What's Special
Two editions from one codebase, split at compile time: MangoSSH for the internet, and MangoSSH Secure for an air-gapped enclave — where the network code is absent from the binary rather than switched off.
Compile-time, not a setting. An operator auditing the Secure edition checks that the outbound code is not in the binary — rather than trusting a switch a bug, a policy reset or a determined user could flip back.
What it can and cannot reach
Air-gapped here means no internet, not no servers. A real enclave runs its own vault, its own relay, its own identity provider. So the Secure edition does not refuse to speak to a server — it refuses to speak to an address you did not give it.
- The guarantee — No telemetry, no phone-home, no baked-in external addresses, no internet-only features. Deliberately not "no network" — that would sound stronger while being weaker, since it would still rest on something staying switched off.
- Enforced at build — Every release builds both editions for all four platforms, then greps the compiled Secure binary for fourteen external hostnames. One match fails the release. A check on the shipped artefact, not a promise about intent.
- The webview too — An embedded browser can egress independently of the backend, so the Secure build also ships a locked content-security policy: local sources only for scripts, images, media and fonts, no outbound fetch, no framing, no form posts.
In a real deployment
- One installer, nothing fetched — A single signed installer per platform. The terminal emulator, the VNC client, the code editor and the RDP helper are all bundled in — no package manager runs, and nothing downloads after install.
- Nothing to activate — The licensing module is not compiled into the Secure edition at all. There is no activation call, no token to validate, and no grace period that can quietly expire on a machine that will never see the internet.
- Every address is yours — Relay, vault, certificate authority, JIT approval and the brokers each take a URL you type in Settings — an internal hostname or a bare IP. Nothing assumes DNS resolves beyond your own network.
- No database to stand up — State is local encrypted files plus your operating system's own credential store. No server, no schema migration, no cloud database.
- Evidence stays on the machine — A hash-chained audit log, session recordings, terminal exports and command history all live on disk, and all export by hand. Nothing is shipped anywhere for you to retrieve later.
- No telemetry, no crash reporting — Neither edition contains any. There is nothing to opt out of.
- No update button to ping — The version check and news feed are compiled out, so the app never reaches for a release manifest. You deploy the next installer through whatever media your process allows.
Built for
Classified and defence networks, OT and ICS plant floors, utility substations, card-data environments, clinical device networks, and anywhere connectivity is physically absent — ships, rigs, mines. The common thread is a network where an unexpected outbound packet is an incident, not an inconvenience.
MangoDock does this differently
Worth knowing if you run both. MangoDock is also built for isolated networks, but it is a server whose entire purpose is reaching Docker daemons — that network code cannot be compiled out, because it is the product. So it ships one image that makes no request of its own, and its editions differ in how the software and its scanner databases cross into the network rather than in what they contain. "The code is not in the binary" is the right claim for a client; "it only goes where you send it" is the right one for a server.
Step-by-step guides
How to set each of these up, one task per page.
- PAM Broker and browser access →Let people connect without ever seeing the password, from the app or a browser link.
- Remote access by ID →Reach a machine with no port forwarding: the host agent, Connect by ID, P2P and the unattended service.
- Policies →One page to set recording, JIT, crypto and key rules across many hosts.
Full detail
Step-by-step instructions, how to check each one worked, and what to do when it did not.