1. At a glance
- You choose what to connect. LayerAdapt only reaches the website, hosting account or database you give it, using the details you enter. It does not know what you have connected or what it contains unless that comes through the product.
- Your passwords stay locked. Hosting and database passwords are encrypted before they are stored, and are never sent to your browser, written to logs or shown to the AI.
- Your website's code is read, never run on LayerAdapt's servers. Files that handle logins, payments, admin areas, settings or form sending are never edited, and files that contain a password or key are never changed or shown.
- Your database records are read live, when someone opens a list, record, dashboard or report. LayerAdapt does not keep its own copy of your tables.
- The AI sees content and structure, not secrets. It never receives passwords, and the AI assistant never receives the records in your database.
- Removing a connection deletes the stored password at once. The audit log of what happened is kept. Details are in section 8.
2. Website mode
For businesses that already have a website. LayerAdapt finds the content in your pages (texts, pictures, services, posts, menus), moves it into tables you can edit, connects the pages to those tables and publishes the changes back to your hosting. Your design stays as it is.
| What you provide | A name for the website and, optionally, its public address. Then either a ZIP file of the website (up to 200 MB, up to 20,000 files, each up to 50 MB), or your hosting's FTP or cPanel details: host name, port, username, password and the website's folder (normally /public_html). The secure connection option (FTPS) is on by default. You also choose whether LayerAdapt may only analyze the website, or also publish changes after your approval. |
|---|---|
| Permissions needed | A ZIP needs no access to your hosting. With FTP, the account needs permission to read the website's folder. To publish, it also needs permission to write the files LayerAdapt changes; LayerAdapt checks this by creating a tiny test file (.layeradapt-write-check) and deleting it straight away. We recommend a separate FTP account limited to the website's folder. |
| What LayerAdapt accesses | The files in the folder you give, except folders that are never part of a website (such as .git, node_modules, vendor, cache, tmp, logs, cgi-bin and .well-known), shortcuts (symbolic links) and very large files. It also visits the public pages at your website's address to read the title, description and sharing picture a visitor's browser gets. It visits only your public address, never a private network address, and identifies itself as "LayerAdapt website check". |
| What is processed | LayerAdapt reads your files as text; it never runs your website's code. It works out how the site is built, which parts are content and which files must not be touched. Files that look like login, account, payment, admin, settings, database connection or form-sending files, and files that contain a password or key, are marked protected and are never edited. When you ask for AI analysis, the AI receives page texts, page names, short samples of repeated content and field names (see section 5). LayerAdapt then creates content tables, connects your pages to them and checks every prepared page against the original before anything can be published. |
| What is stored | On LayerAdapt's server: a private copy of your website's files with the history of every version (this copy includes files LayerAdapt does not edit, such as settings files, which are never shown in LayerAdapt or sent to the AI); your content tables and their entries; pictures you upload; search settings; a record of each prepared change and publish; a fingerprint of each file as it was on your hosting, to spot outside edits; your encrypted FTP password; and, for websites without hosting access, the ZIP downloads LayerAdapt prepares for you. |
| What is temporary | The connection to your hosting is open only while LayerAdapt imports, tests or publishes. An uploaded ZIP is unpacked in a temporary folder that is removed after import; the uploaded file itself is also kept with the record of the import task until a day after the import finishes (or fails), when it is removed by the daily clean-up. Just before publishing, LayerAdapt reads the current version of each file it will replace, so it can put them back if the upload fails. Download links for prepared files expire after 7 days. |
| When you remove it | The website, its encrypted FTP password, its content tables, change records and publish history are deleted from LayerAdapt's database immediately, and LayerAdapt can no longer connect to your hosting. An audit log entry recording the removal is kept. The private copy of your website's files on our server, with its version history, pictures and prepared downloads, is deleted at the same time. Nothing on your hosting is deleted. See section 8. |
| What to keep in mind | LayerAdapt writes to your hosting only when you (or someone you allowed) publishes. Before publishing you see which files will change, and LayerAdapt checks whether anyone changed them on your hosting in the meantime. Keep your own backup of your website too, especially before the first publish. |
Step 1: Add your website
Upload a ZIP of your website or enter your hosting's FTP or cPanel details. LayerAdapt tests the connection before saving it, and refuses addresses that point into a private or internal network. The password is encrypted before it is stored.
