BURSUcm

ssh · rdp · vnc · telnet · serial · web · ftp · sftp

All your connections,
in one place.

BURSU Connection Manager brings your servers, credentials and team into one workspace. Terminal and SFTP side by side, RDP and VNC in a tab, jump hosts and tunnels — and passwords in an encrypted vault, whose key never leaves your device.

Windows · macOS · Linux · Android · iOS and iPadOS

▸ snippet Disk space → prod-web-01
admin@prod-web-01:~$ df -h /var/lib/postgresql
Filesystem      Size  Used Avail Use% Mounted on
/dev/nvme0n1p2  512G  318G  194G  63% /var/lib/postgresql
admin@prod-web-01:~$ 

The partition is 63 % full and growing by about 4 GB a day. Show the largest tables? The command only reads data.

5432 → localhost:15432 jump: bastion.corp vault unlocked Secret Shield: on
Windows3.2.0Installer x64 / x86 / ARM64, Authenticode-signed
macOS2.2.0.dmg for Apple Silicon and Intel, notarised by Apple
Linux2.2.0.deb · .rpm · .pkg.tar.xz, signed repositories
Android1.8.7Google Play or the APK from this site
iOS / iPadOS1.2.7App Store, one universal app

Everything a connection manager should be

Built for engineers and teams that live in remote sessions — every protocol, every credential and fine-grained access, in one place.

8+protocols
SSH · RDP · VNC · Telnet · Serial · Web · FTP · SFTP
AES-256-GCMencrypted
credential vault
3storage modes
SQLite · PostgreSQL · Cloud
4app interface languages
+ light / dark themes

All your sessions in tabs

SSH, RDP, VNC, Telnet, Serial, Web, FTP and SFTP all open in tabs — with a full embedded terminal, a side-by-side SFTP file panel, split view for two sessions at once, full-screen mode and an embedded remote desktop.

Jump hosts & tunnels

Reach servers behind a bastion with ProxyJump chains, open local and remote port-forwarding tunnels together with the session, and authenticate with keys from the OpenSSH agent.

Split view & broadcast

Run two sessions side by side in one tab, or type once and broadcast your keystrokes to every open session — with keyboard shortcuts for the whole app.

Command snippets

A shared library of your everyday commands, sent into the terminal in one click — {placeholder} values are asked at send time, and the library syncs through your database and the web portal.

AI assistant — optional

An assistant beside your SSH or RDP session that explains output and can run routine commands — with your own API key or a local model, and approval required for anything that changes the system. Not your thing? One checkbox in Settings switches the whole feature off.

Built for flow

A live status dot on every tab, one-click reconnect when a session drops, and a confirmation preview before multi-line text is pasted into a terminal.

Encrypted credentials

Passwords are protected by a portable AES-256-GCM master-password vault — or Windows DPAPI on Windows. Folders inherit credentials.

Folders & permissions

Nested folders with per-folder grants: who can view, edit, or reveal passwords. Clean tree navigation, as in the tour.

BURSUcloud sync

Switch storage to BURSUcloud and your catalog lives in an isolated PostgreSQL database, reached only server-side through our zero-knowledge API.

Home dashboard

A pinnable, closable Home tab that greets you with quick stats, your recent and favorite connections, vault status and one-click actions to get straight to work.

Team & program users

Invite portal teammates or create desktop-only program users — everyone gets per-folder rights down to view, edit or reveal passwords, and the database owner always stays administrator.

Themes & languages

System, Light and Dark themes plus English, Russian, Ukrainian and Georgian — set it once in Settings.

Session restore & updates

Reopen the connections you had open when you last closed the app — on demand or automatically on startup — and get a quiet heads-up when a new version is ready to download.

Remote desktops: RDP & VNC

Full remote desktops inside a tab. Our own built-in RDP engine draws the screen with H.264 graphics, remote audio, clipboard and multi-monitor support, and VNC connects with TLS/VeNCrypt encryption, clipboard sharing, scaling and a view-only mode.

Two-factor codes built in

Keep the TOTP secret next to the login it belongs to and copy a live six-digit code in one click — no phone in hand. The seed is protected by the same master-password vault as your passwords.

A terminal that fits you

Pick a colour scheme, font and size for your terminal, generate strong passwords right where you store them, record a session to a log file, and wake a sleeping machine with Wake-on-LAN from its own menu.

BURSUcloud

Your master password never leaves your device

The app never connects to PostgreSQL directly. The catalog is read and written over HTTPS through the portal, and the portal opens the database on 127.0.0.1 only. The server holds ciphertext and nothing else.

