What it does
X25519 + XChaCha20-Poly1305 AEAD. Your secrets never touch disk in plaintext.
kosh run intercepts stdout and stderr, scrubbing secret values before they reach your terminal.
Sync encrypted secrets across your team. Role-based access: owner, admin, developer, readonly, ci.
Works fully offline. The server is optional, use it only when you need team sync.
How it works
Privacy & Security
Kosh uses established, audited primitives from the Rust dalek, chacha20poly1305, and argon2 crates. No custom crypto. No telemetry. No cloud accounts required.
On-device decryption, always. Your private key never leaves your machine. The Kosh server (if used) stores only encrypted blobs. Even if the server is compromised, your secrets remain ciphertext without your local key.