Security and data handling
Zero telemetry
No credentials in sync
EU operator
How Edgely handles your data
The short version: your credentials are encrypted with keys we never hold, sync carries connection metadata only, and there is no telemetry to opt out of.
Security and data handling
What leaves your machine, and what doesn't
Stated as commitments you can check in the product, not assurances you have to take on faith.
-
Zero-knowledge vault
- Passwords, SSH private keys and API tokens are encrypted on your device with AES-256-GCM. We cannot decrypt them, because we never hold the key.
-
Two ways to unlock it
- A master password, from which Argon2id derives the vault key, or a device-only 256-bit key kept in the OS keychain. Each application gets its own keychain entry, and switching between the two re-encrypts every entry in one operation.
-
No credentials in sync
- Sync carries connection metadata only: hostnames, ports, usernames, groups, preferences. A credential cannot reach our database, and the server rejects any item that looks like one.
-
Encrypted exports
- Credentials move between your devices through a password-protected file you create and import yourself. The password is at least 12 characters, it never leaves your device, and there is no recovery flow.
-
Zero telemetry
- No usage counters, no session tracking, no crash or error reports. Diagnostic logs stay in a folder on your own device. There is no setting to switch off because there is nothing to collect.
-
Signed installers
- The macOS disk image is signed and notarized, the Windows installers and the binaries inside them carry an Authenticode signature, and every Linux package ships with a GPG signature and a signed SHA256SUMS file.
Cross-device sync
What gets synced, and what never does
An account exists to carry your licence and to sync your setup between your own devices. That list is the whole list: there is no advanced option that syncs more.
Synced to your account
-
·
Connection metadata: hostnames, ports, usernames, protocol settings
-
·
Groups: the folder structure you organize your entries in
-
·
Preferences: theme, locale, layout, default protocols
-
·
Bookmarks: the items you pinned
-
·
Snippets: the commands you saved
-
·
Custom data: plugin items that opt into sync
Never synced
-
·
Passwords for any saved connection
-
·
SSH private keys and their passphrases
-
·
API tokens, OAuth tokens, bearer tokens
-
·
Client secrets, AWS access keys and session tokens
-
·
Anything stored in your local credentials vault
Enforced on the server
The desktop apps strip credentials from every payload they produce, and the portal checks again independently. Forbidden key namespaces, a denylist of credential field names walked through the whole payload, and a missing integrity signature each answer 422 and are counted on the admin dashboard, so a misbehaving client is visible rather than silent.
Organization-shared connections are readable by us
A connection shared with an organization is stored so the server can apply membership, which is what makes removing a member remove their access at once. It is not end-to-end encrypted, unlike your personal entries. It still carries no credential: host, port and username travel, and every member supplies their own password from their own vault.
Moving credentials
How to move credentials between devices
There is no server-side path for this on purpose. The file is the path, and you hold its password.
-
1
Export on the source device
Open the desktop app, then Settings, then Export.
-
2
Choose what to take, and set a password
Vault for credentials only, Full backup for everything, Connections for connections with their credentials. The encryption password is at least 12 characters and is independent of your vault password.
-
3
Move the file yourself
USB drive, secure file share, encrypted email, your own cloud folder. The file is encrypted, so what matters is that you protect the password.
-
4
Import on the target device
Settings, then Import, then supply the password.
File formats
.evlt
.efull
.econ
.eset
Lose the password and the file is unrecoverable. There is no recovery flow, because we do not hold the password either.
Verifying a download
Check what you install, before you install it
Every platform is signed. On Linux the signature is ours to publish, so the key and its fingerprint are here.
-
macOS
- The application is signed and the disk image is notarized by Apple, so Gatekeeper checks it at first launch. No PKG is produced.
-
Windows
- The MSIX package, the Setup.exe and every executable and library inside them carry an Authenticode signature. A ZIP cannot carry one, so what counts there is the signature on the executable inside. The one exception is the uninstaller Inno Setup writes beside an installed app.
