Your credentials never leave your machine
Darang is a desktop application. Connection secrets are encrypted locally, unlocked with a key from your OS keychain, and — unless you choose otherwise — never sent anywhere.
Local, zero-knowledge encryption
AES-256-GCMConnection passwords, SSH keys, and SSL certificates are encrypted on your machine with AES-256-GCM before they are written to disk or synced. The plaintext never leaves your device.
Keys live in your OS keychain
OS KeychainThe master key that unlocks your encrypted store is held in the operating system credential vault — Keychain on macOS, Credential Manager on Windows, libsecret on Linux — not in a Darang config file.
Offline-first by design
Local SQLiteDocuments, query history, notebook outputs, and schema caches are stored in a local SQLite database, so the app keeps working with no network connection.
Cloud sync stores only ciphertext
Opt-inIf you opt in to cloud sync, the server receives the already-encrypted credential payload. It cannot decrypt your connection secrets — only your desktop client can.
Connecting to your databases
- SSL / TLS connections with configurable verification modes (PostgreSQL sslmode, MySQL TLS)
- SSH tunnelling for databases that are not directly reachable
- Credentials are decrypted only inside the desktop client process, never in the UI layer
- Database drivers run in an isolated worker process, separate from the renderer
The AI assistant is opt-in and permissioned
- Bring your own API key, or run entirely local with Ollama / LM Studio — no AI traffic is proxied through Darang
- Per-domain tool permissions: turn off Schema Builder, Connections, Export, and more individually
- When the assistant runs a query on its own to check data, it is restricted to a single row-limited read-only SELECT
- Any statement that writes data or changes schema is shown to you as a proposed action and needs explicit approval
- AI conversations and remembered schema context are stored locally, not on a server
Reporting a vulnerability
If you believe you've found a security issue in Darang, please report it privately through a GitHub Security Advisory on the releases repository rather than opening a public issue. We aim to acknowledge reports within a few days.