Apricaut

Websites, built and run.

How it's built

Built so there's less to break into.

Not a list of badges. This is how the software is written, how the machines are built and run, and how your site is kept apart from everybody else's.

In detail

What actually stops someone getting in.

The parts that matter, including the one we don't have.

It's written in a language that rules out a whole class of break-in.

Your site runs on Rust, which makes an entire family of memory-handling mistakes impossible to write rather than merely discouraged. Those mistakes are the raw material behind a large share of serious security holes across the software industry. They can't happen here, because the language won't compile them.

The software runs with no administrator rights at all.

If someone found a way into the software running your site, they'd arrive somewhere with nothing worth taking. It runs as an ordinary user, with no administrator powers, no way to grant itself any, and every special permission stripped out.

This isn't a setting we chose and hoped would hold. The cluster refuses to start anything that doesn't meet it — the strictest standard Kubernetes publishes, enforced rather than recommended. We know because it has turned us down: we asked it to run a helper of our own that fell short, and it said no.

There are no plugins to go out of date.

This is how most small-business websites actually get broken into. Something was bolted on two years ago, whoever made it stopped maintaining it, a hole opened, and nobody noticed until it was being used.

There's nothing bolted on here. Your site runs the same software every site here runs, and keeping it current is our job. No plugin directory, nothing to install, nothing for you to remember.

The parts underneath are watched by a robot.

Your site is built on shared building blocks, the way all software is. When somebody finds a flaw in one of them, a fix gets published — and the gap between that fix existing and being applied is where a great many break-ins happen.

We have a robot watching for exactly that. It raises the update the day the fix appears, so the question is never whether anybody remembered to look.

Every machine is built from a locked recipe.

Servers usually rot: somebody patches one by hand at two in the morning, and a year later nobody can say how it differs from the others.

Ours are built from a written, locked recipe, the same one every time. No hand-patched machine, no one-off server, nothing drifting quietly out of date.

A machine that goes wrong gets replaced, not nursed.

When one stops being healthy it's taken out and a fresh one is built from the same recipe — rather than somebody logging in to poke at it and leaving it slightly different from all the others afterwards.

Nothing changes by hand.

Every change is written down as code first, recorded, then applied automatically. Nobody edits a live server, and there's no console where somebody clicks something into production at midnight. Before any of it reaches a server it's built and put through its checks, and code that doesn't pass doesn't ship. If anything drifts from what's written down, it gets put back.

Your database has a password no person ever chose.

Your orders, your enquiries and your words live in a database built for your business and nothing else — not a shared table with a column recording which customer you are.

Its password is generated by the system the moment the database is created. No person chooses it, no person types it, and it never appears in our code or in anything you'd have to look after. The administrator account isn't switched on at all, so there's one key to that door and it belongs to your site.

Each database also carries its own certificate authority — the electronic equivalent of a lock cut for that one door, and no other.

There's no password of yours to steal.

You sign in with Google or GitHub. We never create a password for you, never store one, never email you one. There's no password of yours anywhere in our systems to leak, guess, or be reused elsewhere — because there isn't one at all.

You can add someone from your team, and take them off the day they leave.

Traffic is encrypted, and the doors are shut.

Everything travelling between your visitors and your site is encrypted, on a certificate that renews itself before anyone has to remember it. The machines sit behind a firewall that refuses traffic nobody asked for.

And every site is sealed off from every other.

Each business gets its own walled-off space — its own machines, its own database, its own login system. It isn't a folder inside a bigger system with your name on it.

Nothing here is trusted simply for being on the inside. Every connection has to be allowed on purpose, and anything not allowed is refused. The approach is called zero-trust networking, and what it means for you is that trouble somewhere else on the platform has no route to your site.

These aren't rules written on paper. The network itself enforces them.

The other two questions.

People usually ask about two more things. There's what happens to your money, which never passes through us on its way to your bank, and what the AI can and can't see, which is a shorter list than most people expect.

What we don't have.

We're not going to list certifications we don't hold. We don't have SOC 2, we don't have ISO 27001, we haven't done a PCI audit, and we're not putting badges on a page to imply otherwise.

What we have is everything above, and a willingness to tell you exactly what it is. When we earn a certification we'll say so, and you'll be able to check it.

Ready when you are.

Describe your business, and it's open in about ten minutes. $200 a month, seven days free, no card.

Start taking customers