Security & data

Privacy and trust boundaries

Understand what encryption protects, who handles usable data, and what a secure connection cannot promise.

3 min read User guide

Start with the connection you actually use

OmniTerm has several workflows, not one universal privacy boundary. A direct native SSH connection, a client-to-agent relay tunnel, a Gateway-hosted session, an encrypted vault and a shared terminal protect different information between different parties.

The useful question is not simply whether encryption exists. Ask where usable data appears, which machine handles it, and who operates that machine.

Who can handle what?

Workflow Important boundary
Direct native SSH Your device and destination handle the session. Verify the destination's identity and protect both endpoints.
Native protected relay tunnel The forwarding relay carries encrypted traffic. Routing metadata, timing and volume remain visible to service operators.
Gateway-hosted protocol session The Gateway handles the remote protocol and can hold decrypted session data and credentials in memory. It is a trusted endpoint.
Encrypted vault Stored information needs the appropriate unlock or recovery authority. Usable data is available to the unlocked client while you work.
Live terminal sharing Invited participants receive usable output. Encryption does not prevent an authorized viewer from copying it.
Delegated server access A trusted enrolled agent holds an encrypted target credential and uses it to open authorized sessions.
AI or connected assistants The selected provider or assistant can receive the information and permissions you give it. Review that relationship separately.

A statement about an encrypted forwarding relay must not be applied to a protocol-handling Gateway. Read how relay works before selecting a route for sensitive work.

Local storage is a choice with consequences

Local workstation data, an enrolled local vault and a hosted cloud workspace have different behavior. The hosted workspace does not offer a general offline-mode switch. Signing in does not automatically migrate a local vault to cloud storage. Cloud-only mode does not mean the browser never holds usable data in memory, nor does it erase downloads, screenshots or clipboard history.

Read cloud and offline data before working on a shared device. Lock the workspace when finished and protect the operating-system account as well as the vault.

Metadata and diagnostics still matter

Authentication, routing, usage accounting and service operation can involve identifiers and connection metadata. Optional product-usage telemetry is a different choice from the information required to operate an authenticated connection. Review available telemetry controls rather than assuming that a preference removes every operational record.

Do not infer a fixed retention period, certification or independent audit from the presence of encryption. This guide does not make those claims. Review the applicable service terms and ask the operator about requirements specific to your organization.

Your practical safety checklist

Verify new and changed server identities. Keep device and server software maintained. Store recovery material separately. Give viewers and assistants only the access they need. Review output before sharing it, and check the outcome of revocation rather than assuming instant cutoff.

Encryption cannot undo commands, retract copied information, prevent every service outage, or protect an unlocked session from a compromised endpoint. For concrete steps, continue with vaults, recovery and connected assistants.

Features vary by release, platform and connection route. Check availability before planning your setup.

Search the guides

Search runs in your browser.

Your search stays here. No account or external search service.