One native macOS app for SSH, SFTP, FTP and Telnet. Your hosts, passwords and SSH keys stay in an encrypted file on your Mac, and optional Swiss-hosted sync carries that same file to your second Mac — we never hold the password that opens it.
No more switching between iTerm + Cyberduck + 1Password. ILYGO Hawser handles SSH, SFTP, FTP, Telnet, plus your credentials, in one native binary.
Open a shell from the host list in one click. The SSH engine is native and reconnects on its own when the link drops. Your start-up snippets run as soon as the shell opens.
Browse the remote tree, create, rename and delete, and move files both ways with a progress bar. Drop files straight from the Finder onto the remote pane; local and remote sit side by side in the same tab.
Hosts, passwords and SSH keys live in a single .ivault file whose location you choose — nothing scattered, no plaintext config. AES-256-GCM at rest, Argon2id from your master password. None of it needs the cloud.
Optional, and idle until you create an account. After every save your Mac uploads the encrypted file to Swiss servers; opening it on your second Mac downloads it back. We store the ciphertext and a count of items for the quota — never your password, never your hosts in the clear.
Before writing your vault, Hawser copies the previous encrypted version into a folder outside the vault’s own, so a third-party sync tool cannot take both down. The 5 most recent copies are kept; you reopen one from the Finder if you ever need it.
From an open SSH tab, one click shows the server load, disk and memory, the Docker stack, or your Kubernetes nodes and pods. Hawser runs the commands over the same connection and lays out the result; the raw output stays one click away.
Real screenshots of the current build.
Every host you administer in one searchable list, grouped as you like, with a dot showing what answers right now. One click opens a shell or a file browser.
Create an account, create a cloud vault, and every save uploads it encrypted. Open that same vault on your second Mac to pick up where you left off — one Mac at a time. 2 items free, 500 with Pro.
Step away and the vault closes itself. Choose the idle delay (1 minute to 1 hour, or never), follow the countdown in the top bar, and get a 60-second warning with the option to stay. ⌘L closes it right away.
Four articles built into the app — first host, the encrypted vault, shortcuts, connection troubleshooting. Nothing is fetched from the network.
The desktop app stays free. Cloud sync starts at 10 items, Pro lifts that ceiling to 100,000, and Enterprise — still in preparation — will add vaults shared between several people.
Included in every plan, free accounts too: Swiss hosting, two-factor authentication on your account (enabled from your account page on the web), and the last 100 uploads of your vault kept server-side.
Quotas indicative — final pricing may evolve before public release. Two technical caps apply to every plan alike: 10 MB per uploaded file, 64 KB average per item.
ILYGO Hawser is designed under a strict threat model: the server is hostile, your laptop may be lost, and credentials must survive both.
Your master key never leaves your Mac. What the server receives is the AES-256-GCM encrypted file plus a count of items for the quota. Even with full access to it, an attacker gets blobs he cannot open.
Stealing your sync account password lets an attacker download your ciphertext. Without the (separate) vault password, it stays unreadable.
On your Mac, the encrypted versions written before your last 5 saves are kept in a separate folder — you reopen one from the Finder. On the server, your last 100 uploads are kept; restoring one of those is done with us, at hawser@ilygo.ch.
One .ivault file: copy it to a backup disk, carry it to another Mac, keep it wherever you like. The format is shared across the ILYGO suite, and your hosts export as a standard OpenSSH config.
The first time you reach a server, Hawser shows its SHA256 fingerprint and asks you to trust it once or for good. If that fingerprint later changes, the connection is refused outright — there is no button to click through.
A real macOS app, no Electron. Encryption uses AES-256-GCM and Argon2id, two standards that have been under public scrutiny for years. When the vault closes (⌘L or auto-lock), the decrypted contents leave memory.
Four differences you can check yourself, on the first day.
Your hosts, SSH keys and passwords live in a single encrypted .ivault file, wherever you put it. You copy it, back it up and move it like any other file.
Sync is optional. The server receives the encrypted file and a count of items for your quota — never your master password, which does not leave your Mac.
SSH, SFTP, FTP and Telnet share the same tabs and the same vault.
Published by ILYGO Sàrl and hosted in Switzerland. The app works entirely offline.
Native binaries are in the works. The desktop app will be free; cloud sync is optional and starts free with 2 items — just a taste.