3.0 PREVIEW

Notice: GETSSH 3.0 PREVIEW is scheduled for release around October 10, 2026. Capabilities marked as "Coming soon" will be available for early access in this milestone.

Cross-Platform SSH Terminal · Ops Agent · BYOK

A solid, dependable SSH terminal,
and an intelligent ops copilot

Coming soon

A modern cross-platform terminal engineered for production ops. Featuring isolated session processes, fluid multi-display pane tear-offs, and OS keychain credential storage. When configured with your own model keys, it assists in multi-step diagnostics and fleet operations under human verification and strict security boundaries.

macOS 13+ · Windows 11+ · Ubuntu 22.04+ · Apache-2.0

0Deeply adapted models
∞Split panes
0 layersRuntime defense
agent · 3 hosts · deepseekAgent mode
production-web-01SSH
db-primarySSH
legacy-switch-03TELNET
The terminal itself

Pure, Solid Terminal CoreComing soon

Every split pane runs in its own isolated process without interference. The connection engine is deeply compatible with modern Linux distributions as well as legacy network equipment. Backpressure-optimized streaming keeps long-running, high-throughput log inspection fluid and responsive.

Multi-pane splitting and cross-screen detachment NEXUS CORE

Panes can be detached from the main window and seamlessly hot-plugged across external displays, preserving runtime state and connection contexts.

Multi-Environment Workspaces WORKSPACES

Organize servers into dedicated workspaces (Production, Staging, HomeLab). Assets, active sessions, and split layouts remain strictly isolated with one-click fluid switching.

Built-In Visual SFTP Manager INTEGRATED SFTP

No need for external tools like FileZilla or WinSCP. Integrated visual SFTP drawer offers drag-and-drop transfers, streaming backpressure, and inline remote editing.

Streaming I/O & Memory Safety STREAM I/O

Engineered with stream-based backpressure and memory safeguards to prevent runaway memory usage during large-scale log output and high-volume transfers, maintaining long-term stability.

All protocols, auto-detected SSH · TELNET · SFTP

Enter ssh://, telnet://, or directly user@host. The intelligent parser identifies the protocol in milliseconds and establishes the tunnel without tedious form setup.

OS-level key store OS KEYCHAIN

SSH private keys and login credentials are held by macOS Keychain or Windows Credential Manager, encrypted with hardware-accelerated AES-256-GCM. Nothing plaintext touches disk.

connect ❯
SSH Engineup
Telnet Engineup
SFTP Engineup
Decoupled Tier Architecture

Built on a decoupled architecture: a modern desktop shell powers fluid UI interactions, a mature connection engine guarantees device compatibility, and Rust native modules handle keychain encryption and watchdog monitoring, with all persistent data held locally.

Explore cross-section
Command Center

Command paletteComing soon

Fuzzy matching powered by Fuse.js — instantly summon server fleets, cryptographic credentials, and automation scripts. Execute actions directly from the side panel.

Windows / Linux: Ctrl K
↑↓ Select↵ Runesc Close
03 / ARCHITECTURE

Power. Speed. Control.Coming soon

Engineered for high-frequency infrastructure operations. Native low-level architecture built to eliminate bloat and UI latency.

Nexus Rendering Core

Native multiplexing event loop ensures silky-smooth rendering even under heavy, bursty terminal log streams.

sub-5ms Latency

Dynamic Backpressure

Self-tuning circular ring buffer ensures memory footprint remains bounded even during high-throughput log dumps.

Zero Memory Leak

OS Keychain Hardware Binding

Private keys and host credentials bind directly to macOS Keychain or Linux Secret Service with hardware encryption.

Hardware Secure Enclave

Native Dual-Pane Streamed SFTP

Integrated dual-pane browser with drag-and-drop transfers, resumable uploads, and inline preview.

Integrated Dual-Pane

Zero-Telemetry Offline Boundary

Runs completely air-gapped. Zero tracking of server hostnames, key hashes, or terminal commands.

100% Offline Safe

Ops Diagnostic Guard

Generates safe, reviewable diff patches when terminal errors occur, strictly gated by human verification.

