Encrypted sync

Encrypted Database Sync for a Local-first Mobile Client

DBPort encrypted sync moves connections, snippets, and vault-backed credentials between your devices as end-to-end encrypted records the backend cannot read.

5 min readUpdated June 12, 2026
Metadata sync works without credential syncPasswords and SSH keys sync with cloud sync; turn them off anytimeEvery synced record is encrypted before upload

Two layers: workspace sync and credential sync

DBPort sync normally moves supported local records such as folders, connection organization, snippets, and sync state. Database passwords, SSH private keys, key passphrases, and certificates ride a separate credentials toggle that is on by default once sync is enabled, so you can exclude them whenever you want.

How encrypted records move

Before a supported record leaves your device, DBPort encrypts it. The backend can store, version, and deliver that encrypted record to your other devices, but it is not given the readable contents.

Credential sync without readable secrets

While credential sync is on (the default once sync is enabled), passwords, SSH keys, passphrases, and certificate material are read from the local vault, encrypted as vault records, and uploaded only in encrypted form. Another device can use them only after the user unlocks the sync vault.

What sync does not include

Sync does not make DBPort a cloud database proxy. Query result rows, live database traffic, and direct database sessions stay outside the sync backend. AI context remains a separate explicit action.

Designed for personal device continuity

Encrypted sync is for continuity between your own devices. It is not cloud database hosting, and it does not turn DBPort backend into a place where readable credentials or query results live.

Frequently asked questions

Does sync include query result rows?

No. Sync is for supported local records such as folders, connection organization, snippets, and optional vault-backed records.

Can I use sync without syncing passwords?

Yes. Credential sync has its own toggle, so you can turn it off and sync connections and snippets without syncing passwords or SSH keys.

Does DBPort see my Master Password or recovery code?

No. Your Master Password and recovery code are not sent to DBPort backend.