1. Reporting a vulnerability
Please do not open a public issue. Email [email protected] with steps to reproduce, impact and the affected component, or use GitHub’s private vulnerability reporting. We acknowledge reports within 72 hours, work with you on a fix and coordinate disclosure. Credit is given unless you prefer otherwise. Machine-readable contact details are in /.well-known/security.txt.
In scope: the platform, dashboard, API, CLI and installer. Escaping container isolation and anything that exposes stored secrets are especially valuable. Applications our users deploy are out of scope.
2. Where we are today
Pushify is in beta and run by a very small team. We do not hold SOC 2 or ISO 27001 certification. Security fixes land on the latest release; self-hosters should keep up with it, because earlier betas are not patched retroactively.
3. Accounts
- Passwords are hashed with Argon2id.
- Two-factor authentication with an authenticator app, plus backup codes.
- Organizations can sign in through any OIDC identity provider (Okta, Entra ID, Google Workspace, Auth0, Keycloak) and require it for their email domains.
4. Secrets
Environment variables, SSH private keys, database passwords and access tokens are encrypted at rest with AES-256-GCM. Off-site database backups can additionally be encrypted with rclone’s crypt before they leave the control plane.
5. What Pushify does on your server
When you connect your own server over SSH, Pushify:
- connects as
rootand appends its own public key to~/.ssh/authorized_keys(the key’s comment starts withpushify-); - installs Docker, nginx and certbot if they are missing, and creates
/opt/pushify; - adds one nginx site per app (
pushify-<app>) and, for an app deployed without a domain, opens its port in the firewall it finds (ufw, firewalld or iptables). Existing firewall rules and yournginx.confare left as they are.
On a server Pushify creates for you, setup also resets ufw (deny incoming, allow 22, 80 and 443) and replaces /etc/nginx/nginx.conf and the default site. Setup now keeps the original nginx.conf as nginx.conf.pushify-backup; servers created before this change have no copy.
Connect a server you dedicate to Pushify rather than one already running other services. Metrics are read over the same SSH connection; no agent or telemetry is installed.
Removing a server
Deleting a connected server in Pushify removes our key from /root/.ssh/authorized_keys. Your own keys are not touched. If the server cannot be reached at that moment, the deletion still completes and the dashboard shows the command to run yourself:
sed -i '/ pushify-<id>$/d' /root/.ssh/authorized_keysTo remove everything else Pushify added (containers, nginx sites, firewall openings, /opt/pushify), run the uninstall script. Try it with --dry-run first. It keeps Docker volumes (your database data), Docker, nginx, certbot and your certificates.
curl -fsSL https://raw.githubusercontent.com/pushifydev/pushify_backend/master/scripts/server-uninstall.sh | sudo bash -s -- --dry-run6. Isolation on shared runners
On servers that host more than one customer, apps run on a dedicated Docker network with inter-container traffic off. Firewall rules drop traffic from one app to another, to private and link-local ranges and to the host, except the host’s own ports 80 and 443. Apps with a domain are only reachable through nginx.
7. AI assistant
The dashboard assistant is powered by Anthropic. It receives the messages you type and the name of the dashboard page you are on. It does not automatically receive your environment variables, logs or source code. Only paste what you are comfortable sharing.