Self hosted
Your vault, on your own infrastructure.
Keep every byte in your own network. Ravelon Sync is an open-source server you run yourself, and the Ravelon apps sync with it instead of Ravelon Cloud.
01
Free, open source, no licence check
Ravelon Sync is MIT licensed and lives at github.com/ravelon-app/ravelon-sync. No licence key, no activation, nothing to buy. It sends no telemetry and never phones home, so your server keeps working without any connection to us.
- Free and MIT licensed, no licence key
- No telemetry and no phone-home
- Source you can read, so you can audit the protocol yourself
- Runs with Docker Compose or npm start
02
What you actually run
One container, one port, one volume. The server runs on Node.js 22 and serves the API and a web interface together. It uses SQLite by default; switch to PostgreSQL if you want replicas or your existing backup routine. Put a reverse proxy with TLS in front, because the apps only accept plain HTTP on 127.0.0.1.
Once it's set up, you'll rarely touch a file. The web interface handles users, invitations, sign-up rules, SMTP, maintenance mode, retention and an audit log. Email is optional: without SMTP, invitation and reset links show up in the admin interface and you pass them on yourself.
- Accounts, teams and shared vaults
- Two-factor with authenticator apps and recovery codes
- Sign-up by invitation, by email domain, open or closed
- SQLite by default, PostgreSQL optional
03
It still can't read your vault
Hosts, credentials, keys and snippets are encrypted on your devices. Your account secret only reaches the server locked under a key your device derives from your account password with Argon2id. The server stores passwords as scrypt hashes and refuses any push that looks like unencrypted data.
Everything stored on the server stays encrypted. Your password only passes through when you sign in, so run the server on infrastructure you trust, and the project's security notes describe the model in detail.
“Self hosting changes who runs the server. It still can't read your vault.”
04
Which apps work with it
In the desktop app, go to Settings, Account & sync, Own server, enter the URL and sign in with email and password, or approve the device from a browser where you're already signed in. The iOS app signs in with email, password and your second factor if you use one.
- Desktop: personal and team vaults
- iOS: your personal vault, synced while the app is open
FAQ
Frequently asked questions
Does the desktop app work differently against my own server?
Barely. You enter your server's URL instead of using Ravelon Cloud, and sync, team vaults and device approval work the same way. The overview page in your server's web interface shows the exact URL to enter.
Do I need Ravelon Pro for my own server?
No. Pro pays for sync through Ravelon Cloud. Ravelon Sync is free, and your server decides who can sign up and sync.
Can I move from Ravelon Cloud to my own server later?
Yes. The vault lives on your device and the sync target is just a setting. Change it, and the app uploads the encrypted records to the new server.
What happens if I lose the server?
Every device keeps a full local vault, so losing the server costs you sync, not your hosts. Still, back up the database and the server secrets: without the key that protects the two-factor data, everyone who uses two-factor has to set it up again.
Get started
Try it in your own workspace.
On one device the desktop app is free, with nothing held back: the encrypted vault, terminal, SFTP and the assistant are all included.
What else Ravelon can do
Vault & sync
Encrypted on your device before it syncs, and every new device needs your OK.
Team vaults
Shared encrypted vaults, with team roles and vault roles kept apart.
For companies
Machine policy, company proxies, diagnostic logs and packages for rollout.
iPhone & iPad
Native SSH, SFTP and local tunnels on iPhone and iPad, coming to the App Store.