Security

An AI with root access, and you holding the keys

Giving an AI a root shell is powerful and should feel uncomfortable. SudoWhizzy is built around that: nothing to break into, every action sorted by risk, a gate in front of anything destructive that only you can open, a way back from every change, and a record of all of it.

Every action is sorted by risk

Before a command, file write or query reaches your server, SudoWhizzy classifies it. The level decides what happens next.

ReadRuns at once

Reading logs and config files, service status, disk use, database SELECT queries in a read-only transaction, listing sites and snapshots.

ChangeRuns after /etc is saved

Installing packages, editing config, restarting services, clearing caches, ordinary database updates, deploying code. Every file the AI overwrites keeps its previous version.

DestructiveWaits for your approval

Deleting your folders or files, dropping or emptying tables, database users, reboots, SSH, sudo and firewall changes, switching off security checks, wiping disks, uninstalling a shop.

BlockedNever runs

Anything touching /etc/sudowhizzy, where the agent keeps its own key, and SQL that hides several statements in one call.

This is the normal mode. Read-only mode refuses everything above Read; full trust runs Destructive without asking, and still logs it.

Nothing to break into

The agent on your server dials out to sudowhizzy.com over HTTPS and asks for work. It opens no port, so there is nothing new to scan or attack on your server.

We never hold an SSH key or a server password. The agent has its own token, and disconnecting a server in the dashboard revokes it: the agent stops and stays stopped. On the server, systemctl disable --now sudowhizzy-agent does the same.

Approvals that cannot be faked

A destructive action does not run. The AI gets a link and you get an email. You open it signed in on sudowhizzy.com, read exactly what will run and approve or deny it.

An approval runs once, only with byte-for-byte the same arguments you saw, and expires after 30 minutes. The AI cannot change the command after you approve it, and cannot approve anything itself.

Approving needs your signed-in session, which your AI never has. That matters because an AI that reads a log file or a web page can be fed instructions planted there. Planted text can ask, but it cannot approve. The AI is also told that anything it reads from your server is data, never instructions.

You decide how much it may do

Each server is read-only, normal or full trust. Read-only lets the AI look and explain; normal is the default with approvals; full trust skips approvals while you watch a big job, and still logs everything.

Pause one server or your whole account in one click, and the AI's calls are refused until you resume.

Everything can be undone

Before a change, /etc is saved (at most every 30 minutes). Every file the AI overwrites keeps its previous version. Before risky work, the AI snapshots folders and databases, and rollback writes them back after saving the current state, so a rollback can be undone too.

Secrets stay on your server

Database tools read the site's own credentials from env.php or wp-config.php on the server, running PHP as the site's owner, never as root, and hand them to the database client in a private file. The password never reaches the AI or the chat.

When the AI creates passwords, for a new shop admin for example, it writes them to a root-only file on your server and tells you where, instead of putting them in the chat.

Your private MCP address is stored only as a hash. If it leaks, make a new one in the dashboard and the old one stops working at once.

A full record

Every tool call is logged with its risk level, arguments, result and the address it came from. You see 90 days of it in your activity log, and you can see every approval you gave.

Signed agent updates

The agent updates itself only when idle, only from a release manifest signed with our key and checked against SHA-256 checksums, and only after the new binary proves it starts. The previous version is kept on the server. A tampered manifest is refused.

Server-to-server copies, never through us

When the AI moves a site between two of your servers, the new server makes a throwaway key that the old server accepts only from the new server's addresses, for at most 24 hours, for reading one folder with rsync and nothing else. The old server's host key is pinned. Your files never pass through SudoWhizzy or the chat, and the key is removed when the move is done.

Your account

No passwords to steal: sign in with an email link or Google. Turn on two-step sign-in with any authenticator app, with ten recovery codes, and get an email whenever it is turned on or off or a recovery code is used.

Your data

SudoWhizzy Lda is a Portuguese company, and the service runs on Hetzner servers in Germany. Your conversations stay with your AI provider; we only see the tool calls it sends. Tool output is deleted after 90 days, and the record of what was asked is kept for 2 years. On your servers, the agent deletes job output and database dumps after 7 days. Details are in the privacy policy.

Found a problem?

Write to hello@sudowhizzy.com with "security" in the subject. We answer every report and will credit you if you want.

Try it read-only first

The Free plan connects one server in read-only mode: your AI can look, explain and diagnose, and cannot change a thing.

Connect your server free