Security
Local vault. Explicit trust.
Built for operators who care what happens on first connect — and what never leaves the machine.
Host key TOFUUnknown keys require a decision. Changed keys block until you replace them on purpose.
↓
AES-256-GCM vaultSecrets sealed locally. Master key in the OS credential store — not plaintext in SQLite.
↓
Optional syncCiphertext only on the server. SSH never depends on cloud login.
Does Klyrn require an account for SSH?
No. SSH, Files, and tunnels work fully offline. An account is only for optional encrypted sync across PCs.
What happens if a host key changes?
Klyrn blocks the connection. There is no casual “accept anyway” path. You must deliberately replace the trusted key.
What does the cloud store?
Optional sync uploads an opaque ciphertext blob. The server does not receive plaintext host profiles or vault secrets.
Read the model, then install Klyrn 1.0. SSH never requires an account.