Security

Security you can check.

Ravelon keeps hosts, passwords and keys in one encrypted file and checks that every server is who it says it is. You choose how strictly the vault is locked, and Ravelon shows you exactly what each setting protects.

ravelon workspace

$

01

One sealed vault, three ways to open it

Hosts, passwords, key passphrases and imported keys all live in one file, encrypted with AES-256-GCM. Nothing readable sits next to it, not even host names. Every save writes a complete new file first and only then replaces the old one, so a crash halfway through won't cost you your host list.

  • Automatic (the default): the key sits in a file next to the vault and Ravelon opens without asking
  • Account password lock: the key is derived from your Ravelon account password with Argon2id
  • Master passphrase: same idea, with a passphrase just for this vault and no account needed
  • The interface never sees a stored secret, only whether there is one

02

Pick the protection that fits you

In automatic mode, your saved passwords stay out of backups, cloud-synced folders and support bundles, and Ravelon opens without asking. For the strongest protection, also against other programs running under your user account, turn on the account password lock or a master passphrase. An idle lock closes the vault again after 5 minutes to 4 hours.

If a vault ever needs recovery, you get a screen with real choices. Starting over archives the unreadable file next to the new one. Ravelon never deletes anything on your behalf.

“Automatic for convenience, a lock for the strongest protection.”

03

Locked when you walk away

With an account password or master passphrase, the vault locks itself after 5 minutes to 4 hours without input, and when your computer wakes up after a longer sleep. ⌘⇧L or Ctrl+Shift+L locks it right away. Locking closes every SSH session, including its tunnels and file transfers, and every remote desktop.

  • Copied passwords disappear from the clipboard after 30 seconds
  • Admins can cap the idle time with a policy
  • Identities with passwords and keys only sync if you turn that on

04

Servers have to prove who they are

On the first connection, Ravelon shows you the host key's algorithm and SHA-256 fingerprint and pins exactly the key you trusted, for every later connection. A changed key gets a dialog that looks different and has differently worded buttons, because from the client's side, a rebuilt server and an interception attempt look exactly the same.

  • Every jump host is checked against its own pin
  • Bring your existing pins over from ~/.ssh/known_hosts
  • VNC with verified TLS certificates
  • RDP with TLS and Network Level Authentication

05

Logs and data that stay yours

The diagnostic log notes connection steps and errors. It never contains passwords, keys, terminal input or output, or AI conversations. Usage statistics are only collected once you agree, and you can see what's stored, export it or wipe everything for this installation.

Desktop updates are verified before they install, and you decide whether they install by themselves. If you installed the .deb or .rpm package on Linux, your package manager takes care of updates instead.

“Enough to debug a connection, nothing that would give one away.”

FAQ

Frequently asked questions

Can Ravelon read my vault?

No. The vault is encrypted on your device. With sync, the server only stores ciphertext and never gets the key.

Does Ravelon have a lock screen?

Not by default: Ravelon opens straight to your hosts. If you want one, turn on the account password lock or a master passphrase. Then you have to unlock Ravelon, and you choose how long it may sit idle before it locks again.

Is telemetry on by default?

No. Ravelon asks once after setup and collects nothing until you say yes. You can change your mind in the privacy settings, and admins can switch telemetry off with a policy.

What does the diagnostic log contain?

App starts, SSH connection steps, host key checks and errors, along with host addresses, ports, user names and fingerprints. Never passwords, keys, passphrases, terminal input or output, or AI conversations.