Staying safe and keeping backups

What is protected

Everything the app stores is encrypted on your computer. Without your master password it is unreadable. Nothing is sent to us or to any cloud.

Locking

Press Ctrl+Shift+L or the lock icon. The app also locks by itself after some minutes of inactivity, when your screen locks, and when the computer goes to sleep (adjust under Settings → General).

To skip typing the password on your own private computer, Settings → Security → Unlock with the system keyring. Do not turn it on for a computer others can use.

Production servers

Mark a live server as Production. It then shows a red bar in the terminal. Dangerous actions — recursive delete, formatting a disk, dropping a database, stopping SSH — ask you to type the server's name before they go through. This protects you from the classic mistake of running a command on the wrong machine.

Activity log

Every important action (a command run, a service restarted, a file sent) is written to a tamper-evident log under Settings. You can check and export it.

Backups

One .krbackup file contains everything — clients, servers, notes, commands, passwords — encrypted with a backup password you choose. It is both your backup and your way to move to a new computer.

  • Manual: Settings → Backup → type a backup password → Save backup…. The app reads the file back to be sure it opens.
  • Automatic: switch on Automatic backup. Choose how often (default every 24 hours) and how many copies to keep (default 7). Pick a folder on another disk or one that syncs elsewhere; a copy beside the original does not survive a failed disk.
  • Restore: on a fresh installation choose Restore from backup, pick the file, type its password.

Write down your backup password somewhere other than this computer. Without it a backup cannot be opened.

Sharing one client without secrets

On a client page Export creates a .krclient file with servers, notes and commands but no passwords or keys — good for handing a setup to a colleague, who adds their own logins.

USB stick

The portable edition runs from a USB stick and leaves nothing on the computer you borrow.

  1. Format the stick as exFAT (or ext4). FAT32 will not work.
  2. Unpack the portable archive onto the stick: tar -xzf KultivatRemote-<version>-linux-portable.tar.gz -C /media/$USER/<stick>.
  3. Open the KultivatRemote folder on the stick and run bash start.sh.

The header shows PORTABLE. Data on the stick is encrypted like the installed version, so a lost stick is unreadable without your master password. Close the app before you pull the stick out. Still keep a backup off the stick.