BURSUcm
Windows · macOS · Linux · Android · iOS / iPadOS

Download BURSU Connection Manager

The full connection manager for SSH, WinRM, RDP, VNC, Telnet, Serial, Web, FTP and SFTP, with local SQLite, PostgreSQL or BURSUcloud storage.

Windows

Version 3.7.0 · released 2026-09-12
Windows installer (x64 / x86 / ARM64)
x64 / x86 / ARM64 · 169.5 MB · updated 2026-09-12
Download
SHA-256 3d80ff6dfd714ae2bf8ee80dd6af6df9a46f57ba17883f3f9b363a0568230dcf

Run the installer and follow the setup wizard. No separate .NET install is required. The installer and the application binaries are Authenticode-signed, so Windows verifies the publisher before anything runs. Or install from the command line: winget install bursucm

macOS

Version 2.7.0 · released 2026-09-12
macOS — Apple Silicon (.dmg)
arm64 · 163.1 MB · updated 2026-09-12
Download
SHA-256 271b09f760de82742595c4286c02445d9776e2ccecaa04ca9148a181fa552994
macOS — Intel (.dmg)
x86_64 · 171.2 MB · updated 2026-09-12
Download
SHA-256 d2e77e624181358e1b96b519cbcd1ac15bc94391f25f488c615faaa24120649c

Open the .dmg and drag BURSU Connection Manager into your Applications folder. Choose Intel or Apple Silicon to match your Mac. Images are Developer ID signed and notarised by Apple.

Linux

Version 2.7.0 · released 2026-09-12
Debian / Ubuntu / Linux Mint / Pop!_OS (.deb)
x86_64 · 137.0 MB · updated 2026-09-12
Download
SHA-256 bd2bd2cbe4c6f155da1d8be5a4b725dcfe77df3fdb0cf6ffe077a05da837c141
Install sudo apt install ./bursucm_2.7.0_amd64.deb
APT repository auto-updates Add the repository once — new versions arrive with your regular system updates.
1. Key sudo wget -qO /usr/share/keyrings/bursucm.gpg https://bursucm.com/repo/bursucm.gpg
2. Source sudo tee /etc/apt/sources.list.d/bursucm.sources >/dev/null <<'EOF' Types: deb URIs: https://bursucm.com/repo/apt Suites: stable Components: main Architectures: amd64 Signed-By: /usr/share/keyrings/bursucm.gpg EOF
3. Install sudo apt update && sudo apt install bursucm
Arch / CachyOS / Manjaro / EndeavourOS (.pkg.tar.xz)
x86_64 · 137.0 MB · updated 2026-09-12
Download
SHA-256 4770661f461abfe8a83ea82dd98ea4b5a5439d7a04d4aac9a0f2d0df81cba25f
Install sudo pacman -U bursucm-2.7.0-1-x86_64.pkg.tar.xz
Pacman repository auto-updates Add the repository once — new versions arrive with your regular system updates.
1. Key curl -fsSL https://bursucm.com/repo/bursucm.asc | sudo pacman-key --add - && sudo pacman-key --lsign-key BA53B57D047CE8F14610C02A037A882DB839E2E0
2. Source echo -e '\n[bursucm]\nServer = https://bursucm.com/repo/arch' | sudo tee -a /etc/pacman.conf
3. Install sudo pacman -Syu bursucm
Fedora / RHEL / AlmaLinux / Rocky Linux (.rpm)
x86_64 · 135.1 MB · updated 2026-09-12
Download
SHA-256 c95f169de9641743f6743d76a0d571561773c696d7f5089bd6a02b8093b686ce
Install sudo dnf install ./bursucm-2.7.0.x86_64.rpm
DNF / YUM repository auto-updates Add the repository once — new versions arrive with your regular system updates.
1. Key sudo rpm --import https://bursucm.com/repo/bursucm.asc
2. Source sudo tee /etc/yum.repos.d/bursucm.repo >/dev/null <<'EOF' [bursucm] name=BURSUcm baseurl=https://bursucm.com/repo/rpm enabled=1 gpgcheck=1 repo_gpgcheck=1 gpgkey=https://bursucm.com/repo/bursucm.asc metadata_expire=6h EOF
3. Install sudo dnf install bursucm

Or open the package with your software centre.

Android

Version 1.8.8 · released 2026-09-03
Android app (APK)
Android · 29.1 MB · updated 2026-09-03
Download
SHA-256 0a783abce969f9c88cb3970da9bf22d8f5569da6a1860a1bafaaa4477f9cc844
Also on Google Play Install from the Store and updates arrive on their own. Get it on Google Play

Download the APK, then open it on your device and allow installation from this source if prompted.

iOS / iPadOS

Version 1.2.8 · released 2026-09-03
App Store
Version 1.2.8 for iPhone and iPad. Requires iOS or iPadOS 17 or newer.
Download on the App Store
Changelogs

Supported systems

  • Windows 10 / 11 and Windows Server 2012–2025; WinRM targets: any Windows Server or Windows 10 / 11 with PowerShell Remoting enabled
  • macOS on Intel and Apple Silicon
  • Linux: Debian/Ubuntu (.deb), Arch/CachyOS (.pkg.tar.xz), Fedora/RHEL (.rpm)
  • Android 8.0 or newer
  • iOS and iPadOS 17 or newer

How to install

  1. Pick your platform above and download.
  2. Run the installer or package.
  3. Launch BURSUcm and sign in. For a local database, use admin / admin on first run; for BURSUcloud, sign in with your account.
  4. Pick storage: Local, PostgreSQL or BURSUcloud.

What's included

  • SSH / WinRM / RDP / VNC / Telnet / Serial / Web / FTP / SFTP in tabs
  • Jump hosts, -L / -R / -D tunnels, tmux sessions and SSH keys from the agent or the vault
  • Split view, broadcast input and command snippets
  • SFTP file panel and remote desktop
  • Encrypted credential vault
  • Optional AI assistant — inactive without your key, disabled entirely with one checkbox
  • Team access with per-folder permissions
  • Light / Dark themes · 4 app interface languages

