Engineers are right to distrust SSH clients. So we built Termetra so that even if we were breached, your keys stay safe. Verify it with Wireshark.
No tracking SDKs. No analytics in the desktop app. No telemetry pings. Run Termetra in an air-gapped subnet or sniff every packet with Wireshark — silence.
Profiles, key references, and snippet variables live in an encrypted SQLite container: 256-bit AES-GCM + Argon2id key stretching (64MB memory cost) + strict RAM secret zeroization on disconnect.
We run no central cloud database. Multi-device sync goes to your Docker container over TLS with zero-knowledge CPace PAKE. Server stores only encrypted envelopes.
Acknowledgement within 24 hours. Triage timeline within 48 hours. Encrypted via PGP.
-----BEGIN PGP PUBLIC KEY BLOCK----- Version: OpenPGP.js v4.10.10 Comment: https://termetra.genthux.id/security mQGNBF+d2iUBDAC... Fingerprint: 4B38 E8F9 12A0 C792 99E4 5891 0F2A 3E4B D81C 920A Email: [email protected] -----END PGP PUBLIC KEY BLOCK-----
Windows 10/11 • Debian • Fedora • Arch • Flatpak — offline license, air-gap ready