Vault & sync

Your vault is encrypted before it leaves your device.

Hosts, credentials, keys, passwords and saved commands are encrypted on your desktop. The sync service gets nothing but the encrypted vault.

local deviceencrypted vaulthosted syncWindowsmacOSLinuxencrypted data only

01

Encryption happens on your device

Ravelon encrypts the vault on your device with AES-256-GCM. Out of the box, the key sits in a file next to the vault, so the app opens without asking for anything. If you want a lock, the key comes from your Ravelon account password or a separate master passphrase instead. The server never gets either.

“The server never gets the key to your vault.”

02

Encrypted sync between approved devices

The encrypted vault moves between your devices. A new desktop has to be approved in your browser before it can use Ravelon Cloud. With Self Hosted, you can use the same browser approval or sign in directly, depending on how you set it up.

  • The server only sees encrypted vault data
  • Every device on Ravelon Cloud needs your approval
  • Works across Windows, macOS and Linux
  • Every approved device can restore the encrypted vault

03

One sign-in, several vaults

Sign in with your account email and password, plus your second factor if you've set one up. If your account uses Google, GitHub or Discord, you sign in through the browser. Your personal vault and any team vaults then sit side by side in the vault switcher.

Hosts, groups, snippets and settings follow you as soon as you're signed in. Identities, with their passwords, key passphrases and imported keys, only sync once you turn on Sync keys & identities.

  • Each record syncs on its own, with a three-way merge
  • When the server reports a change, open devices sync
  • Ravelon Cloud, your own server, or no sync at all

04

Built for sensitive server credentials

One SSH key or server password can open a lot of doors in your infrastructure. That's why Ravelon encrypts them before they're stored and never sends a readable copy to the sync server.

“SSH keys and server passwords deserve better than an ordinary settings file.”

FAQ

Frequently asked questions

Can Ravelon's servers read my credentials?

No. Encryption and decryption happen only on your devices. The sync service stores the encrypted vault but has no key to open it.

What happens if I lose my passphrase?

Your passphrase is the only key to the vault. Nobody else holds a copy, not even Ravelon, which is exactly what keeps your data private. Keep your recovery information somewhere safe.

Do I need sync to use Ravelon?

No. The free version is the full app with a local encrypted vault on one device. Sync is what Ravelon Pro adds.