New to BURSUcm? Take the product tour →

Changelog

Version 3.7.0
  • Folder navigation stays responsive on BURSUcloud: expanding, collapsing, selecting and reordering folders no longer waits for a network round trip, while saves remain ordered and reliable.
  • Direct PostgreSQL setup now uses clear host, port, database, user, password and TLS fields, can test the saved connection, and can export or import a password-protected configuration file for a colleague.
  • Shared PostgreSQL vaults now use one portable data key per database. Changing the master password no longer re-encrypts every secret, and concurrent changes cannot be silently overwritten.
  • Legacy vaults migrate safely without losing access, including databases with older KDF metadata; remembered master passwords remain attached to the correct database and survive migration or temporary connection failures.
  • A secret saved by the Universal edition is no longer mistaken for plain text and shown as ciphertext in the Windows client.
  • Folder permissions are safer and clearer: moving or deleting folders preserves grants, partial rights are displayed correctly, root-level items have their own grant, and members can edit their own account and password.
  • Deleting a folder through BURSUcloud is atomic, so a failed request cannot leave the catalogue half-modified; an outdated portal is refused before any destructive step.
  • Smaller fixes across database and account screens: program users can test the saved connection, “Remember master password” now works during initial setup, portable backups contain a complete vault, TLS labels say what is actually verified, the user editor no longer freezes, and provider badges, translations and layouts display correctly.
Version 3.5.1
  • The AI assistant no longer freezes the app while a model streams its reply or its reasoning. Every fragment used to re-lay out the whole text on the interface thread, so a long “thinking” phase left the window marked “Not Responding”; the text is now appended in one go per idle pass, and the interface stays responsive through a 100 KB reasoning stream.
  • The assistant panel stays where you scrolled it while the reply streams, following the stream only while you are at the end, and the end of a turn no longer pulls the keyboard focus from the terminal into the composer.
  • AI chats from before 3.5.0 are visible again. The move to per-account profile folders looked only in the new folder and left the earlier archive behind; both are read now, and the old chats migrate the first time the assistant opens.
  • Name lookups ask before running: nslookup, getent hosts, ping of a host name and openssl s_client wait for your click like curl and wget do, because every label of a queried name reaches whoever runs that zone. An address such as ping -c 3 8.8.8.8 still runs on its own. Secret Shield also hides values named DB_PASS, ROOT_PW or MYSQL_PWD and keys from xAI, Groq, GitLab and DigitalOcean.
  • A command is no longer reported as finished before it was typed. A completion mark from the previous prompt that arrived while the assistant waited for the screen to settle counted as the new command's result, and the “> ” prompt of an open quote was taken for an idle shell, which typed the next command into the string.
  • Provider failures are shown, not swallowed: a timed-out request looked like a pressed Stop, an error in the middle of a streamed reply ended it as if complete, and a rejected key was retried three times before you saw it. A reply that quotes a YAML block before its shell command no longer proposes the prose between them as the command.
  • Smaller things: the provider, attachment and screenshot messages of the assistant panel are translated into Russian, Ukrainian and Georgian; the attach dialog offers every file type the assistant accepts; the panel's divider resizes when released instead of re-laying out the conversation on every pixel.
Version 3.5.0
  • The app now runs on .NET 10 and carries its own copy of the runtime in a “runtime” folder beside the program. Nothing has to be installed on the computer, a system-wide .NET does not affect it, and every file of that copy is signed by Microsoft.
  • Launching from the Start menu is quick again right after a Windows Defender definitions update. The previous build was one 286 MB file that Defender scanned whole on the first start after every update — two to three seconds with the Start menu frozen open. The program is now a 31 MB file next to the runtime, Defender scans only what is actually loaded, and the installer shrank from 221 MB to 170 MB.
  • A warmed-up start is about 100 ms faster: the rendering engine is prepared in the background while the settings are read, and the Windows Forms layer is loaded only when an RDP tab on the Microsoft engine or the import window’s folder picker needs it.
  • Program Files holds only the program: BURSUcm.exe, five native libraries and the runtime folder. The translations and the terminal renderer are built into the program, so the “src” folder beside it is gone, and an upgrade removes everything a previous layout left behind.
  • The desktop shortcut no longer turns into a blank document icon after an update — the installer asks Windows to refresh its icon cache when it finishes.
  • Every file the installer places is checked when the release is built: the runtime keeps its Microsoft signatures, our own files are signed and time-stamped, and the build stops on anything else.
Version 3.3.2
  • Opening a folder in a user's permissions no longer closes the app. The three columns hold live checkboxes, so a click anywhere in a row put that row into edit — and the moment the folder's arrow was then clicked, the list refused to redraw and the app went down with it. A folder whose rights come from a group showed it every time, because its boxes are disabled and the click lands on the row itself. Switching between the connection and credential tables had the same fault one step earlier. Both are closed.
  • A cloud account is no longer shown as holding every folder. An account created in the portal carries an explicit list of what it was granted, and an empty list means it was granted nothing of its own — which is exactly an account whose rights come from a group. The user's card read that as the old rule for accounts from before per-folder rights, “never restricted, so it sees everything”, and drew a ticked “All connection folders”: Read on every folder, for someone who had been given none. Saving the card would have written that as a real grant. Accounts on a local database from before per-folder rights keep the old meaning.
Version 3.3.1
  • User groups. A group is a named set of per-folder rights, and everyone in it inherits them — so a team's access is granted once instead of being re-entered for every account. Rights that come from a group show in the person's card as a green tick, locked and labelled “Inherited from group”, beside the ones granted to them personally. Groups work the same way in the local database, in your own PostgreSQL and in a BURSUcloud database; a group never makes anyone an administrator.
  • One folder per account on this computer. Everything the app keeps outside the database that belongs to a person — trusted host keys and certificates, logs and session transcripts, the offline copy of the catalog, the assistant's chats, the browser tabs' profile, the remembered vault key and “remember me” — now lives in that account's own folder, and the app switches to it the moment someone signs in. Nothing is deleted when the next person signs in: come back and your own state is where you left it. An install updating from an earlier version hands its files to the first account that signs in, and an administrator can remove a person's folder from the users window.
  • The Settings window is everyone's, and it matches the Universal edition tab for tab. Because those preferences are now a person's own on this computer, every user sees every tab and saves the SSH, RDP, VNC and WinRM policies, the session defaults and the logging — where before most of that was an administrator's alone. What stays the administrator's is what describes the shared database: switching it, import and export, the master password and the password policy. The same sections, labels and hints as the Linux and macOS edition, and the Security tab now carries an inline box for unlocking the vault.
  • A folder is picked from the tree, not typed as a path. Everywhere a record's folder is chosen — the connection editor, the credential and SSH-key editors, the parent folder in Edit Folder, and “Move to folder” — the field is now a drop-down of the folders you already have, in the tree's own order and folded the way the tree is folded. Folders you may not save into are shown greyed rather than hidden, so the ones under them keep their place, and the root row reads “(root — top level)”.
  • A right taken away stops working at once. Until now a demotion, a deletion or a withdrawn group membership held until the app was restarted — administrators included, since they were skipped entirely — and a session in which passwords are only read and copied never reloads a catalog, so the decision to reveal a password was made all day from the snapshot taken at sign-in. The signed-in person's rights are now re-read at every catalog reload and before every action that hands out a secret; revoking the assistant's right closes an assistant already open, and a group dialog left open cannot restore rights withdrawn meanwhile.
  • A session through an RD Gateway now pins the gateway's certificate. The app checked that certificate before connecting and then told the engine nothing about it, so the engine accepted whatever the gateway presented during the real handshake; and when the certificate could not be obtained at all, the check was skipped and the session went ahead — a machine answering on the gateway's address would have received the username and the password. The approved fingerprint now travels to the engine, which refuses a gateway that presents anything else, and under the “trust on first use” and “strict” policies a gateway whose certificate cannot be read is refused with an explanation.
Version 3.3.0
  • Windows servers, over WinRM. A new connection type beside SSH: PowerShell runs over PowerShell Remoting and cmd.exe over WinRS, on plain HTTP or over HTTPS, where the server's certificate is trusted once and pinned the way an SSH host key is. Output streams while a command is still running, Ctrl+C stops the pipeline, errors arrive as errors with the line they happened on, and Read-Host, -Confirm and a missing mandatory parameter ask and wait — a password is answered under the session key, never as text on the screen.
