Free tool · Runs in your browser · Nothing uploaded

Analyze a systemd unit.

Most .service files run as root with no sandbox and no restart policy — fine until they aren’t. Paste your unit and get a hardening review: root user, missing sandboxing, no auto-restart, each with the exact directive to add.

100% client-side

root, unsandboxed, and unwatched

A service started by a quick ExecStart with nothing else does three risky things at once: it runs as root, it has the run of the filesystem, and it stays dead if it crashes. systemd can fix all three with a handful of directives that cost nothing — a dedicated user, a few sandbox lines, and a restart policy — but they only help if they’re there. This reads your unit and tells you which are missing.

A hardened unit is a good foundation. Operating multiple backend services also means coordinating releases, checking health, applying traffic policy, and handling crashes without a round of SSH sessions.

Keep permissions explicit. Keep services running.

Infraveil supervises managed backend processes, checks their health, and applies configured restart and recovery controls on your servers. Review service permissions during setup: the elevated Linux/systemd installation defaults the launcher service to root. Application and host hardening remain deliberate configuration choices.

See how it works