Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Vault & Security

    Four independent encryption tiers and a password manager. Your host list is encrypted from first launch with no setup.

    The Password Manager. Reveal and copy can be put behind a biometric gesture.

    How your secrets are protected

    • Per-secret OS encryption — Every password, passphrase, PIN and token goes straight to Windows Credential Manager, macOS Keychain or the Linux Secret Service. Your host list file never receives the value — only a flag saying a secret exists.
    • Private keys — Keys generated in MangoSSH are encrypted in every storage mode. The private key material is never sent to the interface, encrypted or not.
    • The host list itself — Hostnames, usernames, groups and settings are encrypted at rest with AES-256-GCM by Personal Vault, which is on by default.

    Sharing across devices and people

    • Personal Vault — Encrypts your own host list on one machine. No network component at all.
    • Team Vault — Shares a host list through storage you already control — Dropbox, OneDrive, WebDAV or any shared path. No MangoSSH-operated server.
    • Self Hosting Vault — A real sync server, run by you.
    • Cloud Vault — The same protocol, hosted by MangoSSH so you do not run a server.

    Password Manager

    General logins unrelated to any SSH host, organised in folders. Revealing or copying a password can be put behind a Windows Hello or Touch ID gesture.

    What this does not protect against

    Encryption at rest defends against someone obtaining the raw files — a stolen laptop, a copied disk image, a stray cloud sync. It does not defend against a process already running as your logged-in user, or someone at your unlocked machine. That is the same trust boundary every desktop credential store relies on.

    Step-by-step guides

    How to set each of these up, one task per page.

    Full detail

    Step-by-step instructions, how to check each one worked, and what to do when it did not.