  • The WinRM terminal behaves like a terminal. “clear” and “cls” clear this window at once instead of answering with two paragraphs of red; Write-Host keeps its colours and “-NoNewline”, and what a script writes through $host.UI is drawn rather than dropped; a cmd.exe session can be set to a codepage such as 866, so Cyrillic typed into it comes back readable; a paste of several lines runs all of them; a “Password:” prompt from a cmd program hides what you type; and a WinRM tab splits into a second pane, as an SSH tab does.
  • Keep an SSH session in tmux. A checkbox in the SSH options, with a session name beside it, makes the connection attach to that tmux session when the shell opens — created the first time, rejoined after that, so a dropped connection returns you to the same screen with the same programs still running. Detaching (Ctrl+B, D) returns to the plain shell rather than closing the tab; the tab reads “(tmux)” while you are inside, the wheel scrolls tmux's own history, the Files panel still follows “cd”, and the assistant still sees when a command ends. A server without tmux says so in the terminal, and the session goes on without it.
  • A SOCKS5 proxy through the SSH connection (ssh -D). A third kind of tunnel beside local and remote forwards: the tunnels editor now offers “dynamic”, which opens a SOCKS5 proxy on 127.0.0.1 at the port you choose and carries every connection made to it through the session. A browser, curl or a database client pointed at the proxy reaches hosts only the SSH server can route to, and names are resolved on the server side as well (socks5h). The proxy listens on 127.0.0.1 only — it is never offered to the network the computer is on.
  • The assistant's terminal is your terminal. While one of its commands ran, whatever you typed was held back until the command finished — a password typed at a sudo prompt never reached sudo, and once you pressed Ctrl+C it was typed into the shell in clear. Keystrokes now go to the terminal at once, always. A prompt meant for you — a password, a yes/no — is waited for, with “Waiting for your input in the terminal” on the card and no clock running, and the assistant then sees the whole result; a long upgrade that keeps printing is no longer cut off at a fixed minute, because the timeout counts silence. And your environment stays: a pager no longer stops at “Press RETURN”, and tools that keep their configuration in your home directory find it.
  • The assistant asks before a PowerShell line can do harm. It now classifies by PowerShell's own rules: a method call anywhere in the line — “$_.Delete()”, “(Get-Service x).Stop()” — a static member and every script block are judged, so “Get-ChildItem | ForEach-Object { $_.Delete() }” asks for the click instead of passing as a reading command. Reading a file that may hold secrets (the SAM and SECURITY hives, web.config, appsettings, keys, .ssh), any UNC path and “-ComputerName” ask too, because what is read goes to the AI provider with the output.
  • Findings of the pre-release audit. A single pasted line with a line break at its end ran on paste — the break is dropped now and you press Enter yourself, so a page with a hidden command cannot run it for you. A crash report waiting for the next start carried the raw error text, connection strings included, in a file that backup tools read; secrets are cut before it is written. A server that printed “tmux=on” in its banner could switch the tab into tmux mode; the marks are read only after this side has typed its own line. And the hints under plain HTTP and “proceed past certificate errors” now say what each actually gives up.
  • Small things. A text box the app had switched off looked exactly like an empty one — white on white, and inviting to type into; it is grey now, and empty fields carry a hint inside them where one helps. The “Keep-alive” label in the SSH options read in English in every language while its translation sat unused.
Version 3.2.1
  • The AI assistant can now run interactive programs. “htop”, “top” and anything else that takes over the screen were refused outright — the assistant could only start a command and wait for it to finish, and htop never finishes, so the wait could end only in a timeout and a Ctrl+C nobody asked for. It now starts such a program, lets it draw its first screen and hands the terminal back to you.
  • Answers appear as they are written. The assistant collected the whole reply and showed it in one piece at the end, with the “thinking” line already switched off — so the panel sat empty for as long as the answer took, which reads as a hang.
  • A chat you had compacted could never be used again. Compacting stored its summary where the model interface refuses to accept it, and every later message failed; deleting the chat looked like a cure only because it threw the summary away. Chats saved before this update reopen unchanged.
  • Code inside an answer reads as text again. Every backticked word became a full-width grey box with its own Copy button, so a file path named in the middle of a sentence cut that sentence into three stacked blocks. A command still gets its own block and its Copy button; a name inside a sentence stays inside the sentence — and the whole answer can be selected, which is how a path or a value is taken out of one.
  • The assistant is no longer frozen out by “sudo su”, “mysql”, “psql” and the like. Inside those the terminal cannot report that a command has finished, so the assistant refused every request and told you to press Enter or Ctrl+C over a command line you had never typed. It recognises their prompts now, says which case it is when it does refuse, and no longer claims the terminal is busy from its own memory of an earlier answer.
  • Problem reports, after two independent audits: identical faults group together whatever the privacy switches are set to — the grouping used to change with them; server names, logins and IPv6 addresses are masked more carefully while the stack itself stays readable; and declining one fault no longer silences a different one, so two alternating faults stop asking at every start.
  • Problem reports: closing the window cancels the send instead of leaving it running, the fields freeze while a report is in flight so the preview cannot drift away from what is being sent, and a report that arrives after you close the window is no longer recorded as declined.
Version 3.2.0
  • Report a problem, without leaving the app. When something goes wrong the app offers to send a report about it, and Help → Report a problem is there at any other time. You get a report number back, and we get the error itself instead of a description of it.
  • You see exactly what will be sent, before it is sent. “Show what will be sent” is not a summary of the report — it is the report, rebuilt as you type and as you tick the boxes. Nothing leaves the computer until you press Send: there is no background upload and no crash beacon.
  • Passwords, keys and tokens are stripped on your computer, before the preview. Server addresses, account names and IP addresses are replaced with placeholders as well — in a connection manager those are as private as a password — and a checkbox puts them back when you decide they help.
  • When the report already carries the error, writing anything is optional, and the fields say so. People who did not feel like writing used to press Cancel — and then nobody had the error either.
  • A crash is offered at the next start. A fault that closes the app leaves a record beside its crash log, and the next launch asks whether to send it, with the error already inside. Failures that used to reach only a log that is off by default — a background operation that gave up, a fault inside a remote-desktop session — are offered the same way. Saying no is remembered for a day, so a fault that repeats does not ask at every start.
  • A screenshot only when there is something to see. It is taken at the instant of the fault, before any of our own windows are drawn — an earlier attempt photographed the very dialog that was asking about the error — it is off by default, and it is shown to you before it is sent. Reports from the Help menu and offers after a crash carry none.
  • A send that fails loses nothing. The dialog stays exactly as you left it, and “Save to file…” writes the whole report — the readable text and the raw data — ready to be mailed to support@bursucm.com.
  • Settings → Other has a switch that turns the offers off. Off means the app stops asking: no dialog after an error, no question at the next start, no entry in the Help menu. It never meant “report silently” — nothing was ever sent without Send.
Version 3.1.1
  • Local database: signing in after updating from 2.8.3 or 2.8.4 failed with “no such column: ai_enabled”. Those versions had marked the database as fully migrated, so 3.0 and 3.1 skipped the step that adds the columns the AI assistant and SSH-key credentials need. The step now runs again on the first open, and the client checks the columns themselves instead of trusting the version stamp.
  • PostgreSQL: editing or deleting a connection, credential or snippet failed with “could not determine data type of parameter”, and importing a backup was rolled back without a message. The statements now carry the type PostgreSQL needs.
  • PostgreSQL: a new, empty database now opens with the same example folders, connections, credentials and snippets as a new local file.
Version 3.1.0
  • SSH keys are now a kind of credential. A key record keeps the private key and its passphrase sealed under your master password, with the public key and a comment beside them, and it follows the same folders, permissions, owners, backups and sync as a password. Load a key from a file and the matching .pub is picked up next to it.
  • A connection can use a stored key instead of carrying its own. Pick it from the same folder tree the main window shows — a key glyph for keys, a padlock for passwords — and the authentication method follows the pick. The key is used for the target and for every bastion in the jump chain, and the editor names the credential it comes from.
  • A stored key never leaks into a connection. Saving a linked connection leaves its own material untouched, switching back to manual entry restores it, and a key you may edit but not reveal is shown as a write-only placeholder rather than an empty box that a save would erase.
  • Five security audit passes over the credential store. Private keys and passphrases survive a master-password change, the offline queue, backups and migration; “Copy As” never carries a secret sealed to another record and offers to unlock the vault first; “Keep my version” in sync conflicts requires the same edit right as the write itself; a replaced or deleted key forgets its old passphrase.
