I built a local encrypted SSH vault because I don’t want my hosts in the cloud

I built a local encrypted SSH vault because I don’t want my hosts in the cloud

# devops# tooling# security# ssh
I built a local encrypted SSH vault because I don’t want my hosts in the cloudEmperr0r

I got tired of SSH sprawl. PuTTY/Moba sessions in one place. Keys in another. Notes in a random...

I got tired of SSH sprawl.

PuTTY/Moba sessions in one place. Keys in another. Notes in a random markdown
file. And every “modern” SSH app quietly wanting a cloud account and a copy of
my host list.

So I built iLead — a native desktop SSH manager with an encrypted vault that
stays on your machine.

What it is

  • Local vault for hosts, keys, notes (Argon2id + AES-GCM style sealing)
  • Import from PuTTY, MobaXterm, WinSCP, ~/.ssh/config
  • Multi-tab SSH, SFTP, tunnels, fleet commands
  • Small Database Studio (Postgres/MySQL/Mongo/Redis/etc.) when you need it
  • Local MCP bridge for Cursor/Claude: list allowed hosts + run commands only after a native approval dialog — secrets are not tool inputs

Platforms: macOS (Apple silicon + Intel), Windows, Linux.

No cloud inventory. No telemetry.

Why local-first

I don’t hate SaaS. I hate uploading a map of production bastions to a third party
just to get a nicer tab UI. A yearly seat that unlocks the app is fine. Syncing
my attack surface to someone else’s database is not.

Try it

I’m the maker. Roast the UX, ask about the vault, tell me what import you still need.