Bring your code. Ship it encrypted.
Open a folder you already have on disk and say how it should run — a frontend served as files, a backend run in a sandbox, or a full-stack app that ships both as one encrypted bundle. Built with the tools you already use. Nothing to rewrite, nothing to adapt, no SDK and no LockFlare code in your project.
Three project types
The rule is simple: if your tool produces a folder with an entry document, or a server program, it deploys.
Frontend
A static build — Angular, Vue, Svelte, React, Astro, plain HTML. Pre-compiled into an in-memory site bundle and served by the engine straight from RAM. Server-rendered modes that need a live Node process at request time (Next.js SSR, Nuxt SSR, SvelteKit's node adapter) belong on the Node.js runtime instead.
Backend
Node.js or .NET 10 server code, or a static native binary, run in an isolated per-application sandbox — decrypted and executed entirely from memory, with your endpoints served on your own domains.
Full-stack
Your backend and its compiled UI, shipped as one encrypted bundle. The UI is grafted into the backend at the path you choose and served by your own server code — entirely from RAM.
Your stack already works here
Every frontend that builds to a folder. Cipher serves the build you give it — it does not compile, transpile or bundle, so you run the build you always run and deploy the output.
Frontends
Vue, React, Angular, Svelte (adapter-static), Next.js (static export), Nuxt (static generate), Astro, SolidJS, Preact, Qwik (static adapter), Remix (SPA mode), Gatsby, Lit, Ember, Docusaurus, Hugo, Jekyll, Eleventy, static HTML — and any other tool that writes a folder with an entry document.
.NET 10
Razor Pages, MVC, Blazor Server, forms, minimal APIs, SignalR, and every NuGet package you depend on — a standard framework-dependent publish, pushed as it is.
The .NET runtimeNode.js and native
Express, Koa or Fastify on Node.js with the fleet's host-installed package set. Go, Rust, Zig, C and C++ as a static Linux x86-64 ELF — any toolchain that emits one.
The Node.js runtimeWhat a project carries
Encrypted push
Your folder is zipped in memory and uploaded as AES-256-GCM ciphertext. Nothing on your machine is modified, and nothing readable leaves it.
Environment secrets
A .env inside the pushed folder travels with the build; variables set in Cipher are per environment, so a staging database URL never follows a build into production. Both are held encrypted and injected into the process at start. No .env on the host; the engine's own environment, including the server license, is never passed through to your application.
Serving domains
Per environment, with as many hostnames on one project as you need — an apex plus www, a vanity domain, a per-customer hostname. On Node each domain runs in its own vm sandbox, so one tenant's code cannot reach another's on the same server.
In-memory static serving
express.static and sendFile stream your files straight out of RAM; on .NET your wwwroot is staged into a RAM-backed filesystem private to the app. The assets never exist on disk.
Worker models
Standard — one real worker per licensed core, the right answer for ordinary apps and for code that calls cluster.fork() to spread load. Self-coordinating cluster — your master and its workers emulated in one process, for a master that aggregates over IPC. Single instance — one copy, one core, for an app that must never run twice. An unguarded cron under Standard runs on every worker; Cipher says so before the first push.
Self-healing boots
A failed start retries automatically with backoff. A transient database blip or a just-installed package recovers on its own — no redeploy.
Packages on Node: host-installed, shared, never on your server's disk
Your require() calls resolve against the fleet's package set, installed once on the host and bridged through a controlled proxy. There is no per-project node_modules to upload, to poison, or to audit on every box. Your package.json is read at boot and anything missing is reported per package, by name.
- Databases — mongodb, mongoose, mysql2, pg, mssql, knex, better-sqlite3, ioredis
- Auth and crypto — bcrypt, argon2, jsonwebtoken, passport, speakeasy, nanoid, uuid
- Payments and comms — stripe, paypal, square, nodemailer, sendgrid, twilio, slack, web-push
- Files and data — pdfkit, exceljs, archiver, sharp, canvas, qrcode, cheerio, joi, zod, lodash, csv-parse, js-yaml
- Cloud and AI — AWS s3, ses, dynamodb, lambda, sns, sqs, secrets-manager; Google Cloud Storage, Firebase, Azure Blob; the Anthropic and OpenAI SDKs
From folder to serving, in three steps
Open the project
Point Cipher at the folder on your disk — a frontend build, a backend, or a full-stack app. Name it, pick the type and the runtime, set the starting file and the worker model.
Push to an environment
Development, UAT, Live, or a grouping per client. The folder is packed in memory, encrypted on your machine, and uploaded as ciphertext; every server in the environment pulls it.
Reload when you choose
Push and reload are separate. The fleet keeps serving the previous build until you reload, so you can push at any hour and go live when it suits — and roll back by promoting the previous build, a pointer change that takes as long as a reload.
Your project, as it is, on servers you do not have to trust
Write to us with what you deploy — the framework, the runtime, where it runs today — and we will tell you plainly whether it fits, and what the runtime cannot do.