The vault is the boundary for database secrets
A mobile database client handles materials that can open production systems. DBPort stores passwords, SSH private keys, key passphrases, TLS client keys, and certificates in the app vault instead of treating them as ordinary settings.
Local unlock before any secret is used
Vault items are encrypted at rest on the device. App lock, biometrics where available, and the device security layer protect access. When the vault locks, DBPort clears cached secret material and closes active database drivers.
Credential sync is a separate choice
Cloud sync keeps connection labels, folders, and snippets consistent, and credential sync rides the same switch - it is on by default once you enable cloud sync. Turn credential sync off and passwords and SSH keys stay on the device; vault-backed items that do sync are encrypted on the device before upload, so DBPort stores them only as encrypted records.
What DBPort backend cannot read
DBPort backend does not receive database passwords, SSH keys, host credentials, query result rows, or database traffic in readable form. It stores encrypted sync records plus the minimal information needed to deliver them to your own devices.
Recovery has limits
The Master Password and recovery code unlock encrypted sync data on new devices. DBPort cannot recover credentials if both are lost, so database least privilege, credential rotation, VPN rules, and backups still matter.
Frequently asked questions
Does DBPort backend store database passwords or SSH keys in readable form?
No. Plaintext database passwords, SSH private keys, passphrases, and certificates are not stored on DBPort backend.
Are SSH private keys synced automatically?
Cloud sync is off until you opt in. Once it is on, credential sync is enabled by default, so SSH keys sync as end-to-end encrypted records unless you turn credential sync off in Sync settings - then they never leave the device.
What happens on a new device?
After sign-in, the device must unlock the sync vault with the Master Password or recovery code before encrypted vault records can be decrypted into the local vault.