HomeSupportContact | Settings
language Languages
dark_modeperson

Security

Who can do what, on which host, who approves

Local vault. Desktop is the approval gate. The backend does not SSH to the client. Cloud keeps metadata and redacted audit.

Five promises

Limits, said plainly — we do not sell what has not shipped

  1. No secret upload

    Private keys, passwords and the vault never go to the cloud. Sync only pushes cleaned profile metadata.

  2. Desktop is the last gate

    AI does not execute commands. The app on your machine asks for approval on changing commands, then runs them on the local SSH session.

  3. The backend does not SSH to you

    The SSH session goes straight from Desktop to the server. Cloud does not open SSH for you and does not store keys.

  4. Cloud keeps metadata and redacted audit

    Workspace, devices, grants, cloud logs — secrets are redacted. Local logs do not sync by default.

  5. Policy is the safety ceiling

    Workspace Security Policy sets the maximum. Grants per person or per machine cannot exceed it. Trusted devices, revocable.

Security & access

Who can do what, on which host, who approves — all under a safety ceiling

Workspace Security Policy

Workspace policy sets the maximum; grants per person or per machine cannot exceed it.

Trusted devices, revocable

Each machine with the app is a registered device. Revoke it and every cloud action from that device stops.

Approve access and AI commands

Access requests and AI commands that need approval share one Approvals inbox; who approved when is in the audit.

Secrets never leave the device

The local vault holds passwords, keys, passphrases. Cloud keeps metadata and redacted audit.

Role:OwnerAdminOperatorApproverViewer
Said plainly so it is not misunderstood

This is not web SSH

The backend does not open SSH to the client and does not store secrets. The web has an API but it does not replace Desktop for running commands — to run anything, the app on your machine must be open.

Download Desktop and SSH now

Local Mode runs with no account: import existing SSH sessions, open a terminal, use the vault and recorder. Sign in only when you need metadata sync, access, or cloud audit.

Quick questions