Your device

BURSUcm

  • Master password is entered here and stays here
  • The vault PBKDF2 + AES-256-GCM encrypts everything before it is sent
  • Windows, macOS, Linux, Android, iOS
the key stays here
bursucm.com

Zero-knowledge API

  • Checks per-folder rights: view, edit, reveal passwords
  • Cannot decrypt a single record
  • The only process that opens PostgreSQL
Your database

PostgreSQL

  • Isolated database for every account
  • Export and import .sql at any time
  • Database passwords are encrypted at rest too
No account requiredOffline, the app works entirely with a local database. An account is only needed for sync and sharing.
Rights per folderWho can view, who can edit, who can reveal passwords. The root covers the whole database and is the only way to reach items outside any folder.
The owner is always administratorOwnership can be handed over, but a database is never left without an administrator.

Create free account

Designed for clarity

A clean, modern workspace

The credential vault, the two-pane file manager and a remote desktop — one workspace, three views.

bursucm · Encrypted credential vault
Credentials view grouped by folder
bursucm · Two-pane SFTP file manager
Two-pane SFTP file manager with a transfer queue
bursucm · Remote desktop in a tab
Windows remote desktop open in a BURSUcm tab

See the full tour →

Frequently asked questions

Everything you need to know before you connect.

What is BURSU Connection Manager?
BURSU Connection Manager (BURSUcm) is a cross-platform remote connection manager for SSH, RDP, VNC, Telnet, Serial, Web, FTP and SFTP, running on Windows, macOS and Linux. It keeps your servers, credentials and teams in one place, with an embedded terminal, an SFTP file panel and an embedded remote desktop.
Which protocols are supported?
SSH, RDP, VNC, Telnet, Serial, Web, FTP and SFTP today, with more on the way. RDP and VNC both run inside a tab through our own built-in engines, and on Windows you can hand off to the native Remote Desktop client instead.
Does it support jump hosts and port forwarding?
Yes. An SSH connection can go through one or more jump hosts (ProxyJump), with the host key verified against the real target — the terminal and the SFTP panel both work through the tunnel. Each connection can also open local (-L) and remote (-R) port-forwarding tunnels automatically, and keys can come from the OpenSSH agent.
What are command snippets?
A shared library of saved commands you send into a terminal in one click. Snippets support {placeholder} values that are asked at send time, are stored in your database so they sync to every device, and can be managed in the app or on the web portal.
Can I import my connections from PuTTY, WinSCP or mRemoteNG?
Yes. One import window brings your connections over from WinSCP (saved passwords are decrypted automatically), PuTTY, mRemoteNG, Remote Desktop Manager, Royal TS, OpenSSH config files and .rdp files — with a folder-tree preview where you tick exactly what to import and pick a target folder. Import and export also work on the web portal, using the same portable backup format.
Is it free?
Yes — the desktop app is free to download and use. BURSUcloud adds optional cloud sync and team sharing.
Which platforms does it run on?
Windows 10 and 11 (including Windows Server), macOS on Intel and Apple Silicon, Linux (Debian/Ubuntu .deb, Arch/CachyOS .pkg.tar.xz and Fedora/RHEL .rpm), Android and iOS/iPadOS 17 or newer. The iPhone and iPad app is one universal app on the App Store.
How are my passwords protected?
Credentials are encrypted at rest with a portable AES-256-GCM master-password vault (or Windows DPAPI on Windows). With BURSUcloud, secrets stay encrypted and your database is reached only server-side through our zero-knowledge API — your master password never leaves your device.
Does the app include AI features? Can I turn them off?
Version 3.0 adds an optional AI assistant for SSH and RDP sessions. It stays inactive until you add your own API key (OpenAI, Google Gemini, Anthropic Claude, DeepSeek and others) or connect a local model through Ollama, LM Studio or llama.cpp. Commands that could change the system always wait for your approval, and Secret Shield redacts passwords, keys and tokens before any text is sent to a provider. If you would rather not have AI at all, one checkbox in Settings disables the entire feature, and administrators can switch it off per user.
What is BURSUcloud?
BURSUcloud is the optional cloud backend. Your connection catalog lives in an isolated PostgreSQL database reached only through our zero-knowledge API, so teams can share connections with folder-level permissions.
Do I need an account?
No. You can use the app fully offline with local storage. An account is only needed if you want to sync and share through BURSUcloud.

Ready to connect?

Download the desktop app, or create a free BURSUcloud account to sync across your team.