Security and Shared Responsibility

Applies to: all AppWizzy hosted VM projects

AppWizzy secures and operates the hosting infrastructure. You control and maintain the operating system, software, accounts, credentials, and content in your VM.

Responsibility summary

Area AppWizzy Customer
Physical and virtualization infrastructure Operates and patches it
VM creation and lifecycle controls Provides the controls Uses controls safely and reviews destructive actions
VM operating system and installed packages Does not automatically patch them Updates and maintains them
Application code and configuration Provides a template start point when applicable Reviews, changes, tests, and secures them
Application users and permissions Provides a template capability when applicable Configures and administers them
SSH, passwords, sessions, and provider keys Provides supported access and encrypted BYOK storage Protects, rotates, and revokes credentials
Daily VM backup and restoration Provides them Requests restoration and keeps independent exports of critical data
Managed AI provider route Operates the proxy and measures use Selects a model and limits unnecessary sensitive data
Personal ChatGPT login and BYOK provider account Manages the provider account, limits, billing, and access

AppWizzy infrastructure responsibilities

AppWizzy operates and patches the infrastructure that hosts your VM. AppWizzy also provides VM creation and an active disk.

AppWizzy creates at least one backup of each hosted VM system each day. AppWizzy can restore the system from a backup.

AppWizzy provides supported project access and the billing system.

Your VM responsibilities

AppWizzy does not automatically update the operating system or software in your VM. You have these responsibilities:

  • Install security updates for the VM operating system and packages.
  • Update application frameworks, plugins, and dependencies.
  • Configure application authentication and permissions.
  • Remove unused accounts and credentials.
  • Protect secrets and provider keys.
  • Review software that you or an automated agent installs.
  • Monitor application behavior and the data that you expose.
  • Export the data that you must keep independently.

Preinstalled software reduces setup time. AppWizzy does not administer software that you control.

Workspace access can expose sensitive state

A development VM can contain source code, databases, uploaded files, and terminal history. It can also contain browser profiles, active sessions, API keys, and authentication artifacts.

A person with full SSH, Remote Desktop, or project access can reach this sensitive state.

Give access only to people that you trust. Rotate credentials after you remove a collaborator or suspect unauthorized access.

AI data routing

With managed AI, AppWizzy receives your request. AppWizzy sends the request to the provider for the selected model.

AppWizzy measures the use and returns the output. OpenAI receives requests for GPT-family models.

The provider for another hosted model receives requests for that model. Local inference stays in the AppWizzy/Flatlogic infrastructure when AppWizzy provides it.

With a personal ChatGPT login or BYOK, your provider relationship and provider account controls also apply.

AppWizzy staff access prompts or VM content only after you request assistance.

Backups and recovery

AppWizzy creates at least one backup of each hosted VM system each day. AppWizzy can restore the system from a backup.

A restoration returns data from a backup point. The restoration can omit newer changes.

Keep independent exports of critical business data and source code. See Data Persistence and Backups.

Report a security issue

Use this procedure if you believe that someone compromised a VM, credential, account, or AppWizzy service:

  1. Revoke or rotate affected provider keys and passwords.
  2. Pause the affected VM if its operation creates more risk.
  3. Preserve relevant timestamps and non-sensitive error details.
  4. Contact AppWizzy support and identify the affected project.
  5. Do not publish secrets or complete access tokens in the support request.