Operator in Control
Why GETSSH

Why Choose GETSSH?Coming soon

In production environments, terminal connection stability, data privacy, and pane ergonomics dictate troubleshooting velocity. Here is how GETSSH compares directly against PuTTY, Tabby, and Termius:

DimensionPuTTYTabbyTermiusGETSSH
Multi-Pane & Window DetachmentNo split panes or tabs; each session opens an isolated Win32 window, quickly cluttering the desktopSupports basic tabs and split grids, but detaching to a new window reloads the sessionSupports tabs and panes, but window splits are constrained and cannot cleanly detach across displays
Multi-Display Detachment
Infinite binary-tree pane splits; physically tear off any pane to an external display without dropping the SSH session
Workspace & Fleet IsolationNo workspace concept; all saved hosts live in a flat list inside the Windows RegistrySingle-tier profile list; lacks dedicated physical isolation across prod, staging, and clustersSupports basic grouping, but host assets are tied to its commercial cloud synchronization
Workspaces Fleet Isolation
Native Workspaces isolation; switch between production, staging, and lab fleets in one click
Data Privacy & Cloud EgressStrictly local storage; zero telemetry and zero cloud dependencyLocal config by default; supports optional self-hosted WebDAV sync without mandatory cloudMandatory account registration; host IPs, tags, and metadata default to sync to commercial cloud
Zero Data Egress
100% local-first; zero telemetry, zero data egress, no forced account, and no cloud relays
Credential Vault & Hardware SecurityRelies on external Pageant; requires proprietary .ppk conversion; lacks OS secure enclavesRelies on generic master passwords or plaintext configs; lacks OS hardware-backed keychainProprietary cloud encryption scheme; credential retrieval depends on its proprietary backend
OS Keychain + Hardware AES
Native OS Keychain (macOS Keychain / Windows Credential Manager) with hardware AES-256-GCM
Log Throughput & Memory DisciplineWin32 GDI rendering is fast, but lacks modern font smoothing, ligatures, and unicode symbolsPure Web rendering without backpressure control; heavy log streams bloat memory to 1GB+ and stutterSmooth for everyday tasks, but occasional frame drops during massive rapid error bursts
Stream Backpressure Guard
Isolated process scheduling + streaming backpressure pipeline; fluid during millions of log lines
Graphical File Transfer (SFTP)No visual SFTP; requires separate PSCP CLI or third-party WinSCP configurationBuilt-in basic SFTP plugin; large file transfers can occasionally block foreground terminal UIPolished visual SFTP, but locked behind a paid commercial subscription (gated in free tier)
Integrated Free Streaming SFTP
Built-in visual streaming SFTP drawer; drag-and-drop transfers, completely free out of the box
Licensing & PricingOpen source (MIT), but interaction and user experience remain rooted in the 1990sOpen source (GNU GPL v3)Proprietary subscription; core productivity features cost $10-$30/month (hundreds of dollars yearly)
Apache-2.0 Free & Open
Apache 2.0 open-source license; completely free for personal and commercial team use
Intelligent Ops & AI CopilotNo intelligent automation or AI capabilitiesRequires finding and maintaining third-party community extensions with fragmented experienceClosed-source cloud AI addon requiring recurring monthly fees or cloud token purchases
BYOK Ops Copilot
Native decoupled ops copilot; BYOK support; destructive mutations gated by strict human confirmation
Terminal & Copilot

Native Terminal & Ops CopilotComing soon

Keep daily operations lightweight and distraction-free with native terminal execution and real-time command guard; summon the Agent Ops Copilot during complex incidents to orchestrate multi-step workflows under strict human approval.

production-db-primary · Native TerminalTerminal
What it does

Typical scenariosComing soon

Spans from single-command semantic explanation to cross-host rolling deployments. The Agent orchestrates task sequences, executes across nodes progressively, and produces structured audit reports.

Log triage and root cause

Describe incidents in natural language and the Agent automatically inspects error.log, correlating database transactions with system telemetry, delivering root-cause conclusions with evidence line numbers—no manual log triage required.