Step 2: LayerAdapt copies and reads the files
The files are copied into a private workspace for your website on LayerAdapt's server. This workspace is never served to the public. It keeps a history of every version, so any change can be compared and undone.
Step 3: Finding the content
LayerAdapt's built-in rules find the editable content: page texts, pictures, lists such as services or team members, menus and blog posts. It also reads the titles and descriptions of your live public pages. If you ask for it, the AI reviews the website to suggest clear names and to find more content that should become tables.
Step 4: Preparing the pages
LayerAdapt creates content tables and connects your pages to them, changing only the places where content appears. Layout, styles and scripts are left as they are. For dynamic pages, LayerAdapt adds one small folder to your website (aos-content) with a file that reads your published content from LayerAdapt and keeps a copy on your hosting. That copy is refreshed at most every 30 seconds and is used if LayerAdapt cannot be reached. The address it reads from returns only published content, which is public on your website anyway; it holds no passwords.
Step 5: Review and publish
You see what will change before anything goes live. With hosting access, LayerAdapt uploads the changed files to your hosting over FTP (FTPS where available). Each file is uploaded under a temporary name and then swapped in, and if any upload fails, the earlier files are put back. Without hosting access, you get a ZIP of the changed files to upload yourself. Any earlier version can be restored.
3. Database mode
For businesses that keep their data in a MySQL or PostgreSQL database. LayerAdapt reads the database's structure and builds lists, forms, dashboards, reports, roles, field permissions, approvals, an audit log and an AI assistant around it. Your data stays in your database.
| What you provide | The database type (MySQL or PostgreSQL), host, port, database name (and schema for PostgreSQL), username, password, the SSL setting and, if needed, a certificate. You also choose the access mode: read-only (the default), read and write, or full managed schema (structure changes, which only schema administrators can switch on). |
|---|---|
| Permissions needed | Read-only: permission to read the tables you want to use and the database's structure information. Read and write: also permission to add, change and delete rows in those tables. Full managed schema: also permission to change table structure. The database must be reachable from the internet; private and internal network addresses are refused. We recommend a separate database user with only the permissions you need. |
| What LayerAdapt accesses | The structure: table and view names, columns and their types, keys and links between tables, allowed values defined in the structure, comments and estimated table sizes. The records: only when a person in your workspace opens a list, record, dashboard or report, runs an export or asks the assistant a question, and only what their role, field permissions and row rules allow. |
| What is processed | The structure is analyzed to suggest business names and areas for your tables. Unless you turn it off, the AI helps with this using table and column names and your industry only, never your records. Records are read live and shown to the person who asked. Changes made through LayerAdapt are checked against permissions and validation rules, can require approval, and are written to your database. AI assistant questions are turned into queries that LayerAdapt runs itself; the records found are not sent to the AI. |
| What is stored | Your encrypted password and certificate; the other connection details (host, port, database name, username, SSL setting); versions of the database structure; the set-up LayerAdapt builds (labels, fields, roles, permissions, approvals, dashboards, reports and saved views); connection health history; audit log entries, including the values that changed (see section 6); assistant conversations (questions, answers and query plans, not the records found); and any business notes you add for the assistant. |
| What is temporary | Records LayerAdapt reads to show you are not kept as a copy of your tables. The database connection is opened when needed and closed afterwards. Export files (CSV) are created on LayerAdapt's server so you can download them, and are deleted by the daily clean-up after one day. |
| When you remove it | You confirm by typing the connection's name. The connection, its encrypted password and certificate, the stored structure, and the lists, fields, permissions, approval workflows and saved views built on it are deleted from LayerAdapt immediately. Audit log entries are kept, and assistant conversations remain until their retention period ends. Reports or dashboard tiles that referred to it may remain until you delete them. Nothing in your database is changed or deleted. See section 8. |
| What to keep in mind | Read-only mode is enforced by LayerAdapt; for a guarantee enforced by your database itself, connect with a database user that only has read permission. In the other modes, changes are written to your live database. A record deleted through LayerAdapt is deleted in your database (the audit log keeps a copy of it). Keep regular backups of your database. |
Step 1: Add a connection
Enter the connection details and choose the access mode. LayerAdapt tests the connection, refuses private or internal network addresses, and encrypts the password before storing it. Only the first two characters of the username are ever shown again.