  • AI assistant: commands written in backticks become copyable chips; connection names, notes and tags reach the model as untrusted data, not as part of its rules; a sed script runs automatically only when it plainly cannot execute or write anything — everything else asks first. Google Gemini is driven through its native SDK, and SSH usernames are validated before a connection is saved.
  • Access permissions are a real tree: one table switched between connection and credential folders, indented with chevrons and folder glyphs, a search by full path, “Only granted”, Expand all / Collapse all and a counter, and “All folders” shows exactly what it grants. A checkbox now takes one click instead of two, and the user window has General and Access permissions tabs like Settings.
  • The connection editor, the credential editor and the credential card are laid out in two columns with nothing to scroll: what the item is on the left, how it authenticates on the right. Fields a credential owns are dimmed, a key's card shows the key rows instead of an empty password, “+ Add credential” opens an in-app panel that explains both kinds, and subfolders sit under their own heading in the order you saved.
  • Reassigning an owner works in every setup again: portal administrators are always offered, so the owner row no longer disappears when no program user may edit the folder, and an unchanged owner is left alone on save. The release pipeline now refuses to package anything that changed after publishing, accepts upstream signatures only from expected publishers, and has a second timestamp authority.
Version 3.0.0
  • Meet the new AI assistant for SSH and RDP. It understands the active session, explains output, investigates failures and can carry out complete administration tasks without making you copy commands between windows.
  • Choose the intelligence that fits the job: OpenAI, Google Gemini, Anthropic Claude and DeepSeek are supported alongside local Ollama, LM Studio and llama.cpp models. API keys are encrypted with your master password, while model discovery, connection testing and provider switching are built into Settings.
  • Automation is guarded by what a command actually does, not by a brittle list of command names. Read-only work can run automatically; anything that may change the system is clearly explained and waits for approval, with exit codes, timeouts and interactive commands handled explicitly.
  • Secret Shield detects and redacts passwords, API keys, private keys, cookies, tokens, database connection strings and .env contents before text is sent to an AI provider. Chat history is encrypted locally, and provider-side storage controls are shown only where the provider supports them.
  • AI chats are now a real workspace: create, rename, archive, restore and delete conversations; pin a chat to a connection; resize the panel and keep that size; see context usage; and compact a long conversation without losing its working summary.
  • Give the assistant the evidence it needs. Paste a screenshot from the clipboard or attach logs, configuration files, text files and documents; text is extracted for analysis, while images are sent only to a vision-capable provider.
  • When something fails, Find the cause of the error builds a focused diagnosis. Create report produces a copyable record of the problem, server and time, commands, results, changes and final checks, with detected secrets hidden.
  • Risky configuration work gains a safety net: the assistant can preserve the original state, show the diff, apply a change, validate the result and offer a one-click rollback when the check fails.
  • The RDP assistant combines a persistent PowerShell command channel with visual control for GUI-only work. Screenshot access is explicit, read-only actions can continue automatically, and dangerous visual actions still require confirmation and a checkpoint.
  • The Windows installer and distributed application binaries are now signed with a valid Certum Authenticode code-signing certificate and trusted timestamp, so Windows can verify their publisher and integrity. The release also includes repeated security audits, more reliable cancellation and cleanup, corrected session restoration and live light/dark theme updates.
Version 2.8.3
  • Connecting through an RD Gateway now checks the gateway's own certificate as well as the server's. It is shown to you once and you are asked, and a gateway you did not approve means the session is not opened — that leg carries the same user name and password as the target, so it deserves the same care. Approved gateways are remembered apart from servers: saying yes to one is never read as saying yes to the other.
  • The built-in remote desktop engine was rebuilt for all three architectures — 64-bit, 32-bit and ARM64 — and verifies more strictly. Where you have no fingerprint of your own for a server, the full certificate chain and the host name have to vouch for it; only a certificate you looked at and accepted yourself relaxes that.
  • A remote desktop host that is not answering is now reported within seconds, and the reason is named in your own language — the connection was refused, there is no route to the host, the address does not resolve, or nothing answered in time. No tab opens to sit black while the engine waits out its own timeout, and how long the check may take is yours to set in Settings → RDP: from 3 to 30 seconds, 5 by default.
  • Which engine a remote desktop connection uses is decided per connection now. “Remember my choice” stores the answer on that one connection and nowhere else; left unticked it holds for this session only, and the question comes back next time. The engine picked in Settings gives newly created connections their starting point and changes nothing that already exists, and the button that brings the question back takes effect the moment you press it — it asks again, it does not switch anything over.
  • A connection created in BURSUcm for Linux or macOS now opens here on the engine it was saved with. Both clients write the built-in engine under one name, and the older spellings are still understood, so nothing has to be corrected by hand.
  • The RDP, SSH and VNC pages in Settings are laid out in two columns instead of one long scrolling strip, grouped by subject — what you trust about the server on the left, what the session then does on the right. The FTPS button that forgets trusted certificates moved to Security, beside the policy it answers to, and two long SSH labels now wrap instead of being cut off.
  • In the Georgian interface, the four “Continue with …” sign-in buttons are now built the same way.
Version 2.8.2
  • Signing in to your BURSU account now also works with Apple and GitHub, next to Google and Microsoft. The sign-in itself is unchanged — the same browser window as before — and Settings shows which service an account came in through.
  • A saved password reaches a remote session only when the certificate the server presented in that very session is the one you approved. A fingerprint remembered for the address used to be enough, so a server that had since changed its certificate was still handed the secret — in RDP and in VNC alike.
  • Copying files into an RDP session asks for permission at the moment the server reaches for them, the answer covers that one copy and nothing else, and the offer is withdrawn as soon as the clipboard moves on. Names carrying invisible Unicode characters — including the reversed-writing trick that makes an .exe look like a document — are refused.
  • Writing through a shortcut on a server now asks first, and refuses by default. Editing through a link the administrator placed is ordinary work; a link somebody else left in a writable folder is a way to aim your write at ~/.ssh/authorized_keys, and only you can tell the two apart.
  • A move onto a shortcut that fails halfway no longer takes the original with it — the file used to be gone from both ends while the error was still on screen. A file replaced on a server also keeps its own permissions instead of picking up the server's defaults, and the temporary file the write passes through is closed to everyone else before its first byte: a secret with mode 0600 stays 0600 the whole way.
  • New VNC profiles ask for encrypted VeNCrypt by default, a classic-VNC password warns before it crosses an unencrypted link, and the editor now says plainly that such a password is cut to 8 characters. A profile whose port was left at 0 no longer loses the protection against a downgrade along with it.
  • Private keys, jump hosts and cloud rows: a key kept on a network share or a removable device is refused before Windows can be made to authenticate to it, a jump host in a folder you are not allowed to see is no longer used to reach anything, and a cloud connection asks you before the secret follows a host, port, linked credential or jump host that was changed elsewhere.
  • Local accounts and downloads: a damaged or planted password record no longer accepts any password at all, older accounts are re-hashed in place with stronger protection, and a downloaded file can no longer replace a folder on your computer without an explicit go-ahead for that path.
Version 2.8.1
  • A whole folder can now be moved over SFTP — with F6, with cut and paste, or by dragging with Shift held. The app asks before it starts, and the original folder is removed only after every single file has arrived: anything put into it during the transfer, and anything behind a shortcut, keeps it in place.
  • Deleting a folder over SFTP no longer walks through a shortcut that points outside it. Such a link used to have its target's contents deleted — files you never selected — and the whole thing was reported as a success; the link itself is removed now.
  • Find and replace in the built-in file editor: “Replace all” in a large file no longer freezes the app — 4 MB of Russian text took twelve seconds and is now instant — a search no longer matches text that was never there, and “Replace” changes exactly what was found.
  • Edits waiting in the offline queue are protected: they are no longer overwritten when their encrypted file cannot be opened, a queue that fails to save now says so instead of quietly living in memory alone, and changing the master password can no longer leave them sealed under the key that no longer exists.
  • File copy and paste in RDP sessions: closing a tab no longer leaves the window frozen for up to a minute, a large file is copied whole instead of arriving empty, and a paste on the server always delivers the files you copied last.
  • Working with files on a server: a file edited in place keeps its permissions and its symlink, very long names no longer break a transfer, changing permissions over SFTP works for every mode, and replacing or merging a folder now says what it is about to do.
