Everything in one client
Reach your servers privately, with security that holds whether or not anyone is watching.
Cipher-cascade vault
Servers, keys and passwords are sealed with XChaCha20-Poly1305 inside AES-256-GCM, keyed by Argon2id. Two independent ciphers — breaking one isn't enough.
Tor when you want it
Route any host, including .onion, through Tor — per-server or globally. DNS resolves inside the circuit, so the connection leaks nothing.
Hardware-key unlock
Open the vault with a FIDO2 key over USB. Its hmac-secret derives a real wrapping key, not a yes/no gate. Your password stays as the fallback.
Proper terminals
Full PTY shells, many sessions in tabs, and a system-SSH fallback for the odd host the built-in client can't talk to.
SSH, SFTP and RDP
Shells, file transfer and remote desktops in one app — all over the same encrypted, optionally Tor-routed connection.
Bring your servers
Import from Termius, an SSH config, or JSON. Group and tag hosts, keep notes — all encrypted at rest.