Vault & Security
Four independent encryption tiers and a password manager. Your host list is encrypted from first launch with no setup.
How your secrets are protected
- Per-secret OS encryption — Every password, passphrase, PIN and token goes straight to Windows Credential Manager, macOS Keychain or the Linux Secret Service. Your host list file never receives the value — only a flag saying a secret exists.
- Private keys — Keys generated in MangoSSH are encrypted in every storage mode. The private key material is never sent to the interface, encrypted or not.
- The host list itself — Hostnames, usernames, groups and settings are encrypted at rest with AES-256-GCM by Personal Vault, which is on by default.
Sharing across devices and people
- Personal Vault — Encrypts your own host list on one machine. No network component at all.
- Team Vault — Shares a host list through storage you already control — Dropbox, OneDrive, WebDAV or any shared path. No MangoSSH-operated server.
- Self Hosting Vault — A real sync server, run by you.
- Cloud Vault — The same protocol, hosted by MangoSSH so you do not run a server.
Password Manager
General logins unrelated to any SSH host, organised in folders. Revealing or copying a password can be put behind a Windows Hello or Touch ID gesture.
What this does not protect against
Encryption at rest defends against someone obtaining the raw files — a stolen laptop, a copied disk image, a stray cloud sync. It does not defend against a process already running as your logged-in user, or someone at your unlocked machine. That is the same trust boundary every desktop credential store relies on.
Step-by-step guides
How to set each of these up, one task per page.
- Vaults: Personal, Team and Cloud →Where your hosts and secrets are kept, and how each tier encrypts and syncs them.
- Self-hosting the vault server →Run your own vault server for team sync, step by step.
- Password manager →Keep logins, notes and API keys in the vault, with a generator and a reveal gate.
Full detail
Step-by-step instructions, how to check each one worked, and what to do when it did not.