-
Linux
- The DEB, RPM and AppImage each ship with a detached GPG signature, alongside a SHA256SUMS manifest that is signed as well.
Release-key fingerprint
Cross-check this fingerprint against any imported copy of the key. If your copy prints a different one, do not install, and write to security@edgely.io.
F2BE 8279 C289 AA71 541A 767E 3B5A 5104 FB7A C7B0
- UID
-
Edgely Release Signing <releases@edgely.io>
- Algorithm
- RSA 4096
- Expires
- 2028-05-02
Import it once
curl -fsSL https://edgely.io/content/keys/edgely-release-signing.asc | gpg --import
Then verify before installing
- DEB, detached signature
-
gpg --verify <file>.deb.asc <file>.deb
- RPM, detached signature
-
gpg --verify <file>.rpm.asc <file>.rpm
- AppImage, detached signature
-
gpg --verify <file>.AppImage.asc <file>.AppImage
Hosting and operator
Who runs this, and where
One company, one jurisdiction, and an infrastructure with no public entry point of its own.
- Publisher
- SIGEAD SRL
- Legal form
- Société à responsabilité limitée (SRL), incorporated in Belgium
- Registered office
- Avenue Pasteur 6H, 1300 Wavre, Belgium
- Enterprise number
- BCE/KBO 1014.169.345
- VAT number
- BE 1014.169.345
- Contact
- contact@edgely.io
- Hosting
- OVH infrastructure operated inside the European Union
- Public entry point
- Cloudflare only. The host publishes no HTTP port of its own
- Applicable law
- Belgian law, courts of Brussels
Your account data is processed in the European Union, where the GDPR applies by default. Where data is transferred outside the European Economic Area, the GDPR Policy states the mechanism we rely on.
Full legal notice →
Privacy policy
Data we hold, and why
An account exists to carry your licence and to sync your setup. Nothing else about the software requires one.
-
Account
Email address, licence state, the devices you linked
- To sign you in, to know which tier applies and to let you manage your own devices. Nothing is sold or rented.
-
Sync
Connection metadata
- Hostnames, ports, groups and preferences, so your setup follows you across your devices. No secrets.
-
Billing
Invoice details, through our payment processor
- Invoicing and VAT are a legal obligation, and tax law sets how long the records are kept.
-
Never collected
Session contents, file contents, queries
- They stay between your machine and your servers. We have no copy, and the applications report nothing about how you use them.
Under the GDPR you may ask for access, correction, export, restriction, objection or deletion at any time, by writing to contact@edgely.io. Your vault is out of scope for those requests for the one reason that matters: there is nothing on our side to export or erase.
You can delete your account from the application or by email, either after 30 days, cancellable with one click from the message we send you, or immediately with no undo. Deleting it removes the synced metadata; your local vaults are untouched, because we never held their keys.
Terms of service
Licence in plain terms
A summary for orientation. The documents themselves are what binds either of us.
-
Personal use is free
- Console and Database Manager are complete and free for personal use, students and teachers included. Guard and Transfer are free with their core features.
-
Commercial use needs a licence
- Using Edgely at work requires a paid plan, per user, or per seat for an organization.
-
Cancel at any time
- Cancellation takes effect at the end of the current paid period, and you keep access until then.
-
Statutory withdrawal stands
- Where it applies, the 14-day right of withdrawal for consumers in the European Union is untouched by our terms.
-
Your data is yours
- What you connect to, transfer or query never reaches us, and you keep ownership of anything you send us through support or feedback.
Legal documents
Every document, in six languages
Each one is versioned, dated and served in the language you read the site in.
Questions about any of this?
Procurement reviews, data-protection questionnaires and architecture questions go through the contact form. Suspected vulnerabilities go to security@edgely.io.
Product names, logos and brands mentioned on this page are the property of their respective owners. They are used for identification and comparison only, and their use does not imply any affiliation with or endorsement by them.