Security
No keys in the chat. No claims we can't back.
What Tofu holds and never holds, what your agent can do once you approve it, and exactly what the safety check reads before a deploy — with the limits written beside the claims.
- MAIL_API_KEYsecret••••Qm7xProdPreview
- SMS_API_KEYsecret••••c9d2Prod
- NEXT_PUBLIC_SITE_URLhttps://frankskitchen.comProdPreviewDev
- DATABASE_URLmanaged••••••ProdPreview
Secrets are write-only — once saved, the value is hidden and never shown again.
- key
- "SMS_API_KEY"
- secret
- true
- value
- null
- preview
- "••••c9d2"
The value went to the hosting provider, write-only.
Some things never reach Tofu. So they cannot leak from it.
The most sensitive values stay with the service that owns them: your hosting provider, Google or GitHub, your DNS provider, Stripe.
Secret values
The value of a secret you save.
It goes straight to the hosting provider as a write-only value. Tofu keeps the name, the scopes and a masked preview; neither the dashboard nor Tofu can read the value back.
Passwords
A password for your account.
You sign in with Google or GitHub. Tofu never sets or stores a password for you, so there is none to lose.
Provider keys
A key or token pasted by you.
Nothing in Tofu asks you to paste one to connect a provider. Connecting DNS is an approval you give on the provider's own screen, and the credential that results is Tofu's to hold and to revoke.
Card numbers
Your card details.
You enter them on Stripe's own checkout page, and they never reach Tofu. Tofu keeps your plan and its subscription status.
One exception, and it is yours. For a managed database, the owner-only Show the connection string action rebuilds that string on request. Each call writes an audit line, no agent can reach it, and rotating the password is not built.
Your agent acts for you. Only after you approve it.
A coding agent connects the way a TV app signs in: it shows a code, and you approve that code in your own browser, signed in to Tofu.
The client your agent installs is pinned: the setup prompt carries its SHA-256 and size, and a mismatch stops the install before anything runs.
tofu · login
Approve this sign-in in your browser. The code is
7F3A-C09B-21DE
Approve only a code your own agent printed.
Connect Claude Code (MCP)?
Check that this code matches the one in your coding agent:
7F3A-C09B-21DE
Your agent asks
The Tofu client in your agent starts a sign-in request and shows you a code shaped XXXX-XXXX-XXXX. The request lapses after ten minutes.You compare, then approve
Open the approval page on the Tofu address you signed in to, and approve only if the code matches the one your own agent printed.It lasts seven days
The client keeps the credential privately, bound to one Tofu address, and Tofu stores only its hash. Revoke it any time in Agent connections — deleting local files alone does not.
What an approved connection can do
This connection can upload your app’s source, run the safety check, deploy it — its own migration runs in the build — once you have a hosting plan, create the app’s managed database in that same call, which Tofu runs and pays for as part of your plan, read the app’s build and runtime diagnostics, restore a previous deployment, connect, verify, release or withdraw the authorization for a domain you already own, read your app’s own traffic — the first read for an app that has no counter yet issues its key — and turn that counter on or off, change how your app’s users sign in and how its sign-in email is sent, restore an archived database into a new one Tofu runs and pays for as part of your plan, and hand you a short-lived link to download its archive, keep a database Tofu warned you about from being archived for going unused, delete an app — the source you uploaded is kept until you ask Tofu to erase it — or its database, with nothing kept, sign in to Tofu, report the plan and the account’s GitHub state, and turn automatic updates off.
It cannot buy or transfer a domain, submit a payment, read an environment value or a database password or connection string, change your plan or billing, or import a repository from GitHub. Those stay with you.
Your agent acts on your instructions and asks for your agreement before any call that spends money, writes to a live service or destroys something — and it makes that call on your instructions, never on its own initiative.
It says what it read. And what it did not.
Before a build, Tofu checks the exact files it is about to deploy. The promise is narrow on purpose: Tofu states exactly what it looked at, and never more.