  • Switching the interface language now relabels an open terminal tab as well, and the file editor, the delete confirmations and the sync-conflict window received their missing Russian, Ukrainian and Georgian translations.
  • FTPS certificate pinning is verified properly instead of being skipped for a certificate the system already trusts, and a plain FTP session asks before it sends a saved password unencrypted.
Version 2.8.0
  • Overhauled SFTP and FTP file manager: two panes, background transfers, and a live transfer queue — pause and resume it, reorder the waiting transfers, run one immediately, or clear the finished entries.
  • Files and folders can now be copied and pasted between your computer and an RDP session, in both directions and in both engines — straight through the regular clipboard.
  • Closing an RDP session no longer risks hanging the connection engine: a rare deadlock in the session teardown was found and fixed.
  • The SSH library was updated with a security fix (CVE-2026-48798).
  • Dialog texts no longer get clipped in the Russian and Ukrainian interfaces.
Version 2.7.5
  • Permission to reveal a password is checked against the connection's own folder as well as the linked credential's. That same check also governs the private key, its passphrase, and whether PuTTY and WinSCP are handed the password.
  • Remote sessions stay on the certificate you approved: RDP verifies the pinned certificate on every reconnect, a VNC server can no longer talk the session down to an unencrypted one, and a connection through a jump host is refused instead of being made directly when the jump host cannot be resolved.
  • A password copied inside the app is handed to a remote session only if you trusted that host's certificate — the verification window now says so as part of what trusting means. A host you never trusted, or one you connected to just once, receives ordinary clipboard text only. Copied passwords also stay out of the Windows clipboard history, even while another program is holding the clipboard.
  • Changing the master password now re-encrypts the writes still waiting in the offline queue as well. They used to stay sealed under the key that no longer exists, which made them unreadable on every device.
  • Offline synchronisation: an edit made offline no longer comes back as a conflict against a change nobody made, and resolving a conflict with Keep my version no longer restores the values from before it.
  • Choosing a different cloud database in Settings now takes effect when you press Save — the selection was accepted and then quietly dropped.
  • A folder that links back to itself no longer takes the app down during an import, a backup or a file transfer, and serial connections open again when their settings were saved by another BURSUcm client.
Version 2.7.4
  • Right-clicking in a terminal now copies the selected text when there is a selection and pastes when there is none. This is the new default; the previous behaviour, where the right button always pastes, is still available in a connection's SSH options.
  • The Georgian interface now uses one consistent term for the master password across the app, the website and the documentation.
Version 2.7.3
  • The master password for a cloud database can now be set right in the app: every stored password is encrypted on your device before it is uploaded, so the master password itself never leaves your computer.
  • The master-password dialog gains a Generate button that creates a strong random password and shows it so you can write it down.
  • Setting a master password — in the app or on the website — now also encrypts the passwords that were saved before it existed; previously they quietly stayed unencrypted.
  • The database page on the website now shows a clear red warning while there is no master password, with a button to set one right there and a password generator.
Version 2.7.2
  • A security and reliability release: an audit of the whole codebase was carried out and every confirmed finding fixed. Backups keep stored SSH keys, the clipboard no longer leaks passwords into remote sessions, synchronisation stops losing edits, and helper programs are started only from their real install locations.
  • Backups now include the SSH private keys stored in the database. They were left out silently, so a connection restored from a backup could no longer sign in with its key.
  • The master password is verified properly, and a stored secret that has been damaged is reported as unreadable instead of being handed back as though it were the password.
  • A web tab is given the saved credentials only for the address the connection points at — any other page opened in that tab used to receive them too.
  • A file downloaded from a server can no longer disguise an executable by putting a colon in its name: the launch warning applies to every such file now.
  • Clipboard in VNC sessions: it is sent only from the tab you are working in, never a password copied from the vault, and text a server puts on the clipboard is no longer forwarded on to another server.
  • Synchronisation: an edit no longer disappears when a background sync and a save overlap, an offline delete no longer wipes out newer changes made by someone else, and the conflicts window now explains what the server refused and why.
  • The SFTP tab no longer leaves an authenticated jump-host session open when the connection fails.
  • PuTTY, WinSCP, mstsc and Explorer are started only from their real install locations, never from the current working directory.
  • Pinned FTPS certificates are kept apart from SSH host keys and have their own button in Settings — clearing SSH keys used to unpin every FTPS server as well.
  • Importing no longer freezes the window, renaming a folder with a credential assigned no longer leaves an empty ghost folder behind, and a .vnc file carrying an IPv6 address imports correctly.
  • The diagnostic log is capped and rotated instead of growing without limit, and after signing in with a different cloud account the previous account's offline cache is no longer used.
Version 2.7.1
  • The terminal now colours key words in its output — errors, warnings, successes, IP and MAC addresses and links — and the highlighting can be turned off in the settings.
  • A session tab can be reset from its right-click menu, reconnecting it in place instead of closing and reopening the tab by hand.
Version 2.7.0
  • SSH private keys can now be stored in the connection itself, encrypted with your master password. The key travels with your database, so a connection that needs a key works on every computer you sign in from — no more copying key files around or fixing paths that only existed on one machine.
  • The private key box sits in the connection dialog with a Browse button that reads a key file straight in, and a Delete key button that removes a stored key for good.
  • Authentication is now chosen in the connection dialog itself, and only the fields that choice needs are shown: username and password for password sign-in, the key and its passphrase for key sign-in.
  • A connection that signs in with a key and has no password is no longer shown as if it had no credentials — the connection list and the details panel now mark it with a key.
  • Connections and credentials record who created them, shown in the details panel. Ownership can be handed to any user allowed to edit that folder, so a leaver's entries need not stay in their name.
  • Stronger protection for saved secrets: every stored password, key and two-factor code is now cryptographically tied to the entry it belongs to, so it can only ever be opened in its own place.
  • The connection list now refreshes by itself when another device changes something — and only when something actually changed, so your selection and open folders stay where you left them.
  • The jump-host picker lists only the connections you marked as jump hosts, and creating or deleting a folder in a cloud database is no longer slow.
Version 2.5.3
  • Middle-click autoscroll works again in the built-in web browser: press the mouse wheel to scroll a device panel or web page by moving the pointer.
  • Web connection tabs now show the page address in the tab bar instead of a wrong "ssh admin@http://…" label; serial connections show the COM port and baud rate.
  • Offline-mode hardening: on a shared computer, signing in with a different account now clears the previous account's offline cache and queued changes, so one user can never see another's cached catalog. The database health-check is also rate-limited.
Version 2.5.2
  • Offline mode: when the network — or the database itself — is unreachable, BURSUcm keeps working from an encrypted local copy of your catalog, including a full start with no connection at all.
  • Changes made offline are queued and uploaded automatically as soon as the database is reachable again — items created offline get their real identity on sync, with linked credentials and jump hosts preserved.
  • A status bar shows what is happening: red while offline (with an offline-changes counter and a Retry button), amber while synchronizing, green Synchronized for a moment when done.
  • If the same item was changed both on this device and on the server, a conflict window shows the two versions side by side and lets you keep either one — passwords are never displayed there.
  • Availability is detected by pinging your database itself — every 30 seconds in the background and instantly when you act — so a dead server is noticed even while the internet is fine, and recovery is picked up within half a minute.
  • Signing out while offline now warns how many changes are still waiting to be uploaded.
  • Works for both BURSUcloud and direct PostgreSQL databases — PostgreSQL keeps an up-to-date local mirror on this computer.
Version 2.5.1
  • Fixed several rare cases where a saved secret could be lost: editing or duplicating a credential no longer clears its two-factor (TOTP) code, changing your master password or turning the vault off and on no longer makes saved SSH key passphrases unreadable, and a cloud database password can no longer be silently dropped when it is saved while the vault is locked.
  • Duplicating a session tab now carries the full connection — SSH key authentication, jump host, port forwards and RDP options — so the copy connects exactly like the original, key-only servers included.
  • More reliable sessions: an emoji or other multi-byte character split across the network no longer drops an SSH, Telnet or Serial session, and signing out now properly closes every open session and releases the serial (COM) port for the next connection.
  • Import and backup fixes: folders whose paths differ only in capitalisation no longer hide their subfolders and connections, and a portable (.db) export now always opens with the password you set for it.
