Trust & Security
Security is not just a feature
CloudCMD holds your SSH keys and cloud credentials — you deserve to know exactly how that works. Only you should have the keys required to decrypt your vault. Even we can't see what's in it. We can't use, lose, or abuse data that we don't have.
We are open and explicit about the design — transparent to the point of being annoying. That is intentional.
Privacy & Data
What lives in your workspace, what leaves, how secrets are encrypted, and how Google / cloud credentials are handled.
How access works
Vault unlock, process isolation, account-scoped sync, and who can touch your data.
Security best practices
Practical tips for master passwords, credentials, AI prompts, and device hygiene.
Report a vulnerability
Email security@cloudcmd.com or help@cloudcmd.com. Please give us a reasonable window to fix before public disclosure.