The SSH client
that doesn't leak your keys.

One native macOS app for SSH, SFTP, FTP and Telnet. Sign in and subscribe with Apple. Your hosts, passwords and SSH keys are kept in encrypted cloud vaults hosted in Switzerland.

macOS 12+ · Apple Silicon and Intel · Interface in French and English

ILYGO Hawser — the connections hub, hosts grouped by environment
The connections hub — a real screenshot of the current build.
Native
Native SSH engine — no Electron, no bundled browser
0 keys
leave your device — the server stores your encrypted file, never the password
100
versions of your encrypted vault kept on the server
🇨🇭
Sync hosted in Switzerland · ILYGO operated
Features

One client. All your protocols.

No more switching between iTerm + Cyberduck + 1Password. ILYGO Hawser handles SSH, SFTP, FTP, Telnet, plus your credentials, in one native binary.

SSH in one click

Open a shell from the host list in one click. The SSH engine is native and reconnects on its own when the link drops. Your start-up snippets run as soon as the shell opens.

SFTP, FTP & Telnet

Browse the remote tree, create, rename and delete, and move files both ways with a progress bar. Drop files straight from the Finder onto the remote pane; local and remote sit side by side in the same tab.

Everything in one encrypted file

Hosts, passwords and SSH keys are encrypted on your Mac before cloud sync. AES-256-GCM protects the vault; Argon2id derives the key from your master password.

Zero-knowledge sync

Your Mac encrypts vaults before uploading them to Swiss servers. Sign in with Apple on another Mac to find your vaults, then unlock them with your master password.

A copy before every save

Before writing your vault, Hawser copies the previous encrypted version into a folder outside the vault’s own, so a third-party sync tool cannot take both down. The 5 most recent copies are kept; you reopen one from the Finder if you ever need it.

Dashboards instead of commands

From an open SSH tab, one click shows the server load, disk and memory, the Docker stack, or your Kubernetes nodes and pods. Hawser runs the commands over the same connection and lays out the result; the raw output stays one click away.

The app

A glimpse

Real screenshots of the current build.

ILYGO Hawser connections hub

Connections hub

Every host you administer in one searchable list, grouped as you like, with a dot showing what answers right now. One click opens a shell or a file browser.

ILYGO Hawser cloud account

Cloud account

Sign in with Apple to access your encrypted cloud vaults. Your vault password remains on your device.

ILYGO Hawser security settings

Auto-lock

Step away and the vault closes itself. Choose the idle delay (1 minute to 1 hour, or never), follow the countdown in the top bar, and get a 60-second warning with the option to stay. ⌘L closes it right away.

ILYGO Hawser in-app help

In-app help

The complete manual, built into the app and readable offline — every screen, every setting, and what this version does not do yet. Each view opens with a short help box pointing to the right page.

Pricing

One app. One monthly subscription.

CHF 4 per month in Switzerland, billed by Apple. Apple sign-in and encrypted cloud vaults are included.

Already a customer? Manage your previous Hawser account.

Security

Your secrets stay on your Mac.

ILYGO Hawser is designed under a strict threat model: the server is hostile, your laptop may be lost, and credentials must survive both.

The server can't read your vault.

Your master key never leaves your Mac. What the server receives is the AES-256-GCM encrypted file plus a count of items for the quota. Even with full access to it, an attacker gets blobs he cannot open.

Account compromise ≠ vault compromise.

Stealing your sync account password lets an attacker download your ciphertext. Without the (separate) vault password, it stays unreadable.

Two safety nets, and what each one does.

On your Mac, the encrypted versions written before your last 5 saves are kept in a separate folder — you reopen one from the Finder. On the server, your last 100 uploads are kept; restoring one of those is done with us, at hawser@ilygo.ch.

Your vault is a file you own.

Export an encrypted .ivault backup to a disk you control. Import it into the cloud when needed. Your hosts can also be exported as a standard OpenSSH configuration.

A changed host key stops the connection.

The first time you reach a server, Hawser shows its SHA256 fingerprint and asks you to trust it once or for good. If that fingerprint later changes, the connection is refused outright — there is no button to click through.

Native code, and memory that gets cleared.

A real macOS app, no Electron. Encryption uses AES-256-GCM and Argon2id, two standards that have been under public scrutiny for years. When the vault closes (⌘L or auto-lock), the decrypted contents leave memory.

In practice

What actually changes for you

Four differences you can check yourself, on the first day.

One file, and it is yours

Your cloud vaults remain yours. Export an encrypted .ivault backup and keep it wherever you choose. Import an existing backup into your cloud vault list.

The server never holds the key

Your cloud vaults are encrypted on your Mac. The server receives the encrypted file and quota counters, never your master password. Apple and ILYGO cannot reset that password.

Four protocols, one window

SSH, SFTP, FTP and Telnet share the same tabs and the same vault.

Swiss from code to hosting

Published by ILYGO Sàrl and hosted in Switzerland. The app works entirely offline.

Downloads open soon.

Hawser is being prepared for the Mac App Store. Free download, with a monthly subscription for active features. No annual commitment.

macOS Universal Soon Windows Soon Linux Soon

Want early access? Drop us a line.