Security overview
- One machine per customer: a private cloud computer for your agent alone; nothing is shared.
- Open internet: no incoming connections, unless you switch on a public address for your agent; you reach your pod by signing in with your email.
- Access to the machine: by cryptographic key only, password login disabled; every use approved by our founder, for the reasons in section 3.
- Your account: sign-in by a code sent to your email; no password.
- Encryption: in transit, for all traffic.
- Backups: daily, rotating over roughly 7 days; restores tested.
- Deletion: everything, backups included, 7 days after your paid period ends.
- Incident notice: within 48 hours of confirming one.
- Hosted: in Europe.
- Report a problem: [email protected].
1. Who we are
Everpod is operated by DEH Technologies LLC, a Wyoming limited liability company, doing business as Everpod. The Terms of Service and the Privacy Policy are the binding documents; this page describes how your pod and your account are protected. Security questions and reports: [email protected].
2. Your pod is its own computer
A pod is a separate cloud computer dedicated to you, with its own accounts and files. Your agent’s software, memory, files and the credentials you give it all live on that machine, and nothing on it is shared with other customers. Your agent cannot change the protections around its own machine, so a mistake by the agent, or an attack aimed at it, cannot switch them off. A problem on another customer’s pod, whether a bug, a bad instruction or an attack aimed at their agent, stays on their pod. It has no route into yours.
Pods are hosted in Europe. Where everything is kept, and which providers touch what, is set out in the Privacy Policy, sections 4 and 8.
3. Who can reach your pod
From the internet: nobody, unless you decide otherwise. Your pod accepts no incoming connections from the open internet, which is the route attacks on an ordinary server take. The one exception is a public address for your agent, which you switch on in your pod’s settings when a task needs it: through it, other services and automations can send your agent messages, and your agent can put a web app of its own online. Nothing else on the pod is reachable through it, and the control panel never is. Your agent’s control panel is reached only through a private, authenticated path: you sign in with your email address, and our systems connect you to your pod. Knowing the panel’s address gets nobody in. Your agent can still browse and use the internet normally; its connections start from inside the pod, not from outside.
By us: narrowly. The machine your pod runs on needs maintaining, and that is our job: setting it up, approving device pairings, running security checks, applying managed updates, helping when you ask for support, and investigating security or abuse problems. Machine sign-in is by cryptographic key only, password login is disabled, and the key is held by Everpod’s founder, who approves every use personally, for those purposes only. We do not access or read your pod’s content (conversations, memory, files) except with your permission during support, or where required for security, abuse investigation, or by law.
By you: through your agent. You use your agent through its control panel and the chat apps you connect, after signing in with your email. There is nothing on the server for you to log in to or maintain. Your agent can show you, send you, or delete anything on its computer when you ask.
4. Your account
You sign in with a code sent to your email address, so there is no password to be stolen, guessed or reused, and repeated sign-in attempts are limited. Your account is as secure as your email inbox: protect that inbox with two-factor authentication. A sign-in code you did not ask for means someone typed your address into our sign-in page; without the code they get nowhere, and you can ignore it.
Payments are handled by Paddle, which runs the checkout. We never see your card number; we receive only transaction records.
5. Encryption
Traffic between you and your pod, and between your pod and the AI model provider it thinks with, is encrypted.
6. Software and updates
Your pod’s software is kept on versions we have tested. We apply updates for you, after testing them, and an update keeps everything your agent has: its files, memory, installed tools and accounts.
7. Backups
Backups are made daily and rotate over roughly 7 days, and we test restores. A backup contains everything on the pod, your agent’s memory and credentials included, so it is protected and deleted on the same terms as the pod itself. Anything you delete on the pod ages out of backups on the same cycle.
8. Deletion
When you cancel, your pod runs to the end of the paid period and stops. 7 days later we permanently delete the machine, its contents and its backups, and revoke its credentials. Past that point the deletion cannot be undone by anyone, including us. You can ask for a full copy of your pod’s content before then (Privacy Policy, section 10).
9. What we can see, and what we cannot
Your pod’s content: not collected, not read, not indexed, not used to train anything; the only exceptions are the ones in section 3. What we can see is what it takes to run the service: your account data, your pod’s name and status, and whether the machine is running.
Your agent’s thinking goes to an AI model provider, as with any agent. For the model usage included in your plan, we send it only to providers that do not train on it; the Privacy Policy, section 6, has the details. Your own key or subscription runs under your own agreement with that provider.
Our site and app use analytics to understand how they are used. That never touches your pod.
10. How we check our own security
Every pod is security-checked before you get the keys, and a pod that does not pass is not handed over. We test our systems regularly, including penetration testing, and fix what we find.
11. If something goes wrong
No one can promise absolute security, and we don’t. If we confirm a security incident affecting your data in our systems, we will notify you without undue delay and no later than 48 hours after confirming it.
To report a vulnerability or a suspected incident, email [email protected]. We read every report and reply. Please give us a reasonable time to fix a problem before publishing it, and do not test against our systems or other customers’ pods without our written permission (Terms of Service, section 8). For anything else, [email protected].
12. Changes to this page
When what we do changes materially, this page changes with it, with a new date, and previous versions stay available from this page. Questions: [email protected].