Security

How noxed protects your servers and credentials

noxed holds the keys to your infrastructure, so it's built to keep secrets out of files, keep data on your machine, and treat its own UI as untrusted.

Where your data is stored

DataWhere it lives
Passwords and other secretsYour OS keychain: macOS Keychain, Windows Credential Manager, or libsecret on Linux. Never written to a config file.
Connection details (host, port, username, key path)A local settings file in noxed's app-data folder on your computer.
SSH private keysStay where they already are. noxed stores the path and reads the key only when connecting.

No accounts, no cloud, no telemetry

noxed has no sign-in, no sync service and no analytics in the app. It connects only to the servers, databases and clusters you configure. The one other request is the update check: installed builds ask GitHub Releases whether a new version exists when they start, and nothing is downloaded until you agree.

SSH host key verification

noxed checks every SSH server's host key before sending credentials. Keys you already trust in ~/.ssh/known_hosts (hashed entries included) are accepted automatically. A host noxed hasn't seen before shows its SHA256 fingerprint for you to confirm. If a trusted host presents a different key, noxed warns you and won't connect unless you choose to replace the key. You can review and remove trusted keys under Settings → Security → Known Hosts.

Claude Code access (MCP)

Off unless you turn it on. When it's on, noxed runs an MCP server that listens only on 127.0.0.1 and requires a random token kept in your OS keychain. It also rejects requests that come through a web page. Claude Code never sees your passwords or keys: commands run over the connections noxed already holds. Every command and file read waits for your approval in noxed, and a short list of destructive commands (such as rm -rf /, mkfs and shutdown) is always refused. While noxed is locked, every request is refused. Issuing a new token in Settings cuts off clients that used the old one.

Lock screen

An optional lock screen protects saved credentials with Touch ID, a PIN or a password. It can lock automatically after a period of inactivity. While noxed is locked, secrets aren't released to the interface.

Restricted file access

SSH keys are only read from ~/.ssh, ~/.config/ssh and ~/.pem. Kubeconfigs are only read from ~/.kube and standard config folders, plus files you explicitly import. A compromised UI can't ask the app to read arbitrary files.

Sandboxed, untrusted UI

noxed is an Electron app with a sandboxed, context-isolated renderer. All system access (SSH, SFTP, databases, Kubernetes, keychain) lives in the main process, behind handlers that validate every input. They also check that a window only uses connections it opened.

Guard rails

Signed releases and open source

macOS builds are signed with an Apple Developer ID and notarized, and Windows installers are code-signed. All the source code is on GitHub under the MIT license, so you can audit it or build it yourself.

Reporting a security issue

If you find a vulnerability, please open an issue on GitHub without exploit details, and the maintainer will follow up.