Security, built into the foundation
Safe defaults.
Still your computer.
TermSquad gives your AI agents an always-on cloud computer with protected access, separate admin permissions, and automatic security updates. You keep control of your tools, credentials, and restarts.
Included with every TermSquad Computer.

- Network access
- Firewall + Fail2ban
- Everyday agent work
- Unprivileged
- AI credentials
- Inside your computer
- Security patches
- Automatic
01 / Network access
Two ways in.
Protection on both.
Open your Web Terminal in the browser or connect directly over SSH. Each has its own protected access path to your cloud computer.
- Firewall by default
- Incoming traffic is denied unless the computer needs that access.
- Failed SSH attempts, blocked
- Fail2ban detects repeated failed logins and automatically blocks abusive IP addresses.
- Your own SSH keys
- Use your public keys for direct access. Password access remains available where supported.
Web Terminal
From your browser
- TermSquad web access
- Private tunnel
- Terminal service
Direct SSH
From your tools
- Firewall
- Fail2ban
- SSH access
02 / Permissions
Everyday work.
Without everyday root.
Your agents work in an unprivileged environment. System changes happen through a separate admin environment, when you need them.
Keep normal agent work separate from system administration.
03 / AI credentials
Your agent logins.
In your computer.
Sign in to your AI agents inside the machine terminal. Their API keys and OAuth credentials are kept in your TermSquad Computer and used by the agents there.
The control plane does not need to store your AI credentials.
04 / Security updates
Patches happen.
Restarts are your call.
Security patches install automatically. If a restart is needed, TermSquad surfaces it so you can choose a moment that works for your agents.
No forced automatic reboots.
Explore what we manage- Handled by TermSquad
Security patches install
Automatic updates to the foundation.
- If a restart is required
You choose when to restart
Plan around work that needs to finish.
Frequently asked questions
Security questions.
Straight answers.
The details behind the defaults, from remote access to your next restart.
Talk to usHow is incoming traffic protected?
The firewall denies incoming traffic by default and allows only the access the cloud computer needs. Fail2ban detects repeated failed SSH attempts and automatically blocks abusive IP addresses.
Is root SSH enabled?
No. Root SSH login is disabled. Everyday work happens in an unprivileged agent environment. Use the separate admin environment with sudo when you need to make system-level changes.
Does TermSquad expose the terminal daemon publicly?
The Web Terminal uses a private managed path to the terminal service. The service is not exposed as a general public port. Direct SSH access is a separate path, protected by the firewall and Fail2ban.
Where are my AI credentials stored?
AI agent logins happen inside your TermSquad Computer. Your model API keys and agent OAuth credentials are kept in that environment and used by the agent there. The TermSquad control plane does not need to store those credentials.
Will security updates restart my cloud computer automatically?
No. Security patches install automatically, but TermSquad does not reboot your cloud computer behind your back. When a restart is required, that state is surfaced so you can choose when to restart.
Can I use my own SSH keys?
Yes. Add your public SSH keys for direct access to your cloud computer. Password access remains available where supported. Root SSH login stays disabled.
A solid foundation for your next idea
The defaults are ready.
Make it your own.
Your agents. Your tools. A cloud computer with security built in.
AI subscriptions and usage are not included.
