Registration is coming soon. Acrosite is not open for sign-up yet.Contact us
On this page
Security & Data

How Acrosite handles secrets

GitHub tokens, deployment hook URLs, webhook secrets, and provider credentials stay server-side. You see safe status and masked metadata — never raw secrets, in the UI or in logs.

OverviewFor Owners and DevelopersUpdated June 8, 2026

Connecting Acrosite to GitHub and a deployment trigger involves credentials. Acrosite is designed so those secrets stay server-side — you see safe status and masked metadata, never the raw secrets. This page explains what is protected.

Who this is for

Workspace Owners and Developers who connect integrations and want to know how the credentials are handled.

Secrets stay server-side

Sensitive values are used on the server and are not exposed to your browser:

  • GitHub App keys and installation tokens.
  • Deployment hook URLs.
  • Webhook secrets and provider credentials.
Important
You should never be asked to paste a secret into a document or an unexpected form. Acrosite uses a GitHub App and stores deployment credentials server-side.

What you see instead

In the dashboard, you see safe, useful information rather than raw secrets — for example:

  • Connection status (such as Connected) and verification results.
  • Masked deployment hook metadata, not the full URL.
  • Test-trigger results and safe error summaries.

The deployment hook URL is masked in the interface so it cannot be read or copied.

Logs are sanitized

Publish Logs and Deployment Logs are designed to explain what happened without leaking secrets. They do not show tokens, full hook URLs, raw provider payloads, stack traces, cookies, session data, or environment variables. See Understand Publish Logs.

Note
This describes Acrosite's security design, not a certification claim. Keep your own GitHub and hosting accounts secured, since Acrosite's design does not replace your own account security.

Next steps

Frequently asked questions

No. The deployment hook URL is masked in the interface and stored server-side, so it is not displayed or copyable. You see connection status, test results, and safe summaries instead.
No. Publish Logs and Deployment Logs are sanitized — they avoid tokens, full hook URLs, raw provider payloads, stack traces, cookies, session data, and environment variables.
No. Acrosite connects GitHub through a GitHub App, not a pasted token, and stores deployment credentials server-side. If something asks you to paste a raw secret, stop and check it is really Acrosite.