SECURITY

Publish only what you intend, for only as long as it is needed.

Pubto combines target-level access, encrypted transport, short lifetimes, enforced usage limits, metadata moderation, and immediate revocation. No control makes a public endpoint risk-free.

Select one target

Publish only the port, service, file, folder, or website needed for the handoff. Projects group endpoints but do not silently expose every service on the computer.

Set a short lifetime

Use a clear expiry for temporary demos, database sessions, client files, and meeting links. Stop or delete the endpoint as soon as the work is complete.

Keep source authentication

Use a publication password for browser content, and keep database, SSH, admin, and TCP credentials in the source service. A public address alone is not a secret.

Enforce usage policy

Control measures requests, traffic, visitors, duration, file size, and connections and can reject use beyond the effective plan and time-window limits.

Review public metadata

Names, descriptions, and normalized source hosts pass an operator-managed policy gate. Current automated checks do not inspect every file byte, response body, or encrypted payload.

Respond to abuse

Reports and risk signals can lead to operator review, endpoint revocation, quarantine, or account suspension. Report a suspicious address to [email protected].

Relay networkCurrent + roadmap
Selected locationLos Angelesrelay-1 · Gateway + Relay
Early access
Privacy and safety boundary

Monitor enough to enforce policy without treating every payload as stored content.

Pubto does not log request or response bodies by default. It uses limited metadata and usage totals for operation and safety, and may review a reported public endpoint when reasonably necessary. The Trust and Safety policy documents automated controls, human review, enforcement, and appeals.