termal.in

Termalin for teams

SSH your team — and your agents — can be trusted with.

A fast, modern SSH client with encrypted vaults and access control your security team will recognise — plus the one thing no one else offers: governance over what your AI agents do on your infrastructure.

One place for accessGrant and revoke host and vault access as people and agents join or leave.
Encrypted end to endCredentials are encrypted on the device before they ever reach our servers.
Every action on recordSessions — human or agent — can be recorded, replayed and reviewed.

Onboarding and offboarding without the scramble

Organise people into teams, share the vaults they need, and cut access the moment they leave — no chasing keys spread across laptops.

  • Organisations & roles — owner, admin and member, with people in more than one org.
  • Shared vaults — hand a new hire the exact hosts and credentials for their team.
  • One effective plan — a member inherits the best plan across their orgs automatically.

Security your team already expects

Termalin is built encryption-first: your vault is sealed on the device with a key derived from your master password, and only encrypted blobs are ever synced.

  • End-to-end encrypted vaults — AES-256-GCM, keys never leave the device.
  • Granular access control — decide who reaches which vaults.
  • SAML SSO & enforced 2FAcoming soon
  • Audit logs — every login, host connection, file op and agent command captured server-side; org-wide review coming soon

Govern what your agents do

AI agents are already touching production. Termalin is the only SSH client built for it: agents connect through an MCP server with your keys, and every command they run is yours to watch and review.

  • Agents never hold keys — they authenticate through the running key agent, not copied credentials.
  • Live oversight — watch every agent session mirrored in the grid as it happens.
  • Marked in the record — each agent command is tagged in the session replay and written to a server-side audit log.
  • Per-host & per-key policy — set each host to full, an allowlist of commands, or blocked; the same policy applies per API key on the hosted endpoint.

Built for teams

Everything in Team, plus the controls larger organisations ask for.

SAML SSO coming soon

Bring your own identity provider and enforce 2FA across the org.

SCIM provisioning coming soon

Auto-provision and de-provision users from your directory.

Audit logs org view soon

Every login, host connection, file op and agent command is captured server-side today; org-wide review is coming.

Agent governance beta

See and review every action your AI agents take on your hosts.

RBAC

Roles and per-vault access control, today.

End-to-end encryption

AES-256-GCM vaults with device-held keys, today.

SLA & priority support

Response commitments and a direct line when it matters.

Dedicated manager

Onboarding, migration and a named contact for your rollout.

SOC 2 planned

On our compliance roadmap — ask us where it stands.

Request a demo

Tell us about your team and we'll show you Termalin — including a look at agent governance.

Prefer email? Write to [email protected].