Your agent calls
detectsetFrameworkscan
A tripwire before every deploy
A committed live key, a sign-in form that posts to another site or a seed-phrase collector stops the deploy, and so does a file that cannot be read. It runs on the exact files about to be uploaded.
Rules, not a model
Deterministic rules read the upload: an exposed service key, a table with Row Level Security off, a policy that lets anyone write, an unverified Stripe webhook — and known malware shapes, such as code that decodes and runs itself or an install script that downloads and runs. Critical and high findings block; medium and low are reported.
Every result shows its coverage
How many files were read out of how many were given, which checks ran, and the list of risks no check looks for. That list is never empty.
A finding you can act on
Each finding names its rule and its file, says what it means, and carries a fix prompt you can hand straight to your coding agent.
- When nothing blocks, a result says
- No blocking finding among the checks that ran.
- When no file was read, it says
- Nothing was inspected, so this is not a pass.
Live only when it answers. The last good one stays up.
Health check
Checked before the address moves.
A finished build is requested at its own deployment address first. Your app's address moves to it only if it answers.
Failed builds
A failed build changes nothing live.
The previous version keeps serving. A database migration that fails inside the build fails it the same way.
Rollback
One step back, without a rebuild.
Rollback points your address at an earlier deployment that is ready and answering. Your data does not move back with it.
Where your data lives. Named, not implied.
A summary of the Privacy Policy, which is the full list — including how long each thing is kept and how to ask us to erase it. Read the Privacy Policy.
Visitors to your app. Counted, not tracked.
If you turn on Tofu's traffic counter for an app, it counts page views on Tofu's own endpoint, and the traffic is yours: shown in your dashboard, switched off from there, and used by Tofu for nothing of its own.
- No cookie is set in your visitor's browser.
- No third-party analytics script is added to your app.
- No IP address is stored.
- No full URL: the query string and fragment are dropped, the referrer cut to its hostname.
- Do Not Track and Global Privacy Control stop a view from being counted.
- Kept 90 days by default, never more than 365, and deleted with the app.
Found a hole? Tell us first.
Write to us with what you found and the steps to reproduce it. Please test only against your own account and apps, and give us a chance to fix it before you publish.
The same address is published in /.well-known/security.txt, where a researcher's tools look for it first.
Contact: mailto:hello@trytofu.ai Expires: 2027-09-27T00:00:00.000Z Preferred-Languages: en Canonical: https://trytofu.ai/.well-known/security.txt Policy: https://trytofu.ai/security#report
Limits
What this does not cover
Not a malware guarantee. The safety check matches the shapes it knows, not intent. It does not look at what an app does once it runs, the contents of its database, or dependencies beyond the direct entries in
package.json.No deeper, itemized security report. It is not built. The dashboard says so rather than showing example findings.
A connection is not per-project or read-only. An approved agent covers every project and operation your account allows. Revoke it in Agent connections when you are done.
A checksum is not a signature. The pinned SHA-256 catches a mismatched or corrupt download. HTTPS from Tofu's own address is the trust boundary, so it cannot catch a compromised distribution server.
Log masking is best-effort. Tofu filters credential-shaped text out of the logs it shows, but it cannot read a write-only secret back to find every copy. An app must not print its own secrets.
Deleting an app keeps its uploaded source. The archive stays in private storage until you ask us to erase it.
No self-serve account deletion. Write to hello@trytofu.ai. Requests are handled by hand, and we tell you what was removed and what could not be.
No certification. Tofu is not SOC 2 or ISO 27001 certified, publishes no audit report, and does not claim GDPR compliance for the service.
Paste one line. Go live.
Your app, its database, your domain and your sign-in — from the agent you already use, in about 10 minutes.
The ship-it layer for vibe-coded apps. Your agent wrote it — Tofu ships it.
Works in all coding agents
© 2026 Tofu
trytofu.ai