Access Boundaries & Baseline

Define the boundaries first, then bring Cloud Mac into your development workflow

Every OakVPS rental maps to one dedicated physical Cloud Mac. It runs on a clearly identified physical node and is accessed through the remote entry provided with the order, without sharing a virtual-machine resource boundary with other renters. The platform manages the service entry point and infrastructure; your team manages accounts, keys, developer credentials, project data, and member permissions.

Responsibility record

One order, one physical device, one set of controlled entry points

Not a virtual machine
01

Service-side boundary

We provide the dedicated physical machine, physical node, order status, and clearly defined remote access entry point.

02

Team-side boundary

Manage login credentials, SSH keys, member permissions, development certificates, tokens, and project data.

03

Handoff boundary

Export deliverables and logs during the rental term, complete backups, and remove sensitive material according to your team’s policy.

Security model overview

Dedicated resources do not remove the need for access management

Physical resource isolation defines device ownership; your team must still manage accounts, keys, network sources, and project data continuously.

Physical resources

Clear device ownership

Each rental maps to a dedicated physical machine. The ordered model, node, and term define the current scope; the physical node is not presented as a shared virtual-machine instance.

  • Hardware configuration follows the selected order tier
  • The node is determined by the console response
  • Remote access details are read only from the order
Access control

Clear entry points still need tightening

Verify the host fingerprint, use key-based authentication, restrict credential distribution, and ensure each member receives only the minimum access needed to complete their work.

  • Assign individual credentials to members
  • Avoid sharing one private key long-term
  • Revoke access immediately when a member leaves
Data responsibility

The rental term is your handoff deadline

Users manage code, models, certificates, logs, and build artifacts. Complete backups, exports, access revocation, and sensitive-data cleanup during the rental term.

  • Do not keep artifacts only on the remote device
  • Check that backups are readable after completion
  • Record the location and owner in the handoff log
Cloud Mac security responsibility boundaries
Security object Provided by OakVPS Managed by your team Recommended checks
Physical device Dedicated physical machine and physical node assigned to the order Choose the right configuration and rental term for the workload Model, node, term, and add-ons
Remote access Connection parameters provided in the order details Protect credentials, verify the fingerprint, and restrict sources Username, port, and host fingerprint
Development environment Available macOS graphical and command-line environments Manage dependencies, certificates, tokens, and repository permissions Version, permissions, logs, and available disk space
Project data Device workspace available during the rental term Back up, export, delete, and hand off Artifact verification, backup readability, and cleanup records
Accounts & access

Make every connection traceable to a specific member

Shared accounts obscure ownership of actions and increase risk when team membership changes. Start your access policy with individual identities, least privilege, and timely revocation.

Account baseline

01 Unique strong password

Do not reuse the console password for code hosting, email, or other development services. Store it in a controlled password manager.

02 Key-based authentication

For remote command-line access, prefer locally generated SSH keys. Keep private keys only on controlled devices and never send them through chat.

03 Minimal sharing

When collaboration requires multiple users, create distinguishable access methods for each member instead of distributing one long-lived credential set to the whole team.

04 Timely revocation

When a member leaves, changes roles, or loses a device, immediately remove the associated public keys, tokens, and repository permissions.

Developer credential protection

Bring credentials onto the device only when the task requires them

Signing certificates, private keys, access tokens, and repository credentials should each have a defined purpose, owner, import time, and cleanup action.

01

Before import

Confirm that the credential is required for the current task. Prefer material with narrower permissions and a shorter validity scope, and record its owner.

Check
Purpose and permission scope
Avoid
Copying unrelated certificates and tokens
02

In use

Restrict file permissions. Do not write credentials into repositories, build logs, command history, or publicly downloadable artifact directories.

Check
File permissions and log output
Avoid
Writing secrets in plaintext to project configuration
03

After the task

Remove temporary material according to team policy, revoke tokens that are no longer needed, and check repository status, cache directories, and artifact packages.

Check
Cache, history, and export directories
Complete
Revocation and cleanup record
Do not include sensitive material in issue screenshots.

Before submitting troubleshooting details, redact private keys, certificate passwords, access tokens, complete payment credentials, and connection parameters that could be reused directly.

Network & remote sessions

Verify before connecting, close out when you leave

A remote entry point is not a channel to configure once and ignore forever. Recheck connection conditions whenever you change your local device, network environment, or team members.

01

Verify the host fingerprint

Save the host fingerprint on the first connection. If it changes, stop and verify the order details instead of bypassing the warning.

02

Restrict connection sources

Whenever possible, connect from team-managed devices and trusted networks. Avoid saving keys or session information on public devices.

03

Control transferred content

Before transferring sensitive material, confirm the target path, file permissions, and recipient. Do not mix credentials into ordinary project archives.

04

End the remote session

Before leaving the device, sign out of graphical sessions and command-line connections, close unneeded forwarding, and remove local temporary copies.

First SSH verification sequence SAFE CONNECT
1. Read the host and port from the order
2. Compare and save the host fingerprint
3. Check local private key file permissions
4. Connect with the specified username
5. Verify system and disk information
6. Record the owner of this connection

When a connection fails, check the username, port, fingerprint, key permissions, and local network in that order. See the connection guide for complete commands and troubleshooting paths.

View SSH troubleshooting steps
Data lifecycle

Put backup, export, and deletion into the rental plan

The remote device should not be the only copy of your code, models, logs, or build artifacts. Assign actions for task start, execution, handoff, and completion.

01

At task start: define the data inventory

List the code, dependencies, certificates, models, and test data that will enter the device. Confirm what must be encrypted and what must not be uploaded.

Input
02

During execution: separate workspace from artifacts

Store source files, caches, logs, and final artifacts separately so temporary credentials or unrelated debugging information are not exported along with them.

Process
03

Before delivery: verify backup usability

Download the required artifacts, verify file integrity, and confirm elsewhere that the backup can be read. A successful upload alone does not complete the handoff.

Export
04

At task end: remove sensitive data

Delete credentials, private repository copies, model files, and temporary logs according to team policy. Revoke related tokens and record the cleanup result.

Closeout
Payment boundaries

Marketing pages do not collect payment details

Price confirmation, gateway selection, and order payment take place during checkout. All charges are settled in USD, with only the following two payment methods supported; the console determines which gateway is available.

01

USDT-TRC20

Complete payment using the amount and recipient details shown at checkout. Verify the network and order before submitting.

02

Visa / Mastercard / Amex

Card payments are processed by Stripe. The marketing site does not store complete card credentials directly.

Settlement currency USD
Report a security issue

Preserve evidence first, then report through a controlled channel

Your report should help the support team reproduce the issue and determine its impact, while avoiding public disclosure of details that could still be exploited directly.

Include these five items in your report

  1. 01
    Impact scope

    State whether the issue involves an account, order, node, connection entry point, or a specific device function.

  2. 02
    Reproduction conditions

    List the prerequisites, steps, expected result, and actual result.

  3. 03
    Incident timeline

    Provide the discovery time, the most recent known-good time, and the actions already taken.

  4. 04
    Redacted evidence

    Attach the necessary logs or screenshots, redacting keys, tokens, passwords, and complete payment details.

  5. 05
    Contact context

    Provide the information needed to identify the order, but do not send credentials that could log directly into the device.

Confirm your security baseline and configuration choices together

Check the workload, memory, storage, node, and rental term first. Then prepare individual credentials, a backup location, and a handoff owner for your team.