Security
The vault
Every secret Ropenode stores — a Jira token, a mail or FTP password, a WSL sudo password, an MCP token, your licence token — is sealed with AES-256-GCM in its database.
The key that seals them (the data key) is held one of two ways:
- Keychain mode (default). The data key lives in Windows Credential Manager.
- Master-password mode. The data key is wrapped with a key derived from a password you choose (Argon2id), and the copy in Credential Manager is deleted. The app then boots locked until you unlock it.
Secrets are never sent to the UI. The interface can ask "is a token configured?" and get back a yes or no; it cannot ask for the value.
If you choose master-password mode and forget the password, the secrets are unrecoverable. That is what "encrypted" means. There is no back door.
What is not encrypted
The main database itself (projects, prompts, history) is not encrypted. The secrets inside it always are.
An MCP server needs its token in clear when it starts, so while a Claude Code console that uses one is open, the token is also in that session's MCP configuration file in the app's data folder. The file is deleted when the console closes.
Backups
Settings → Security → Back up database… saves a full copy of the app's database wherever you choose.
Last updated Oct 11, 2026