Step 2: Authentication
Each time LayerAdapt needs your database, it decrypts the password on the server, signs in with your username, and uses SSL according to the setting you chose. "Require" or "verify" settings make sure the connection is encrypted; "verify" also checks your database server's certificate.
Step 3: Reading the structure
LayerAdapt reads the database's structure, not its records, and saves a version of it. When the structure changes later, a new scan records the difference.
Step 4: Building your workspace
From the structure, LayerAdapt suggests names, forms and links between tables, which an administrator reviews. You then set up roles, field permissions, row rules, approvals and dashboards.
Step 5: Daily use
Every list, record, dashboard, report and export reads your database live, filtered by the person's permissions. Every change made through LayerAdapt is recorded in the audit log. Structure changes, and changes the AI proposes, wait for approval by someone with the right permission.
4. Your passwords and keys
- FTP passwords, database passwords, database certificates and the AI provider key are encrypted at rest with authenticated encryption (libsodium secretbox, XSalsa20-Poly1305). The encryption keys are kept separately from the database.
- They are decrypted only on the server, at the moment a connection is made, and are never sent to your browser, never written to logs and never sent to the AI. Logs and the audit log automatically hide anything named like a password, secret, token or key.
- After saving, a password is never shown again, not even to you. To change it, enter a new one.
- Your own LayerAdapt password is stored only as an Argon2id hash. See the Privacy Policy.
5. What the AI sees
LayerAdapt uses Anthropic's Claude models. The AI is used for specific tasks only, and receives only what each task needs:
| Task | The AI receives | The AI never receives |
|---|---|---|
| Website analysis (when you ask) | Page texts, page names, short samples of repeated content, field names, your website's name | Passwords, hosting details, settings files, files that contain secrets |
| Database set-up | Table and column names, your industry | Records, passwords, connection details |
| AI assistant | Your question, your last few messages, the names and types of tables and fields you are allowed to see, allowed values defined in the structure, your workspace's business notes and role names | Records in your database, fields you are not allowed to see, passwords, connection details |
What the AI suggests is checked before it is used: it can only point at content and fields that exist, every query is validated against your permissions, and changes it proposes wait for human approval. We do not use your content to train AI models. Assistant conversations are deleted automatically after the retention period, currently 90 days.
6. Audit log and activity
Important actions are recorded: sign-ins, connections added or removed, websites analyzed and published, records created, changed or deleted, approvals, AI requests and settings changes. Each entry records who did it, when, from which IP address and browser, and what changed.
- For records changed through LayerAdapt, the entry keeps the old and new values of the fields that changed. Fields marked as sensitive in your set-up are hidden as "[redacted]" when records are created or changed.
- When a record is deleted through LayerAdapt, the entry keeps a copy of the deleted record so you can see what was removed.
- Anything named like a password, secret, token or key is always hidden.
- The audit log is not deleted when you remove a website or database, because it is the record of what happened.
