Local vault

Secure Database Vault for Passwords and SSH Keys

DBPort keeps database passwords, SSH keys, and certificates in a local encrypted vault. Cloud sync is off until you opt in, and synced credentials stay end-to-end encrypted.

5 min readUpdated June 12, 2026
Passwords and SSH keys stay in a local encrypted vaultCredential sync is optional and encrypted end to endDBPort servers never receive credentials in readable form

The vault is the boundary for database secrets

A mobile database client handles materials that can open production systems. DBPort stores passwords, SSH private keys, key passphrases, TLS client keys, and certificates in the app vault instead of treating them as ordinary settings.

Local unlock before any secret is used

Vault items are encrypted at rest on the device. App lock, biometrics where available, and the device security layer protect access. When the vault locks, DBPort clears cached secret material and closes active database drivers.

Credential sync is a separate choice

Cloud sync keeps connection labels, folders, and snippets consistent, and credential sync rides the same switch - it is on by default once you enable cloud sync. Turn credential sync off and passwords and SSH keys stay on the device; vault-backed items that do sync are encrypted on the device before upload, so DBPort stores them only as encrypted records.

What DBPort backend cannot read

DBPort backend does not receive database passwords, SSH keys, host credentials, query result rows, or database traffic in readable form. It stores encrypted sync records plus the minimal information needed to deliver them to your own devices.

Recovery has limits

The Master Password and recovery code unlock encrypted sync data on new devices. DBPort cannot recover credentials if both are lost, so database least privilege, credential rotation, VPN rules, and backups still matter.

Frequently asked questions

Does DBPort backend store database passwords or SSH keys in readable form?

No. Plaintext database passwords, SSH private keys, passphrases, and certificates are not stored on DBPort backend.

Are SSH private keys synced automatically?

Cloud sync is off until you opt in. Once it is on, credential sync is enabled by default, so SSH keys sync as end-to-end encrypted records unless you turn credential sync off in Sync settings - then they never leave the device.

What happens on a new device?

After sign-in, the device must unlock the sync vault with the Master Password or recovery code before encrypted vault records can be decrypted into the local vault.