Decide who reaches your website, and check what it serves.
Access rules apply to the live website on its platform address and connected domains. Security scans check the files of each live release. Private preview links are never affected by these rules.
Password protection
Protect the whole site or up to 20 path prefixes such as /members. Add up to 20 site users in the Security section; visitors sign in with the browser's password prompt over HTTPS. Passwords are stored as Argon2id hashes and are never shown again or given to assistants. With protection on and no users, every protected request is refused, and the attention feed says so.
IP rules and hotlink protection
Allow or deny up to 100 IPv4 or IPv6 addresses or CIDR ranges each. Hotlink protection refuses requests for the file extensions you choose when another website embeds them; list up to 50 hosts that may embed them anyway.
AI crawlers and llms.txt
Choose whether to allow AI crawlers, block those that collect training data, or block all known AI crawlers. The list of crawler names comes from a pinned copy of the public ai.robots.txt project. You can also have DeployBeacon generate an llms.txt file for the live release when your build does not include one.
Maintenance, error pages and listings
Maintenance mode answers visitors with a 503 page and an optional plain-text message of up to 280 characters, without changing the live release. Map your own HTML files in the release as the 403, 404 and 500 pages. Directory listing shows a file index for folders without an index page; it is off by default. These settings sit in the Advanced section.
Security scans
Every upload, every live release once a day and any on-demand rescan (one per project per minute) is checked for known-vulnerable JavaScript libraries, browser miners, webshells, script that decodes and runs hidden code, hidden frames that load other websites, password forms that post elsewhere and executable files. Results are findings with fixed guidance. Signature and heuristic checks cannot prove a website is safe, and a scan never changes or removes the live website.
Change rules from an agent or the CLI
Assistants read the rules with the MCP tool site_settings_get and the scan with security_scan_get; they never request visitor passwords. People change rules from their current dashboard session. The PUT /api/v1/projects/{id}/site-settings route requires browser session, CSRF and current assurance; a CLI or assistant bearer token cannot save it. Account and access security has its own guide.
Explore the product and guides
Access is invitation-only. No payments are collected during the private beta. Sign in to your invited workspace.