Security
Safe by design, not by promise
Tendbot’s AI can work out what’s wrong, but its limits are built into the agent on your server. Here’s exactly what it can and can’t do, and what happens to your data.
The AI does the thinking. A fixed catalogue limits the doing.
01 /The limits
What Tendbot can and can’t do
The agent works inside a fixed fence. These limits are built into it, so they apply in every access mode.
outside — never, in any mode
- Run arbitrary commands
- Reboot your server
- Delete disks
- Run read-only checks
- Restart a crashed service or container
- Edit a config file to fix a known problem
- Free up disk space
- Install security updates
- Stop a runaway process
- Change users, SSH or firewall settings
- Make more than 10 fixes a day
- Break the rules you set
outside — never, in any mode
Every fix inside the fence waits for your OK unless you choose otherwise in access modes.
Stop button & report-only mode, always
02 /Access modes
You decide how much Tendbot does on its own
Ask is the default. Switch any time — the limits above apply in every mode.
| Fix | AskDefault | Auto | Autopilot |
|---|---|---|---|
| Restart crashed nginxLow risk · undoable | You approve | Runs on its own | Runs on its own |
| Clear 6 GB of old logsLow risk · undoable | You approve | Runs on its own | Runs on its own |
| Raise PHP memory limitMedium risk · undoable | You approve | You approve | Runs on its own |
| Install 12 security updatesMedium risk | You approve | You approve | Runs on its own |
| Reboot the serverOff-limits | Never | Never | Never |
- Max 10 fixes per server per day
- A Stop button, always
- Report-only mode
- Your own rules apply
- Two-factor login required for Autopilot
03 /Every fix
Seven safeguards on every single fix
Whether you approve a fix yourself or your access mode does, it always goes through the same careful steps.
If anything looks different from what Tendbot expected, it stops and tells you instead of carrying on.
- 01ProposedYou see what will change, how risky it is, and whether it can be undone.
- 02ApprovedBy you, or by the access mode you chose — and it’s logged either way.
- 03Backed upAnything the fix touches is saved first.
- 04Re-checkedTendbot confirms the problem is still there before changing anything.
- 05Applied, one change at a timeNever several fixes at once, so nothing gets tangled.
- 06VerifiedTendbot checks the fix actually worked, and tells you if it didn’t.
- 07Undo for 14 daysOne click restores the backup, free of charge.
activity · web-01live
- Wed 14:05Report-only · 12 security updates found⏸ waiting for you
- Wed 13:46You undid · Raise PHP memory limit↺ restored from backup
- Wed 13:30Refused · Request to reboot the server✗ never allowed
- Wed 13:17Auto mode approved · Clear 6 GB of old logs✓ verified · undo for 14 days
- Wed 13:07You approved · Restart crashed nginx✓ verified
04 /Accountability
Every action is logged
The activity log records what ran, when, and who approved it — you, or the access mode you chose. Refused requests and undos are in there too.
Tendbot remembers what’s normal for your server so it can spot changes, but that memory never stores secrets — and you can edit it.
05 /Your data and access
Your secrets stay yours
What Tendbot keeps, what it never sees, and how you stay in control of your account.
- Secrets stay on your serverPasswords and keys are never shown or sent out.
- SSH login, used onceOnly to install the agent, then deleted.
- Removed means removedA removed server’s data is deleted after 30 days.
- No training on your dataOur AI provider doesn’t train its models on it.
- Anonymised, with opt-outAnonymised data helps improve Tendbot. Opt out in settings.
- Two-factor loginWith an authenticator app. Required for Autopilot.
- Export or delete anytimeTake your data with you, or delete your account, whenever you like.
- Recovery codesTwo-factor login comes with recovery codes, so you’re never locked out.
06 /Questions
Security questions, answered
Does Tendbot keep my SSH login?
No. If you connect over SSH, your login is used once to install the agent and then deleted. After that, only the agent talks to Tendbot — and it only connects out.
Can Tendbot run any command it likes?
No. The agent can only run actions from Tendbot’s built-in catalogue, such as restarting a service or clearing old logs. Arbitrary commands, reboots, disk deletion and user, SSH or firewall changes are never allowed, in any mode.
What if a fix makes things worse?
Every fix takes a backup first, changes one thing at a time and is verified afterwards. If it didn’t work, Tendbot tells you. You can undo a fix with one click for 14 days.
Can I stop Tendbot at any time?
Yes. There’s a Stop button, a report-only mode where nothing is changed, and you can switch access modes whenever you like.
Is my data used to train AI?
Our AI provider doesn’t train its models on your data. We use anonymised data to improve Tendbot and train our own models — you can opt out in settings.
How do I remove Tendbot?
Uninstall the agent with one command. Your account data can be exported or deleted any time, and a removed server’s data is deleted after 30 days.
Private alpha · invites in small waves
Let Tendbot look after your server
Join the alpha with one email address. Early testers help shape Tendbot and keep the founding-member perks after launch.
- No card needed
- Leave any time