Tape off what’s yours.
Hand over the rest.

Castor is the boundary between a website you built and a client who wants to help. Mark exactly what they can repaint — the words, a photo, one button’s colour — and nothing outside the line moves, no matter how hard they lean on it.

Free, self-hosted, AGPL-3.0. No subscription, no seat count.

client-site.example

yours to paint
yours to paint
Book a table

Tape marks what’s locked. Peel one back — it still says no.

You lay the tape. Once.

Most CMSes hand a client the whole dashboard and hope for the best. Castor hands them a page and a taped-off line. You decide which side of it each thing sits on.

exposed — paint it
  • +The words
  • +The photos
  • +Links and buttons
  • +Colours you allow
taped — locked
  • The layout
  • The structure
  • Anything off-brand
  • The code

Try to break it.

This isn’t a screenshot — type in the page below and it edits like the real thing. Then change what’s permitted and reach for a colour it won’t let you have.

Northside DentalDraftNo colours

Click any highlighted text and type.

Gentle dentistry in Northside

Same-day appointments, and a team that explains what it’s doing before it does it.

Book a visit
Every change is checked before it reaches the draft.
A miniature of the real editor. Your client sees this; you set the permissions.

Three moves.

You

Tape it off

Build the site your way, or import one you've already built. Decide what's structural — and what a client may repaint.

Your client

Paints inside the line

They get a link and a password, click a headline, and type. No tickets, no invoice for fixing a typo.

Castor

Holds the tape down

Every change is checked against the boundary you set before it saves. Nothing outside the line moves — ever.

Enough to hand over with a straight face.

Permissions, per site

Tick exactly what each client may touch — text, images, links, colour, spacing. Any combination. Change it whenever.

Colour, held on a leash

Let a client recolour a heading with the real OS colour picker — or keep them to the swatches you chose. Their call, your limits.

Draft, then publish

Every edit lands in a private draft. Nothing goes live until someone presses Publish. No surprise changes on the real site.

Every version kept

Publishing snapshots the site. Going back to how it looked on Tuesday is one click — not a restore from a backup.

Import a built site

Drag a ZIP of an existing site onto the dashboard. It becomes editable, its own scripts still running, safely sandboxed.

Undo that behaves

⌘Z and ⇧⌘Z, without stealing the browser's own undo while your client is mid-sentence in a paragraph.

Nothing goes live by accident.

Edits sit in a draft until published. Each publish is kept forever, so undoing a bad week is one click.

Sample publish history
live v4 · spring hourslive · today
v3 · new team photoroll back
v2 · launch copyroll back

It’s free. Go build.

The source is public and yours to run — for as many client sites as you like, at no cost. It’s open source (AGPL) — anything you build on it stays open too.

Node · Vercel · MongoDB Atlas — free tiers are plenty

Questions first?

Not sure it fits what you’re building, or stuck getting it running? Ask — you’ll get a real answer from the person who wrote it.