in with a link, sees only their own site, and edits fields. They cannot reach the server, cannot see the connection details, and cannot break the layout. If they leave, their access is removed in one click and nothing else changes.
What this means for an agency
You keep the SFTP credentials in cmsspot, encrypted, and never have to hand them to a client. Every change the client or an AI makes is backed up first. When a site is finished, there is nothing to patch and nothing to monitor, because nothing of cmsspot is on it.
What we leave out of this page
On purpose, this page does not list exact limits, file names, or how each check is built. Those details help an attacker more than they help you. If you have a specific question about how cmsspot handles something, write to us and we will answer it directly.
Found something?
If you believe you have found a security issue in cmsspot, write to contact@cmsspot.com before you publish it. We take reports seriously and reply quickly.
Get started
Hand a site over without handing over the keys
Give a client editing, keep the server to yourself.