An AI on your server, and you holding the keys
Giving an AI a shell on your server is powerful and should feel uncomfortable. AskYourStack is built around that: nothing to break into, every action sorted by risk, a gate in front of anything destructive that only you can open, a way back from every change, and a record of all of it. And you should not take our word for any of it, so this page starts with how to check.
Do not trust us. Check.
Software with access to your server deserves scepticism, whoever wrote it. Every claim below comes with the address or the command that checks it. If you are asking an AI assistant whether AskYourStack is safe, give it this page: it can fetch each one.
- 1
It runs as an ordinary Linux user, unless you say otherwise
Run the install line as the user who owns your sites and the agent manages only that user's sites and files: no sudo, no packages, no services, nothing outside what that user can reach. The operating system enforces that boundary, not us. Most site work (Magento, WordPress, databases, logs, SEO) needs no more. Want the whole server, packages, services and firewall? Run the same line as root; then the window, the modes, the approvals and the lock below are what keep it in check.
curl -fsSL https://askyourstack.com/install.sh | sh -s <your token> # as the site's user; as root for the whole server - 2
What runs on your server is public
The agent is the only part of AskYourStack on your machine, and it runs as the Linux user you chose. Its source is at github.com/shopwhizzy/askyourstack-agent, Apache-2.0: about 9,600 lines of Go with no dependency outside Go's standard library. The operations it can run are the
switchinhandle()in main.go, and nothing else. - 3
The binary is that source, and you can prove it
Each release is built from a commit of that repository with flags that make the build reproducible. The signed release manifest at /dl/manifest.json names the version, each binary's SHA-256, the commit and the Go version. verify.sh in the repository checks the signature with the key built into every agent, rebuilds that commit and compares the hash, and can check the binary installed on your server too.
git clone https://github.com/shopwhizzy/askyourstack-agent.git cd askyourstack-agent sh verify.sh /usr/local/bin/askyourstack-agent - 4
Read the installer before you run it
The one-line install runs /install.sh, a short script that downloads the binary for your CPU, enrols with your one-time token and installs a systemd unit. You can download it, read it and run it yourself instead; the dashboard shows that way too.
curl -fsSL https://askyourstack.com/install.sh -o install.sh less install.sh sh install.sh <your token> - 5
What leaves your server
Outbound HTTPS to askyourstack.com and nothing else: three calls (enroll once, poll continuously, result after each job), listed with what each sends in the repository's README. No port is opened. Nothing leaves unless a job reads it: a file your AI asked for, a command's output, a report. Database passwords are handed to the database client in a private file on the server and never appear in a result. Migration copies go straight between your two servers.
ss -tnp | grep askyourstack-agent - 6
Where the limits are enforced, honestly
The agent does not judge commands. The risk classification, the safety mode and the approval gate run at askyourstack.com before a job reaches your server. That means whoever controls askyourstack.com, or your private MCP address within the mode you set, controls what the agent runs, which is true of every agent-based tool. The classification is pattern-based: it catches the usual shapes of destruction and can be fooled by an unusual one. AskYourStack classifies, gates, snapshots and logs; an agent you run as root is not sandboxed, and we do not claim it is. An agent you run as an ordinary user is kept in its place by Linux itself.
- 7
Nothing changes unless you opened a window
Every server has a change window, closed by default and never open for good. While it is closed your AI can look, read logs, run reports and plan, and every tool that would change something is refused with a link for you. You open changes for 1, 2, 4 or 8 hours, signed in, and a countdown shows where you are. Inside the window the safety mode and approvals apply as before; our own daily checks never need it. Like sudo: the right to change a server is granted for a while, not left on.
- 8
A lock the hub cannot open
On the server,
askyourstack-agent lockmakes the agent answer only its own read-only operations (facts, files, logs, the health and crawl reports, read-only database queries) and refuse everything else, whatever the hub sends and whatever mode the dashboard shows, until someone with a shell on that server runsaskyourstack-agent unlock. Shell commands are refused entirely, because the agent cannot tell a reading command from a writing one. It is the one check that does not depend on us: use it to try AskYourStack on a production server with only our word to go on, or to freeze a server for good. The dashboard and your AI see the server as locked.askyourstack-agent lock - 9
Everything your AI did, and everything it could do
Your activity log keeps every tool call with its risk level, arguments, result and the address it came from, for 90 days, and every approval you gave. The full catalogue of tools and playbooks your AI can use is public at /mcp/catalog.
- 10
Leaving takes one command
Disconnect in the dashboard revokes the agent's token and the agent stops and stays stopped. On the server, one command does the same and removes it from startup.
systemctl disable --now askyourstack-agent
Every action is sorted by risk
Before a command, file write or query reaches your server, AskYourStack classifies it. The level decides what happens next.