  • Security hardening: FTPS connections set to ignore certificate errors now pin the server's certificate on first use, a malicious FTP server can no longer write files outside the download folder, and passwords are kept off external tools' command lines.
  • The terminal now shows a slim, elegant scrollbar, so scrolling back through long output is easier.
Version 2.5.0
  • VNC support: connect to VNC servers with TLS/VeNCrypt encryption, Tight, ZRLE and Hextile encodings, view-only mode, clipboard sharing and scaling — and import your existing .vnc files in one click.
  • New two-pane SFTP file manager: open any SSH connection's files in their own tab with a side-by-side local and remote view — a live transfer queue with progress, drag-and-drop, rename, delete, new folder or file, change permissions (chmod), copy path and properties, all from a right-click menu that adapts to what you clicked.
  • TOTP two-factor codes in credentials: store a Base32 or otpauth:// secret and get a live 6-digit code with one-click "Copy TOTP code", protected by the master-password vault.
  • Built-in password generator in the credential dialog: choose the length and character classes and copy a strong password in one click.
  • Customisable terminal appearance: pick a colour scheme (Classic, Dracula, Solarized and more), font family and size for your SSH, Telnet and Serial sessions.
  • Log session output to a file: turn on per-connection logging to keep a transcript of a terminal session; the log folder is configurable in Settings.
  • More native RDP options in the UI: RemoteFX, UDP transport, smart-card redirection and the GFX pipeline are now exposed in the RDP options dialog and as global defaults.
  • Wake-on-LAN: send a magic packet to a connection's MAC address straight from its right-click menu to power on a sleeping machine.
  • The BURSUcloud account card now shows the logo of the provider your account signs in with — Google, Microsoft or BURSUcloud.
  • Cleaner menus: the File and Help menus use the standard arrow cursor with a subtle hover, and the keyboard-shortcuts panel in Settings now uses a tidy two-column layout.
  • More reliable sessions and files: multi-byte (UTF-8) terminal characters are no longer garbled, serial hardware flow control works correctly, settings and database snapshots are saved atomically, and an interrupted download can no longer leave behind a half-written file that looks complete.
  • Security hardening across the credential vault, BURSUcloud sign-in and remote-file access paths.
Version 2.3.1
  • Verify RDP servers before connecting: the first time you open an RDP connection, BURSUcm shows the server's certificate fingerprint and lets you trust and remember it — the same trust-on-first-use protection already used for SSH. If a server's certificate later changes, you're warned before connecting.
  • Manage trusted RDP certificates in Settings: a new "Forget all trusted RDP certificates" button clears them independently of your SSH host keys.
  • Diagnostic logs now save to your user profile folder instead of the installation folder, so logging works even when BURSUcm is installed under Program Files.
  • Stronger protection for your data: encrypted backups and the local sign-in now use a stronger key-strengthening level, and the connection to bursucm.com is certificate-pinned for extra protection against network interception.
  • Safer CSV export: an exported connection list can no longer let a specially crafted field run as a spreadsheet formula when the file is opened.
Version 2.3.0
  • Our own built-in RDP engine — BURSUrdp: the remote desktop is now drawn directly inside BURSUcm by our own RDP engine, built in-house, from one self-contained library, with no external processes and no side-by-side DLLs — giving us full control over its reliability, security and features.
  • Multiple monitors for RDP: each extra monitor opens as its own movable window that you can drag onto your second screen and switch to full screen (F11). Its resolution follows the window size, and its position and full-screen state are remembered for next time.
  • Smoother RDP graphics: H.264 video decoding for crisper video playback and animations.
  • Fixed a black screen that could appear on the first RDP connection after launching the app.
  • DOMAIN\username logins now work for RDP, and disabling Clipboard in a connection's RDP options now actually turns clipboard sharing off.
  • Folders can now be renamed, moved under another folder, or promoted to the top level in one step — from the folder's Edit dialog.
  • The RDP engine ships as a single self-contained file for 64-bit, 32-bit and ARM64 Windows; added a Reset engine choice button in Settings; and completed the Russian, Ukrainian and Georgian translations across the app.
Version 2.2.2
  • Web tabs: a page that opens a new window — a link set to open in a new tab, or a device panel's pop-up — now opens as a new tab inside the app instead of a separate browser window.
  • Web tabs are safer with "ignore certificate errors": the app now remembers the panel's certificate the first time you trust it and shows its SHA-256 fingerprint. If the certificate later changes it warns you and asks again, instead of silently accepting any certificate for that host — and the exception, along with any saved login, stays scoped to that exact host.
  • The RDP password is no longer placed on the RDP client's command line, where other programs on your PC could read it — it is now handed to the RDP client privately over its input stream.
Version 2.2.1
  • You can now arrange connections and credentials inside folders in any order you like — hover a row and use the up/down arrows. The order is saved in your database and synced everywhere: the portal, the Android app and the Linux/macOS app show the exact same order.
  • All reorder arrows (folders included) now appear only while you hover the row, keeping the tree clean.
  • Fixed unreadable highlighting in the terminal: modern shells (bash 5.2+) highlight pasted text until you press a key, and that highlight rendered as gray-on-gray. It now shows as dark text on a light block, like in other terminals.
Version 2.2.0
  • Terminal paste reworked: Windows line endings no longer arrive as an extra Enter per line (or as ^M characters inside editors and heredocs), and bracketed paste is supported — shells and REPLs that enable it receive a multi-line paste as one editable block instead of executing it line by line. The multi-line paste confirmation still guards every paste path.
  • Fixed a freeze when copying text in the terminal while another program (for example the VirtualBox shared clipboard) was holding the Windows clipboard open.
Version 2.1.0
  • One import window for everything: bring your connections over from WinSCP (saved passwords are decrypted automatically), PuTTY, mRemoteNG, Remote Desktop Manager, Royal TS, OpenSSH config files and .rdp files — with a folder-tree preview where you tick exactly what to import and pick a target folder
  • The same import and export now live on the web portal too: move connections between the app, the portal and other tools with one portable backup format
  • Portable backups (.bcmbackup): export with a master password (encrypted) or without one for quick transfers — the app warns clearly when passwords would be stored in plain text; CSV export without passwords is also available
  • Your cloud database now carries its own users: database users are stored inside the database itself, so a full backup or SQL dump moves them along with everything else, and changing the database handle is instant
  • Sign in with Microsoft: personal and work Microsoft accounts now work everywhere Google sign-in does — on the website, in the app and during first-run setup
  • SFTP file panel: a real transfer queue with progress bars and speed, drag & drop from Windows Explorer, and full folder upload/download (the whole tree is mirrored)
  • FTP panel gets the same transfer queue and recursive folder transfers
  • Duplicate with cwd: duplicate an SSH tab and the new session opens in the same directory you were working in
  • Serial connections now auto-detect COM ports with friendly device names and a refresh button
  • Friendlier first run: a redesigned database chooser with visible sign-in fields and a clear database list, PostgreSQL and local storage tucked behind buttons, a first sign-in hint showing the default admin credentials, and one-click switching between local and BURSUcloud sign-in
  • Deleting a cloud database now requires typing a confirmation phrase, so a whole database can never be lost to a stray click
  • An Import / Export button on the Home tab, clearer user-management labels explaining members vs database users, the database handle editable right from the user dialog, and a slimmer credentials tree that matches the connections list
Version 2.0.0
  • Jump host / bastion support: route an SSH connection through one or more intermediate servers (ProxyJump), with the host key verified against the real target — the terminal and the SFTP file panel both work through the tunnel; mark connections that may be used as jump hosts
  • Per-connection port forwarding: define local (-L) and remote (-R) tunnels that open automatically with the session and work through a jump host too
  • SSH agent support: use keys from the Windows OpenSSH Agent (named pipe) so a key passphrase is entered once in the agent instead of on every connection
  • Split view: run two sessions side by side in one tab — open another server in a split or duplicate the current one — and switch between vertical and horizontal layout on the fly
  • Broadcast input: type once and send the same keystrokes to every open session at once, with a bright banner showing how many sessions are receiving input
  • Keyboard shortcuts throughout the app (new connection, close and switch tabs, jump to a tab, focus search, lock the vault and more), with an on/off toggle and a shortcut legend in Settings
  • Command snippets: a shared, synced library of commands you send into a terminal in one click, with {placeholder} prompts filled at send time, managed from a dedicated window and from the web portal
  • Full cloud team access: manage both database users and shared portal members from the app, each with per-folder connection and credential permissions (view / edit / reveal passwords)
  • The database owner is always an administrator and can no longer be demoted or removed, so a cloud database is never left without an admin
  • Live status dot on every session tab — yellow while connecting, green when live, red when the connection drops — so you can spot a dead session without opening the tab
  • One-click reconnect: when a session drops unexpectedly, a Reconnect button (press Enter) appears right inside the session instead of having to close and reopen it
