DEV Community

Cover image for I built a local encrypted SSH vault because I don’t want my hosts in the cloud
Emperr0r
Emperr0r

Posted on

I built a local encrypted SSH vault because I don’t want my hosts in the cloud

I got tired of SSH sprawl.

PuTTY/Moba sessions in one place. Keys in another. Notes in a random markdown
file. And every “modern” SSH app quietly wanting a cloud account and a copy of
my host list.

So I built iLead — a native desktop SSH manager with an encrypted vault that
stays on your machine.

What it is

  • Local vault for hosts, keys, notes (Argon2id + AES-GCM style sealing)
  • Import from PuTTY, MobaXterm, WinSCP, ~/.ssh/config
  • Multi-tab SSH, SFTP, tunnels, fleet commands
  • Small Database Studio (Postgres/MySQL/Mongo/Redis/etc.) when you need it
  • Local MCP bridge for Cursor/Claude: list allowed hosts + run commands only after a native approval dialog — secrets are not tool inputs

Platforms: macOS (Apple silicon + Intel), Windows, Linux.

No cloud inventory. No telemetry.

Why local-first

I don’t hate SaaS. I hate uploading a map of production bastions to a third party
just to get a nicer tab UI. A yearly seat that unlocks the app is fine. Syncing
my attack surface to someone else’s database is not.

Try it

I’m the maker. Roast the UX, ask about the vault, tell me what import you still need.

Top comments (0)