7. Stored and temporary
| Data | Where | How long |
|---|---|---|
| Encrypted FTP and database passwords | LayerAdapt's database | Until you remove the connection |
| Private copy of your website's files and their history | LayerAdapt's server | Until you remove the website, then deleted at once |
| Content tables, uploaded pictures, search settings | LayerAdapt's database and server | Until you remove the website (uploaded picture files: until you ask us) |
| Uploaded website ZIP | With the import task record | Removed a day after the import finishes |
| Content copy on your hosting (aos-content) | Your hosting | Yours to keep or delete |
| Database structure and set-up | LayerAdapt's database | Until you remove the connection |
| Your database records | Your database | Not copied by LayerAdapt, except values in the audit log and in exports |
| Export files (CSV) | LayerAdapt's server | One day, then deleted by the daily clean-up |
| Audit log | LayerAdapt's database | Kept as the long-term record of the workspace |
| AI assistant messages | LayerAdapt's database | Currently 90 days |
| Temporary working files | LayerAdapt's server | Removed when the task that needed them finishes |
8. Removing a connection
Removing a website
- Deleted immediately: the website's settings, its encrypted FTP password, its content tables and entries, prepared changes, publish history and the records of what LayerAdapt found.
- Kept: the audit log entries, including one recording that the website was disconnected.
- Also deleted immediately: the private copy of the website's files, its version history, uploaded pictures and prepared downloads on LayerAdapt's server.
- On your hosting: nothing is removed. Pages LayerAdapt prepared keep working, using the last copy of your content saved on your hosting.
- What you should do: change the FTP password, or delete the FTP account you created for LayerAdapt, in your hosting control panel.
Removing a database connection
- Deleted immediately: the connection, its encrypted password and certificate, the saved database structure, and the lists, fields, permissions, row rules, approval workflows and saved views built on it.
- Kept: audit log entries (including old and new values of changed fields and copies of deleted records), assistant conversations until their retention period ends, and reports or dashboard tiles you created until you delete them.
- In your database: nothing is changed or deleted.
- What you should do: remove the database user you created for LayerAdapt, or change its password.
Closing your workspace or account
There is no self-service button for this yet. Email support@layeradapt.com and we will remove your workspace, its connections and stored copies, and tell you what we have to keep and why (for example, invoices the law requires us to keep).
9. If you stop using LayerAdapt
Your website keeps working. Pages prepared by LayerAdapt use the copy of your content saved on your own hosting when LayerAdapt cannot be reached, so they keep showing your last published content. To make further changes, you would edit that content on your hosting yourself, or ask us before you leave to help you put the content back into the pages. Your database is never moved, so it stays exactly where it is.
10. Your responsibilities
LayerAdapt acts on what you connect and the instructions you and your team give. You are responsible for:
- making sure you own, or are authorized to connect and process, every website, hosting account, database and piece of data you connect;
- keeping your credentials private, and deciding what permissions the accounts you give LayerAdapt have;
- keeping backups of your website and database where appropriate;
- reviewing what LayerAdapt prepares, and what the AI suggests, before you publish it, approve it or rely on it;
- the people you invite to your workspace and the roles you give them;
- meeting the privacy and other legal obligations that apply to the data in your systems.
See the Terms & Conditions for the full rules.
11. Connecting safely
- Use strong, unique passwords for LayerAdapt, your hosting, your database and your email. A password manager helps.
- Turn on multi-factor authentication wherever it is offered: your hosting control panel, your database provider, your domain registrar and your email.
- Give LayerAdapt its own access. Create a separate FTP account limited to your website's folder, and a separate database user with the least permissions needed: read-only if you only want to look.
- Review permissions before connecting. Check what the FTP account or database user can reach, and choose the most limited LayerAdapt access mode that does the job.
- Turn on secure connections. Keep FTPS on, and use "require" or "verify" SSL for databases where your provider supports it.
- Only connect resources you trust and are allowed to use.
- Never share passwords or API keys by email or chat, including with us. We will never ask for your LayerAdapt password.
- Revoke access you no longer need. Remove the connection in LayerAdapt and delete or change the FTP account or database user.
- Check your sign-in activity in LayerAdapt from time to time, and sign out devices you do not recognize.
More on how LayerAdapt protects you on the Security page.
12. Questions
If you are unsure what LayerAdapt will access, or you want something deleted, email support@layeradapt.com before or after you connect. See also our Privacy Policy.