AES
256-GCM encryption, on device
0
Plaintext stored server-side
PBKDF2
Key derivation, unique salt per vault
OS
Keychain for encrypted blob storage
Security
principles.
Six decisions made early. Each one shapes what Termique will and will not do.
Local-first, always
The terminal surface and all credentials live on your device. Optional sync exists but is never required. Termique works fully offline.
AES-256-GCM encryption
Your credentials are encrypted with AES-256-GCM before they leave the renderer process. The encryption key is derived from your master password and never touches the network.
PBKDF2 key derivation
Your master password is never stored. The encryption key is derived locally via PBKDF2 with a high iteration count. Each vault has a unique salt.
OS keychain storage
Encrypted blobs live in the OS keychain - macOS Keychain, Windows Credential Manager, or libsecret. The server never receives plaintext.
No clipboard exposure
Termique connects using decrypted credentials in memory, in-process. Passwords are never written to the clipboard.
Command audit logs
Every command run in every session is timestamped and logged locally. Useful for compliance, shared hosts, and post-incident review.
Sharing is the exception
A host you deliberately share is re-encrypted under a per-share key that our servers hold, encrypted at rest. We can decrypt it - that is what lets a share reach its recipient without you being online. Revoking removes their access through Termique within 30 seconds, but a credential they already accepted lives on their device. Rotate it if someone should lose access.
COMPLIANCE & AUDITABILITY
SOC 2 SSH Access Controls: Audit Logs, Credential Boundaries, and Device Isolation
Meeting SOC 2 Type II criteria (CC6.1 logical access, CC6.2 credential registration, CC6.3 revocation, CC6.8 access audits) requires proving that server access credentials never leak into unmanaged developer environments. Termique enforces these boundaries at the architecture level:
Credential Boundaries (CC6.1)
Key material lives in the Rust keyring layer and never touches the JavaScript heap. Passwords and passphrases are decrypted strictly in-memory during connection initiation.
Command Audit Trails (CC6.8)
Tamper-evident command audit logging with timestamps, originating host identifiers, and executed commands for compliance reviews.
Device Revocation (CC6.3)
Instant single-click session and device key revocation from the account dashboard without needing to cycle remote server authorized_keys manually.
Learn more about our multi-device key architecture in our guide: Managing Multiple SSH Keys Across Devices.