Skip to content

Product · Agentless over SSH

Nothing to install on your servers.

Xtic reaches each server over SSH with its own key, checks the server's pinned host key on every connection, and runs only one root-owned helper that accepts a short list of fixed commands.

One connection, three checks
  1. 01Xtic server
  2. 02Pinned host key
  3. 03Backup user (no shell tricks)
  4. 04bmp helper: fixed verbs
  5. 05tar · docker · database tools
  • Host keys are pinned

    The fingerprint is approved once; a changed key blocks every plan on that server until an administrator re-pins it.

    Read the docs
  • One key per server or environment

    Ed25519 keys generated in Xtic; a credential can be restricted to the servers it is meant for.

    Read the docs
  • A reviewed onboarding script

    Creates a backup user, a restricted authorized_keys entry and the helper — printed for your administrator to read and run. Xtic never needs a root password.

    Read the docs
  • A least-privilege helper

    The only thing the backup user may run as root. It validates its input and executes a fixed command line — never caller-supplied options.

    Security model
  • Jump hosts and tunnels

    Reach private networks through bastions and databases bound to localhost, with the real target's key verified.

    Read the docs