TermiGramDocs
Help & safety

Security and privacy

The practical security boundaries for Telegram sessions, stored secrets, sharing, AI, and support.

TermiGram combines Telegram identity, encrypted secret storage, SSH/SFTP transport, and optional Master Password protection. Security still depends on your Telegram account, device, SSH account, and server policy.

Telegram session

The Web App verifies the signed session information supplied by Telegram. Direct browser access without a valid Telegram session does not load the normal profile or SSH/SFTP workflow. User data is scoped to the authenticated app user.

Stored credentials

Saved SSH passwords and private keys are encrypted by TermiGram. Master Password adds a device-side protection layer for profiles saved under that mode. Do not interpret this as a claim that every data field uses universal end-to-end encryption.

Transport

The public Web App uses encrypted web connections. TermiGram establishes SSH and SFTP connections according to the selected profile and its connection settings.

Managed Guest links support expiry, revocation, and use controls. Full access creates a recipient-owned profile copy and cannot be recalled after import. See Share Links.

AI and support

AI assistants should not have direct access to saved SSH secrets and should remain within product/technical scope. Support staff should never request passwords, Master Password, private keys, or tokens.

Your responsibilities

  • Protect your Telegram account with device security and two-step verification.
  • Use restricted SSH accounts and least privilege.
  • Rotate credentials after suspected exposure.
  • Review active Share Links.
  • Keep recovery access outside TermiGram for critical infrastructure.
  • Redact logs and screenshots before sharing them.

No system is absolutely secure

TermiGram reduces common handling risks but cannot protect a compromised phone, Telegram account, server, SSH account, or recipient of a Full access copy.

On this page