  • Safer paste: pasting multi-line text into a terminal now asks for confirmation with a preview, protecting against hidden commands copied from a web page
  • Plus polish across the board: a new Other tab in Settings, cleaner action buttons and a sticky footer on the web portal, and numerous smaller fixes
Version 1.7.5
  • Our built-in RDP engine is now the primary one, with Microsoft RDP still available as an alternative
  • Fixed the app interface freezing during an active RDP session — the sidebar, panel and keyboard shortcuts now stay responsive
  • Embedded RDP connections are now much more reliable (fixed a timeout that sometimes prevented a session from connecting)
  • Fixed local drive redirection — your drives now actually appear on the remote desktop
  • Fixed printer and microphone redirection (previously enabling them could break the connection entirely)
  • Clipboard redirection can now be turned off correctly for an individual connection
  • New: a friendly notice before your first embedded RDP connection (with a "don't show again" option)
  • Native RDP now closes the tab by itself when the server ends the session (instead of leaving a gray window)
  • The bundled RDP engine is now a single self-contained file (no DLLs) for x64/x86/ARM64 — including 32-bit Windows for the first time
  • Keyboard and mouse focus is now kept after switching monitors
  • Full Screen now expands correctly from Full Window
Version 1.7.3
  • Full Screen now shows your open session tabs in the top toolbar — switch, reorder by dragging, close, and right-click for Duplicate / Pin / Close, all without leaving full screen
  • Duplicating a connection now opens the copy right after the original instead of at the end
  • Connection and credential pages now have a "Go back to open sessions" button that returns you to the session you came from
  • Disconnecting a session now returns to the Welcome tab instead of a blank detail page
  • Removed the close (X) button from the full-screen and full-window toolbars to avoid accidentally quitting the app — use Disconnect or Exit
  • Fixed white flicker while dragging session tabs, and the full-screen toolbar no longer lingers after minimizing and restoring
  • Crisper buttons (no more blurry labels) and a roomier Settings window
Version 1.7.2
  • Connection details now show the linked credential's name instead of an internal ID, and add a Copy button next to the host address
  • New Full Screen mode: a session fills the whole screen with an auto-hiding top toolbar (pin it to keep it visible) — press F11 to exit
  • The previous maximized behaviour is now called Full Window, with Minimize and Close buttons in its toolbar
  • Improved Georgian translation and minor fixes
Version 1.7.1
  • Home dashboard: the Vault card's Security button now opens Settings directly on the Security tab
  • Home dashboard: the Administrator card now opens user management directly
  • Minor visual and behaviour polish
Version 1.7.0
  • New Home dashboard tab: a pinnable, closable welcome screen with quick stats, recent and favorite connections, vault status and one-click actions
  • Restore last session: reopen the connections that were open when you last closed the app — on demand, or automatically on startup (Settings)
  • Automatic update notifications: the app can check for a newer version and let you know, with a one-click link to download (toggleable in Settings)
  • Click any connection while a session is open to view its details page without losing your open tabs
  • Favorites: the star now updates instantly and clearly shows when a connection is favorited
  • Fixed: editing a connection now reliably saves cleared fields (tags, notes, and more)
  • Refined empty-state graphics and overall visual polish
Version 1.5.9
  • The app now bundles the .NET 8 runtime — no separate .NET install required; just download and run
  • Much faster startup: ReadyToRun precompilation plus optimized BURSUcloud loading (the catalog is now fetched once and in parallel)
  • Native builds for x64, x86 and ARM64 — the installer automatically installs the right one for your PC
  • Security: the SFTP file panel now always verifies the SSH host key (no fallback that could skip verification)
  • Security: BURSUcloud connections to any non-local host are forced to HTTPS, so credentials are never sent over plain HTTP
  • Minimum password length raised to 8 characters
  • Improved Russian, Ukrainian and Georgian translations
Version 1.5.8
  • App settings are now stored fully encrypted on disk with Windows DPAPI (tied to your Windows account) instead of a readable file — including cloud database identifiers and the remembered vault key. Existing settings are migrated automatically
Version 1.5.7
  • Folder order and expanded/collapsed state are now stored in the database and synced across all your devices and the web portal, instead of being saved per-computer
  • Fixed FTP/FTPS connections and a crash that could happen when pressing Disconnect
  • Unexpected errors no longer close the app — they are caught and can be logged for diagnostics
Version 1.5.3
  • Complete interface localization — every dialog and message (SSH, RDP, FTP and Serial options, the SFTP file panel, BURSUcloud sign-in and the master-password screens) is now fully translated into Russian, Ukrainian and Georgian
  • New database snapshot backup: export or import a master-password-protected snapshot of your database; local mode can also import an existing SQLite database file
  • Full FTP and FTPS support — a new FTP connection type with explicit/implicit TLS, passive mode and a dual-pane file browser
  • Various stability fixes and interface polish
Version 1.5.0
  • Major architecture upgrade: BURSUcloud connections no longer go through an SSH tunnel — the app now talks to our own purpose-built, zero-knowledge HTTPS API
  • Your master password never leaves your device: all encryption and decryption happens locally, the server only ever sees ciphertext
  • Faster, more reliable BURSUcloud sync — no more tunnel handshakes, dropped connections, or SSH key management for end users
  • Simplified sign-in: log into BURSUcloud with your email/password or Google account directly, no manual connection tokens to copy or paste
  • Hardened server side: removed the legacy token-based pairing system entirely, closing off an old attack surface
  • Smaller, cleaner connection setup dialog now that tunnel/token configuration is gone
  • Numerous internal stability and security improvements across the BURSUcloud client and server
Version 1.1.2
  • Security: updated the bundled SQLite engine to address a High-severity advisory (GHSA-2m69-gcr7-jv3q)
Version 1.1.1
  • New Serial (COM port) connections with a full options dialog (baud, data bits, parity, stop bits, flow control)
  • New Web (HTTP/HTTPS) connections in an embedded browser tab, with saved username/password and a mini toolbar
  • Connection details now show the username and password with Copy buttons and a Show/Hide toggle, including credentials inherited from a saved login
  • Clear prompt to enter the master password when a saved password is locked
  • Prettier connection-type picker with per-type icons, matched on the BURSUcloud web portal
  • Various fixes and cleanup (correct icons, encoding, and translations)
Version 1.1.0
  • Per-connection SSH options (key auth, timeouts) and per-connection RDP options (display, performance, redirection, security), each with global defaults in Settings
  • SSH host-key verification (Trust On First Use), like PuTTY, to protect against man-in-the-middle attacks
  • Terminal right-click modes: paste, smart copy/paste, or a Copy/Paste context menu
  • Standard ANSI terminal colours so Midnight Commander and other TUI apps render correctly
  • Sessions now close automatically when the remote side disconnects (Ctrl+D / exit)
  • Folder highlight on click and "Add connection" directly into the selected folder
  • Redesigned BURSUcloud account card with Google / BURSUcloud provider logos and automatic database loading
  • Removed the old bundled RDP engine; RDP uses the native Windows control plus "Open with Remote Desktop"
Version 1.0.1
  • Minor security fixes
Version 1.0.0
  • First public release of BURSU Connection Manager. Windows installer (Any CPU)
Version 2.7.0
  • Direct PostgreSQL setup now uses clear host, port, database, user, password and TLS fields, can test the saved connection, and can export or import a password-protected configuration file for a colleague.
  • Shared PostgreSQL vaults now use one portable data key per database. Changing the master password no longer re-encrypts every secret, and concurrent changes cannot be silently overwritten.
  • Legacy vaults migrate safely without losing access, including databases with older KDF metadata; remembered master passwords remain attached to the correct database and survive migration or temporary connection failures.
  • Folder permissions are safer and clearer: moving or deleting folders preserves grants, partial rights are displayed correctly, root-level items have their own grant, and members can edit their own account and password.
  • Deleting a folder through BURSUcloud is atomic, so a failed request cannot leave the catalogue half-modified; an outdated portal is refused before any destructive step.
  • Smaller fixes across database and account screens: setup saves a PostgreSQL catalogue only after it has answered, “Remember master password” works during initial setup, portable backups contain a complete vault, TLS labels say what is actually verified, and the account card shows the provider that really signed you in.
Version 2.5.1
  • Streamed replies reach the screen once per frame instead of once per token, and the assistant panel follows the stream only while you are at the end, so an earlier answer can be re-read while the model is still writing.
  • Closing a WinRM tab, or losing its connection, now stops its assistant as an SSH tab does; it used to keep running against a terminal that was gone.
  • Roll back restores the change of the card you clicked. It always restored the most recent change, whichever card's button was pressed.
  • Reset on an SSH tab gives the assistant a fresh session. It used to keep the old one and answer “Start the AI assistant for this SSH session first”.
  • Name lookups ask before running: nslookup, getent hosts, ping of a host name and openssl s_client wait for your click like curl and wget do, because every label of a queried name reaches whoever runs that zone. An address such as ping -c 3 8.8.8.8 still runs on its own. Secret Shield also hides values named DB_PASS, ROOT_PW or MYSQL_PWD and keys from xAI, Groq, GitLab and DigitalOcean.
