Control publishing privacy
Use Privacy settings to control published-app access and protect development URLs.
Privacy settings, cropped to exclude personal account details and unrelated settings.
Private deployments
A public deployment is intended to be accessible to visitors outside your organization. A private deployment requires authorized access rather than exposing the app publicly. Use Private deployments to choose your team’s publishing policy:
This policy applies to newly published apps. It does not change the visibility of apps that are already published. Review existing apps separately.
Public publishing exceptions
Select Manage beside Public publishing exceptions to review and revoke project-specific exceptions across the account. This helps administrators track projects permitted to publish publicly without relaxing the policy for everyone.Password-protected deployments
Password protection lets builders share a published app with people who have its password. It is different from private access tied to an authenticated identity. Use Password-protected deployments to control whether builders can create them:
Protect development previews
Require private development URLs controls access to apps while they are being built, rather than their published production deployments. When enabled, all app development URLs require authentication. This includes SSO if your organization has enabled SAML.Restrict exports and uploads
The same Privacy settings section includes two additional controls:- Ban source code export: Prevents builders from exporting app source code as a ZIP file. This is an export control, not a guarantee that code cannot leave through another route.
- Ban attachment uploads: Prevents builders from uploading file attachments in Replit chat or importing files.
Choose deployment geography
Under Deployment settings, use Deployment geography to control where members can publish projects. Choose All geographies to allow any available geography, or select a specific geography.
This setting governs deployment geography. It is not a promise that every service used by an app, such as an external database or API, stores or processes data in the same geography.
Next step
Agent modes and models
Choose approved models and control access to higher effort levels.