Batch and rolling execution

Broadcast commands across host clusters with ease. Production environments automatically trigger rolling rollouts with pre-flight configuration checks, immediately halting on any anomaly for human review.

Config and script generation

Accurately parses infrastructure intent to generate production-ready systemd units, Nginx configs, and deployment manifests. Full Diff previews are required before landing on disk.

Dangerous command interception

Commands like rm -rf /var/* are proactively intercepted before execution, assessing potential blast radius and recommending safe alternatives with --dry-run included.

Handover and postmortems

Ingest session transcripts to generate comprehensive postmortem drafts featuring chronological timelines, blast-radius assessments, and remediation checklists ready for incident archives.

Plain language to commands

No need to memorize journalctl flags. Simply describe the query goal to synthesize compliant, accurate commands, ready to dispatch upon confirmation.

Per-model adaptation

Eight primary models, dedicated adaptationComing soon

Function calling schemas, payload structures, and streaming conventions vary widely across providers. Generic wrappers fail to deliver reliability. GETSSH provides dedicated low-level adaptation acrosspayload, interface, and instruction layersfor eight leading foundation models, with universal fallback for standard endpoints.

Generic vs custom adaptation

Boundary

Execution boundaries and securityComing soon

Model API keys reside in OS-level secure enclaves. Agents execute within isolated sandboxes, and every write mutation requires explicit human confirmation. Backed by six independent runtime defense layers.

SHIELD ENFORCED · HARD BOUNDARY
LATENCY: <0.2ms
LAYER 01 // HUMAN-IN-THE-LOOP

Execution confirmation gate

Read-only discovery proceeds autonomously; any mutation enforces a mandatory human approval barrier. This boundary is enforced by the native engine and cannot be bypassed.

SECURITY TELEMETRY LOGENFORCED
14:23:01.102[AGENT_CORE]Discovery task initiated: Inspect system load & disk usage
14:23:01.320[AGENT_AST]Generated: df -h && uptime [READ_ONLY] -> PASSED
14:23:02.045[AGENT_MUT]Proposed write command: rm -rf /var/log/nginx/*.log
14:23:02.046[GATE_FILTER]>>> HARD BARRIER HIT: Destructive file mutation detected <<<
14:23:02.047[UI_MODAL]Execution blocked. Triggering interactive Human Approval Dialog...
FAQ

FAQComing soon

Frequently asked questions from the developer community. For deeper discussions or inquiries, join us on GitHub Issues.

How does GETSSH compare to traditional SSH clients?

First and foremost, GETSSH is a pure, dependable, and ergonomic SSH client. Its connection engine is deeply compatible with modern and legacy Linux distributions and network hardware, featuring isolated session processes, multi-screen pane detachment, and instant fuzzy search. Second, AI capabilities are completely modular—without any model keys configured, it remains a responsive, distraction-free modern terminal; when troubleshooting complex incidents, it acts as an in-situ copilot with rigorous human approval safeguards.

Does the AI access or collect my server data?

Strict zero-trust design. The Agent only accesses explicitly authorized context slices for the active turn—never scanning full session logs or touching the host filesystem. Full data manifests are reviewed before any payload leaves the client.

Does it work fully offline?

Core terminal capabilities are 100% offline. Network requests occur exclusively when communicating with your configured model endpoints. When paired with local Ollama or vLLM instances, operations run completely air-gapped.

Where are model API keys stored?

Credentials reside in OS-level secure enclaves (macOS Keychain / Windows Credential Manager) backed by AES-256-GCM hardware encryption. Zero plaintext touches disk, and no telemetry or auth servers mediate your credentials.

What if my model is not in the eight deeply adapted providers?

Any compatible endpoint integrates via our universal OpenAI adapter. Eight leading foundation models feature dedicated payload, streaming, and instruction optimizations. Submit an issue on GitHub to request dedicated adaptation for additional models.

Are third-party plugins secure?

Plugins execute inside a dual-tier sandbox (Node VM isolated within an iframe) with strict API allowlists. Any privilege escalation trips the independent Rust Watchdog daemon for immediate termination.

Bring your own keyComing soon

Open source under the Apache License 2.0. No account to register — fill in your own model key and go.