Most apps promise they won't look at your data. DockPilot is architected so we can't — your keys, your commands, and your AI conversations never pass through our infrastructure in the first place.
Every connection is made directly from your device. DockPilot ships the client — it is never a hop in the path.
VPS, bare metal, Pi, or cloud instance — anything reachable over SSH.
DockPilot + Apple Keychain. Keys, history, and projects live here.
Anthropic, OpenAI, or Google — billed to your own API key.
SSH private keys, passwords, passphrases, and AI provider API keys are stored in your device's secure Keychain. They're never uploaded to us, never sent to any model, and only leave the device to authenticate directly with your own server or provider.
SSH sessions run straight from your device to your server; AI requests go straight to the provider whose key you supplied. DockPilot never proxies, mirrors, or logs those connections — there is nothing on our side to breach.
Projects, command history, and monitoring data sync privately through your own iCloud account across iPhone, iPad, Mac, and Watch. We can't read them — and there's no DockPilot account or cloud login to create.
Only the command output you're actively working with — the exact text a command returns — is sent to the model you chose, so it can reason about the task. DockPilot never bulk-uploads your filesystem, databases, or logs.
Fresh projects start read-only. Anything that would modify your server is blocked until you explicitly enable writes — and in Plan and Ask modes, you see the exact command and approve it with a tap before it ever touches the box.
Everything the agent runs — proposed, approved, or automatic — lands in a full, searchable history on your device. You can audit exactly what happened on your server, and edit or reject anything before it runs.
The AI can only do what you allow. Start cautious, loosen the leash as you build confidence — and change it any time, per project. Try it:
Approve each command. You see the exact command, can edit or reject it, then approve with a tap.
A No — and not because of a policy, because of the architecture. Credentials sit in your Keychain and connections run device-to-server. There's no DockPilot backend that ever holds them.
A Your instruction plus the output of the commands run in that session — sent directly to the provider you picked, on your API key, under their data terms. Never your credentials, never unrelated files.
A No. There's no sign-up, no login, and no user database of yours to leak. Purchases go through the App Store; sync goes through your own iCloud.
A Writes are blocked until you enable them, and in Plan/Ask modes every command is shown to you first — editable, rejectable, and logged. Nothing runs behind your back.
A Ed25519, ECDSA, and RSA keys (with or without passphrase) plus password auth. Generate keys in-app or import your existing ones — they never leave the Keychain unencrypted.
A The privacy policy and terms of service spell everything out — or ask us directly.
Download DockPilot and manage your servers with an AI copilot that never sees more than you allow.