Your running application
Your running application, process environment, and persistent files remain on infrastructure you control. Local components start and supervise configured services and operate supported gateway routes.
Run releases, supervise processes, govern managed traffic, and use supported recovery controls.
Choose the operating workflow your team needs—from releases and service failures to scoped production access.
Practical tools and guides for teams running applications.
Learn about Infraveil, how the product works, and its security and data-handling practices.
Trust and transparency
Infraveil coordinates operations through a hosted control plane while local launcher and agent components perform configured work on your servers. The boundary below explains runtime authority, release approval, and the information shared with the hosted service.
Your running application, process environment, and persistent files remain on infrastructure you control. Local components start and supervise configured services and operate supported gateway routes.
The hosted control plane coordinates releases and settings and receives selected operational data, including service health, logs, changes, and incidents. Managed-package uploads may include application source; running on your servers does not mean all information stays local.
Authority
These are release-signing policies, not blanket permission for every operational action. Assistant and remediation features use separate permissions and review settings; choosing automatic release approval does not grant every assistant capability.
Review a pending release before your customer-held key signs its exact hash. This preserves a per-release review step on the deployment path using that gate.
Preapprove specific release hashes. Matching pending hashes can be signed without another prompt; only hashes you added are preapproved.
Sign every pending release hash while this mode is enabled. It removes the per-release human review step; use it only when that is the policy you intend.
Review release changes and managed actions alongside the affected service’s health, logs, and incidents. The history helps explain what was requested and reported; it does not substitute for checking the service or independently reviewing security.
Runtime components installed on your servers are source-visible there. This website provides browser tools and product documentation. The hosted management dashboard is private.
The architecture paper explains components, trust boundaries, data flow, approval modes, failure behavior, and current limits without exposing private backend source or secrets.