Security and data handling Zero telemetry No credentials in sync EU operator

How Edgely handles your data

The short version: your credentials are encrypted with keys we never hold, sync carries connection metadata only, and there is no telemetry to opt out of.

Security and data handling

What leaves your machine, and what doesn't

Stated as commitments you can check in the product, not assurances you have to take on faith.

Zero-knowledge vault
Passwords, SSH private keys and API tokens are encrypted on your device with AES-256-GCM. We cannot decrypt them, because we never hold the key.
Two ways to unlock it
A master password, from which Argon2id derives the vault key, or a device-only 256-bit key kept in the OS keychain. Each application gets its own keychain entry, and switching between the two re-encrypts every entry in one operation.
No credentials in sync
Sync carries connection metadata only: hostnames, ports, usernames, groups, preferences. A credential cannot reach our database, and the server rejects any item that looks like one.
Encrypted exports
Credentials move between your devices through a password-protected file you create and import yourself. The password is at least 12 characters, it never leaves your device, and there is no recovery flow.
Zero telemetry
No usage counters, no session tracking, no crash or error reports. Diagnostic logs stay in a folder on your own device. There is no setting to switch off because there is nothing to collect.
Signed installers
The macOS disk image is signed and notarized, the Windows installers and the binaries inside them carry an Authenticode signature, and every Linux package ships with a GPG signature and a signed SHA256SUMS file.

Cross-device sync

What gets synced, and what never does

An account exists to carry your licence and to sync your setup between your own devices. That list is the whole list: there is no advanced option that syncs more.

Synced to your account

  • Connection metadata: hostnames, ports, usernames, protocol settings
  • Groups: the folder structure you organize your entries in
  • Preferences: theme, locale, layout, default protocols
  • Bookmarks: the items you pinned
  • Snippets: the commands you saved
  • Custom data: plugin items that opt into sync

Never synced

  • Passwords for any saved connection
  • SSH private keys and their passphrases
  • API tokens, OAuth tokens, bearer tokens
  • Client secrets, AWS access keys and session tokens
  • Anything stored in your local credentials vault

Enforced on the server

The desktop apps strip credentials from every payload they produce, and the portal checks again independently. Forbidden key namespaces, a denylist of credential field names walked through the whole payload, and a missing integrity signature each answer 422 and are counted on the admin dashboard, so a misbehaving client is visible rather than silent.

Organization-shared connections are readable by us

A connection shared with an organization is stored so the server can apply membership, which is what makes removing a member remove their access at once. It is not end-to-end encrypted, unlike your personal entries. It still carries no credential: host, port and username travel, and every member supplies their own password from their own vault.

Moving credentials

How to move credentials between devices

There is no server-side path for this on purpose. The file is the path, and you hold its password.

  1. Export on the source device Open the desktop app, then Settings, then Export.
  2. Choose what to take, and set a password Vault for credentials only, Full backup for everything, Connections for connections with their credentials. The encryption password is at least 12 characters and is independent of your vault password.
  3. Move the file yourself USB drive, secure file share, encrypted email, your own cloud folder. The file is encrypted, so what matters is that you protect the password.
  4. Import on the target device Settings, then Import, then supply the password.

File formats .evlt .efull .econ .eset

Lose the password and the file is unrecoverable. There is no recovery flow, because we do not hold the password either.

Verifying a download

Check what you install, before you install it

Every platform is signed. On Linux the signature is ours to publish, so the key and its fingerprint are here.

macOS
The application is signed and the disk image is notarized by Apple, so Gatekeeper checks it at first launch. No PKG is produced.
Windows
The MSIX package, the Setup.exe and every executable and library inside them carry an Authenticode signature. A ZIP cannot carry one, so what counts there is the signature on the executable inside. The one exception is the uninstaller Inno Setup writes beside an installed app.
Linux
The DEB, RPM and AppImage each ship with a detached GPG signature, alongside a SHA256SUMS manifest that is signed as well.

Release-key fingerprint

Cross-check this fingerprint against any imported copy of the key. If your copy prints a different one, do not install, and write to security@edgely.io.

F2BE 8279 C289 AA71 541A  767E 3B5A 5104 FB7A C7B0
UID
Edgely Release Signing <releases@edgely.io>
Algorithm
RSA 4096
Expires
2028-05-02

Import it once

curl -fsSL https://edgely.io/content/keys/edgely-release-signing.asc | gpg --import

Then verify before installing

DEB, detached signature
gpg --verify <file>.deb.asc <file>.deb
RPM, detached signature
gpg --verify <file>.rpm.asc <file>.rpm
AppImage, detached signature
gpg --verify <file>.AppImage.asc <file>.AppImage

Hosting and operator

Who runs this, and where

One company, one jurisdiction, and an infrastructure with no public entry point of its own.

Publisher
SIGEAD SRL
Legal form
Société à responsabilité limitée (SRL), incorporated in Belgium
Registered office
Avenue Pasteur 6H, 1300 Wavre, Belgium
Enterprise number
BCE/KBO 1014.169.345
VAT number
BE 1014.169.345
Contact
contact@edgely.io
Hosting
OVH infrastructure operated inside the European Union
Public entry point
Cloudflare only. The host publishes no HTTP port of its own
Applicable law
Belgian law, courts of Brussels

Your account data is processed in the European Union, where the GDPR applies by default. Where data is transferred outside the European Economic Area, the GDPR Policy states the mechanism we rely on.

Full legal notice →

Privacy policy

Data we hold, and why

An account exists to carry your licence and to sync your setup. Nothing else about the software requires one.

Account Email address, licence state, the devices you linked
To sign you in, to know which tier applies and to let you manage your own devices. Nothing is sold or rented.
Sync Connection metadata
Hostnames, ports, groups and preferences, so your setup follows you across your devices. No secrets.
Billing Invoice details, through our payment processor
Invoicing and VAT are a legal obligation, and tax law sets how long the records are kept.
Never collected Session contents, file contents, queries
They stay between your machine and your servers. We have no copy, and the applications report nothing about how you use them.

Under the GDPR you may ask for access, correction, export, restriction, objection or deletion at any time, by writing to contact@edgely.io. Your vault is out of scope for those requests for the one reason that matters: there is nothing on our side to export or erase.

You can delete your account from the application or by email, either after 30 days, cancellable with one click from the message we send you, or immediately with no undo. Deleting it removes the synced metadata; your local vaults are untouched, because we never held their keys.

Terms of service

Licence in plain terms

A summary for orientation. The documents themselves are what binds either of us.

Personal use is free
Console and Database Manager are complete and free for personal use, students and teachers included. Guard and Transfer are free with their core features.
Commercial use needs a licence
Using Edgely at work requires a paid plan, per user, or per seat for an organization.
Cancel at any time
Cancellation takes effect at the end of the current paid period, and you keep access until then.
Statutory withdrawal stands
Where it applies, the 14-day right of withdrawal for consumers in the European Union is untouched by our terms.
Your data is yours
What you connect to, transfer or query never reaches us, and you keep ownership of anything you send us through support or feedback.

Legal documents

Every document, in six languages

Each one is versioned, dated and served in the language you read the site in.

Questions about any of this?

Procurement reviews, data-protection questionnaires and architecture questions go through the contact form. Suspected vulnerabilities go to security@edgely.io.

Product names, logos and brands mentioned on this page are the property of their respective owners. They are used for identification and comparison only, and their use does not imply any affiliation with or endorsement by them.