The short answer
Antideploy is a real platform that runs real apps, and it is run by a small team. It is young, and it says so. Your secrets are encrypted and write-only, your agent's access is limited and revocable, and what it will not host is written down. It does not promise things it cannot keep, such as always-on apps or instant rollback.
You do not have to take this on trust. You can check most of it yourself.
Who runs it
Antideploy is a young platform run by a small team. You can write to support@antideploy.com and a person answers. The terms, privacy policy and acceptable use rules are public, and so are the platform's limits, which are collected in what Antideploy cannot run.
The connector that agents use, antideploy-mcp, is open source under the MIT licence, on GitHub.
Where your code and data live
-
Your app runs in one region, Singapore, as one instance with 1 shared vCPU and 1 GB of memory (a Java app gets 1 dedicated vCPU and 2 GB).
-
Your database is Postgres, in Singapore, beside the app. It belongs to your application, and deleting the application deletes it.
-
Your files go in a private bucket in Singapore. Every object is private, and the key reaches that one bucket only.
-
Your app's email keeps no subject, body or address. What is kept is how many addresses a message went to, whether it was accepted, and what the delivery report said.
How secrets are handled
-
Encrypted and write-only. Values are encrypted when saved. The console shows which variables are set, never what is in them, and your agent cannot read a value back.
-
Your
.envfile. It is read when you deploy so you do not retype keys. The values go into the encrypted store and the file itself is dropped from the build. -
Your agent's token. It is saved on your machine in a file only you can read, and it is never printed in the chat. You can revoke it at any time.
What your agent cannot do
It cannot delete an app, drop a database, read a secret back, attach a domain or add money to your AI wallet. Those stay in the console, in your browser. See what your agent can do with your account for the full list.
What is checked and refused
Every deploy that goes live gets an automatic security check of the running app. It looks for mistakes that leak data, such as keys shipped to the browser, a downloadable .env file or a wide-open CORS policy. It is free and never holds a deploy up.
Antideploy refuses a short list of things: cryptocurrency mining, remote desktops, remote shells and tunnels, open proxies and VPNs, and malware, phishing and spam. Static sites are checked for phishing pages before they go live. The rules are in the acceptable use page.
What it does not promise
- It does not promise that apps are always on. Apps sleep when idle, and the first request after sleeping takes seconds
- It does not promise zero downtime. A new version replaces the old one on the app's single machine
- It does not promise instant rollback. Going back is a rebuild
- It does not promise global speed. Apps run in one region
- It does not offer team accounts today
How payment works
The Free plan needs no card. Paid plans are charged in rupees through Razorpay, by UPI Autopay or card. You can cancel from Settings, then Billing, and nothing is deleted when you do. AI model usage is paid from a prepaid wallet, so there is no card on file for it and no surprise bill.