On your device
Hosts, settings, SSH sessions, terminal content, and optional vault credentials remain on your machine.
Nothing to enableSecurity at Zync
Zync keeps everyday SSH work on your desktop. Optional sync and sharing features have clear, limited boundaries.
Based on SECURITY.mdUpdated August 29, 2026Data boundaries
Your workspace stays local unless you deliberately enable encrypted backup or share a localhost service.
Hosts, settings, SSH sessions, terminal content, and optional vault credentials remain on your machine.
Nothing to enableEncrypted backup and sync collections go to the hidden drive.appdata folder in your Google account.
Encrypted before uploadWhile a share is active, traffic from the localhost port you selected passes through the Zync relay.
Only while activeProtection layers
The optional vault uses Argon2id key derivation and authenticated encryption for credentials at rest.
Passphrase + recovery keyThe vault is optional. You can continue using SSH key files stored on disk.
No forced migrationRemembered vault unlock material and Public URLs session tokens use the operating system credential store.
Opt in per deviceMarketplace plugins do not receive raw vault secrets by design. Review third-party permissions before installing.
No raw vault secretsPractical guidance
Losing both your vault passphrase and recovery key means local vault credentials cannot be decrypted.
Enable it only on a personal, trusted device. Anyone with access to your unlocked OS session may reach vault-backed connections.
A Drive backup can include related hosts, tunnels, snippets, and credentials. Review the preview before applying it.
Anyone with the URL can reach the selected service while the share is active unless you set an optional password.
Responsible disclosure
Report vulnerabilities privately to the maintainers. Do not open a public issue with exploit details.