Skip to content
Zync

Security at Zync

Your infrastructurestays yours.

Zync keeps everyday SSH work on your desktop. Optional sync and sharing features have clear, limited boundaries.

Based on SECURITY.mdUpdated August 29, 2026

Data boundaries

Where your data lives.

Your workspace stays local unless you deliberately enable encrypted backup or share a localhost service.

Default

On your device

Hosts, settings, SSH sessions, terminal content, and optional vault credentials remain on your machine.

Nothing to enable
The core app works without a Zync account.
Optional

Your Google Drive

Encrypted backup and sync collections go to the hidden drive.appdata folder in your Google account.

Encrypted before upload
Drive Sync uses its own OAuth client and encryption passphrase.
Public URLs Beta

Zync relay

While a share is active, traffic from the localhost port you selected passes through the Zync relay.

Only while active
SSH sessions, vault secrets, and terminal content are not sent automatically.

Protection layers

How access is protected.

Encrypted Local Vault

The optional vault uses Argon2id key derivation and authenticated encryption for credentials at rest.

Passphrase + recovery key

Existing key files still work

The vault is optional. You can continue using SSH key files stored on disk.

No forced migration

OS credential store

Remembered vault unlock material and Public URLs session tokens use the operating system credential store.

Opt in per device

Plugin boundary

Marketplace plugins do not receive raw vault secrets by design. Review third-party permissions before installing.

No raw vault secrets

Practical guidance

A few things to remember.

Save the recovery key offline

Losing both your vault passphrase and recovery key means local vault credentials cannot be decrypted.

Use remembered unlock carefully

Enable it only on a personal, trusted device. Anyone with access to your unlocked OS session may reach vault-backed connections.

Review restore previews

A Drive backup can include related hosts, tunnels, snippets, and credentials. Review the preview before applying it.

Stop public shares when finished

Anyone with the URL can reach the selected service while the share is active unless you set an optional password.

Responsible disclosure

Found a security issue?

Report vulnerabilities privately to the maintainers. Do not open a public issue with exploit details.