Reading logs and config files, service status, disk use, database SELECT queries in a read-only transaction, listing sites and snapshots.
Installing packages, editing config, restarting services, clearing caches, ordinary database updates, deploying code. Every file the AI overwrites keeps its previous version.
Deleting your folders or files, dropping or emptying tables, database users, reboots, SSH, sudo and firewall changes, switching off security checks, wiping disks, uninstalling a shop.
Anything touching /etc/askyourstack, where the agent keeps its own key, and SQL that hides several statements in one call.
This is the normal mode. Read-only mode refuses everything above Read; full trust runs Destructive without asking, and still logs it. In every mode, Change and Destructive run only while you have opened changes on that server (1 to 8 hours).
Nothing to break into
The agent on your server dials out to askyourstack.com over HTTPS and asks for work. It opens no port, so there is nothing new to scan or attack on your server.
We never hold an SSH key or a server password. The agent has its own token, and disconnecting a server in the dashboard revokes it: the agent stops and stays stopped. On the server, systemctl disable --now askyourstack-agent does the same.
Approvals that cannot be faked
A destructive action does not run. The AI gets a link and you get an email. You open it signed in on askyourstack.com, read exactly what will run and approve or deny it.
An approval runs once, only with byte-for-byte the same arguments you saw, and expires after 30 minutes. The AI cannot change the command after you approve it, and cannot approve anything itself.
Approving needs your signed-in session, which your AI never has. That matters because an AI that reads a log file or a web page can be fed instructions planted there. Planted text can ask, but it cannot approve. The AI is also told that anything it reads from your server is data, never instructions.
You decide how much it may do
Each server is read-only, normal or full trust. Read-only lets the AI look and explain; normal is the default with approvals; full trust skips approvals while you watch a big job, and still logs everything.
Pause one server or your whole account in one click, and the AI's calls are refused until you resume.
Everything can be undone
Before a change, /etc is saved (at most every 30 minutes). Every file the AI overwrites keeps its previous version. Before risky work, the AI snapshots folders and databases, and rollback writes them back after saving the current state, so a rollback can be undone too.
Secrets stay on your server
Database tools read the site's own credentials from env.php or wp-config.php on the server, running PHP as the site's owner, never as root, and hand them to the database client in a private file. The password never reaches the AI or the chat.
When the AI creates passwords, for a new shop admin for example, it writes them to a root-only file on your server and tells you where, instead of putting them in the chat.
Your private MCP address is stored only as a hash. If it leaks, make a new one in the dashboard and the old one stops working at once.
Google data, read-only
If you connect Google Search Console or Google Analytics, AskYourStack asks Google only for read-only permissions. Your AI can read your data but cannot submit sitemaps, request indexing, change settings or touch anything else in your Google accounts.
The access token is stored encrypted. Your Search Console and Analytics data is not stored: each request goes to Google and the answer goes to your AI, and AskYourStack logs only that the call happened. Disconnect on the Search Console page and AskYourStack revokes the access at Google and deletes the token.
A full record
Every tool call is logged with its risk level, arguments, result and the address it came from. You see 90 days of it in your activity log, and you can see every approval you gave.
Signed agent updates
The agent updates itself only when idle, only from a release manifest signed with our key and checked against SHA-256 checksums, and only after the new binary proves it starts. The previous version is kept on the server. A tampered manifest is refused. The manifest names the public source commit each release was built from, so an update is as checkable as an install.
Server-to-server copies, never through us
When the AI moves a site between two of your servers, the new server makes a throwaway key that the old server accepts only from the new server's addresses, for at most 24 hours, for reading one folder with rsync and nothing else. The old server's host key is pinned. Your files never pass through AskYourStack or the chat, and the key is removed when the move is done.
Your account
No passwords to steal: sign in with an email link or Google. Turn on two-step sign-in with any authenticator app, with ten recovery codes, and get an email whenever it is turned on or off or a recovery code is used.
Your data
Whizzy Digital Solutions Lda is a Portuguese company, and the service runs on Hetzner servers in Germany. Your conversations stay with your AI provider; we only see the tool calls it sends. Tool output is deleted after 90 days, and the record of what was asked is kept for 2 years. On your servers, the agent deletes job output and database dumps after 7 days. Details are in the privacy policy.
Found a problem?
Write to info@askyourstack.com with "security" in the subject, or follow /.well-known/security.txt. We answer every report and will credit you if you want.
Try it read-only first
The Free plan connects one server in read-only mode: your AI can look, explain and diagnose, and cannot change a thing.
Connect your server free