Termetra logo
TERMETRA
[ structural trust — not pinky promises ]

SECURE BY
ARCHITECTURE.
NOT SLOGANS.

Engineers are right to distrust SSH clients. So we built Termetra so that even if we were breached, your keys stay safe. Verify it with Wireshark.

0 packets to vendor AES-256-GCM Argon2id 64MB CPace PAKE
pillar 01

Zero Telemetry Daemon

No tracking SDKs. No analytics in the desktop app. No telemetry pings. Run Termetra in an air-gapped subnet or sniff every packet with Wireshark — silence.

wireshark -i any host termetra.dev
→ 0 packets. verified silence.
pillar 02

SQLCipher v3 Local Vault

Profiles, key references, and snippet variables live in an encrypted SQLite container: 256-bit AES-GCM + Argon2id key stretching (64MB memory cost) + strict RAM secret zeroization on disconnect.

vault.db → AES-256-GCM
→ wrong passphrase = random bytes.
pillar 03

Self-Hosted Sync Only

We run no central cloud database. Multi-device sync goes to your Docker container over TLS with zero-knowledge CPace PAKE. Server stores only encrypted envelopes.

docker compose up -d termetra-sync
→ your VPC. your keys. your rules.
[ coordinated disclosure ]

Found a vulnerability? Highest priority.

Acknowledgement within 24 hours. Triage timeline within 48 hours. Encrypted via PGP.

Genthux Security PGP Public Key
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: OpenPGP.js v4.10.10
Comment: https://termetra.genthux.id/security

mQGNBF+d2iUBDAC...
Fingerprint: 4B38 E8F9 12A0 C792 99E4 5891 0F2A 3E4B D81C 920A
Email: [email protected]
-----END PGP PUBLIC KEY BLOCK-----
[ threat-model faq ]
What happens if Termetra's company servers are hacked?
Nothing leaks — there is no central credential database to steal. Sync servers are customer-hosted and store only SQLCipher-encrypted envelopes. License verification is offline via embedded public keys.
Are private keys ever written to disk in plaintext?
No. Keys are referenced from your SSH agent or OS keychain, or stored inside the AES-256-GCM vault. RAM secrets are zeroized on session disconnect.
How can I audit the "zero telemetry" claim?
Block all egress except port 22/443, run Wireshark during a full workday, or run fully offline — every feature except update checks works air-gapped.
free forever — no card, no account to start

GET TERMETRA.
KEEP YOUR KEYS.

Windows 10/11 • Debian • Fedora • Arch • Flatpak — offline license, air-gap ready