  • A command is no longer reported as finished before it was typed. A completion mark from the previous prompt that arrived while the assistant waited for the screen to settle counted as the new command's result, and the “> ” prompt of an open quote was taken for an idle shell, which typed the next command into the string.
  • Provider failures are shown, not swallowed: a timed-out request looked like a pressed Stop, an error in the middle of a streamed reply ended it as if complete, and a rejected key was retried three times before you saw it. A reply that quotes a YAML block before its shell command no longer proposes the prose between them as the command.
  • Smaller things: 37 messages the panel and the AI settings showed in English are translated; archiving a chat holds across tabs; long reasoning text wraps instead of widening the panel.
Version 2.5.0
  • Libraries updated to their latest long-term-support versions. Nothing changes on screen, and the packages carry everything they need inside them, as before. From this version the app needs macOS 14 or newer; on Linux every distribution it already supported stays supported.
  • A tunnel that cannot listen says why. On Linux and macOS a local (-L) or dynamic (-D, SOCKS5) tunnel on a port below 1024 fails because those ports belong to root — the terminal showed only “Permission denied”, and the same connection worked on Windows, which has no such limit. The failure line is now followed by a plain explanation, and the connection editor warns while such a port is being typed. 1080 is the customary SOCKS5 port.
  • The User Management window opens complete. On a BURSUcloud database it used to assemble itself in stages — an empty list, then the accounts, then the groups, then the buttons — because its content was five round-trips to the portal served one after another. It is now fetched as one answer, in parallel, before the window opens; what appears is the finished window, and an edit refreshes it in place.
  • A right inherited from a group is drawn green in the person's card, locked and labelled “Inherited from group” — as designed, and as the Windows edition draws it. It came out in the same blue as the account's own rights, so the two could not be told apart.
  • The note “tmux is not installed on this server — plain shell” no longer vanishes a second after connecting. The files panel's bootstrap, which follows the shell's current directory, ended by erasing the screen from a row above the prompt and ran on a timer at every connect, landing exactly on the note. It now runs only when the files panel is open, as in the Windows edition.
  • Smaller things. The assistant reads a streamed reply to its end without holding the service on the network; the tunnel status lines at the top of a terminal can no longer carry control sequences from a stored host name; and a renamed BURSUcloud database shows its new handle in the User Management window at once.
Version 2.3.2
  • The app remembers who signed in again. In 2.3.1 every start asked for the password afresh: the note saying who was here last, and the folder holding each account's own settings, host keys, logs and offline copy of the catalog, were both swept aside at launch before anything could read them — and re-created, so nothing ever looked missing. They are left alone now, and whatever an earlier start put aside is moved back the first time this version runs. Nothing was lost: the sign-in saved before the update is found again.
  • A cloud account is no longer shown as holding every folder. An account created in the portal carries an explicit list of what it was granted, and an empty list means it was granted nothing of its own — which is exactly an account whose rights come from a group. The user's card read that as the old rule for accounts from before per-folder rights, “never restricted, so it sees everything”, and drew a ticked “All connection folders”: Read on every folder, for someone who had been given none. Saving the card would have written that as a real grant. Accounts on a local database from before per-folder rights keep the old meaning.
Version 2.3.1
  • User groups. A group is a named set of per-folder rights, and everyone in it inherits them — so a team's access is granted once instead of being re-entered for every account. Rights that come from a group show in the person's card as a green tick, locked and labelled “Inherited from group”, beside the ones granted to them personally. Groups work the same way in the local database, in your own PostgreSQL and in a BURSUcloud database; a group never makes anyone an administrator.
  • One folder per account on this computer. Everything the app keeps outside the database that belongs to a person — trusted host keys and certificates, logs and session transcripts, the offline copy of the catalog, the assistant's chats, the browser tabs' profile, the remembered vault key and “remember me” — now lives in that account's own folder, and the app switches to it the moment someone signs in. Nothing is deleted when the next person signs in: come back and your own state is where you left it. An install updating from an earlier version hands its files to the first account that signs in, and an administrator can remove a person's folder from the users window.
  • The Settings modal is everyone's, and it matches the Windows edition tab for tab — the same sections, labels, option texts and hints. Because those preferences are now a person's own on this computer, every user edits and saves the SSH, RDP, VNC and WinRM policies, the session defaults and the logging; before, a non-administrator's changes were dropped silently while the dialog said “Saved.” Remembering and forgetting the master password is now each signed-in user's own decision, and the whole-database Data tab is the administrator's alone.
  • A folder is picked from the tree, not typed as a path. Everywhere a record's folder is chosen — the connection editor, the credential and SSH-key editors, the parent folder in Edit Folder, and “Move to folder” — the field is now a drop-down of the folders you already have, in the tree's own order and folded the way the tree is folded. Folders you may not save into are shown greyed rather than hidden, so the ones under them keep their place, and the root row reads “(root — top level)”.
  • A right taken away stops working at once. Until now a demotion, a deletion or a withdrawn group membership held until the app was restarted, administrators included. The signed-in person's rights are now re-read on every catalog reload and again by every request that hands out a secret: revealing a password, a one-time code, the parameters of a remote-desktop session, a CSV or database export, the portable copy and every call to the assistant. Stopping a running assistant still works without the right — taking the right away must not leave anyone unable to interrupt it — and a group dialog left open cannot restore rights withdrawn meanwhile.
  • A session through an RD Gateway now pins the gateway's certificate. The app checked that certificate before connecting and then told the engine nothing about it, so the engine accepted whatever the gateway presented during the real handshake; and when the certificate could not be obtained at all, the check was skipped and the session went ahead — a machine answering on the gateway's address would have received the username and the password. The approved fingerprint now travels to the engine, which refuses a gateway that presents anything else, and under the “trust on first use” and “strict” policies a gateway whose certificate cannot be read is refused with an explanation.
  • Smaller things. A web tab's “ignore this certificate” answer belongs to the person who gave it: the trust is keyed to their own profile and cleared when the profile changes, so one person's answer no longer decides for the next, and a web tab that fails to start shows the error instead of a blank page. The service's own error messages arrive in all four languages — they used to come in English whatever the app was set to. Electron 43.6.0.
Version 2.3.0
  • Windows servers, over WinRM. A new connection type beside SSH: PowerShell runs over PowerShell Remoting and cmd.exe over WinRS, on plain HTTP or over HTTPS, where the server's certificate is trusted once and pinned the way an SSH host key is. Output streams while a command is still running, Ctrl+C stops the pipeline, errors arrive as errors with the line they happened on, and Read-Host, -Confirm and a missing mandatory parameter ask and wait — a password is answered under the session key, never as text on the screen.
  • The WinRM terminal behaves like a terminal. “clear” and “cls” clear this window at once instead of answering with two paragraphs of red; Write-Host keeps its colours and “-NoNewline”, and what a script writes through $host.UI is drawn rather than dropped; a cmd.exe session can be set to a codepage such as 866, so Cyrillic typed into it comes back readable; a paste of several lines runs all of them; and a “Password:” prompt from a cmd program hides what you type. The trust questions — the certificate on HTTPS, the once-per-server confirmation on plain HTTP — now get the three minutes they may take instead of the tab giving up after one while the dialog was still open, and the plain-HTTP one no longer poses as an untrusted certificate with a fingerprint to verify.
  • Keep an SSH session in tmux. A checkbox in the SSH options, with a session name beside it, makes the connection attach to that tmux session when the shell opens — created the first time, rejoined after that, so a dropped connection returns you to the same screen with the same programs still running. Detaching (Ctrl+B, D) returns to the plain shell rather than closing the tab; the tab reads “(tmux)” while you are inside, the wheel scrolls tmux's own history, the Files panel still follows “cd”, and the assistant still sees when a command ends. A server without tmux says so in the terminal, and the session goes on without it.
  • A SOCKS5 proxy through the SSH connection (ssh -D). A third kind of tunnel beside local and remote forwards: the tunnels editor now offers “dynamic”, which opens a SOCKS5 proxy on 127.0.0.1 at the port you choose and carries every connection made to it through the session. A browser, curl or a database client pointed at the proxy reaches hosts only the SSH server can route to, and names are resolved on the server side as well (socks5h). The proxy listens on 127.0.0.1 only — it is never offered to the network the computer is on.
  • The assistant's terminal is your terminal. While one of its commands ran, whatever you typed was held back until the command finished — a password typed at a sudo prompt never reached sudo, and once you pressed Ctrl+C it was typed into the shell in clear. Keystrokes now go to the terminal at once, always. A prompt meant for you — a password, a yes/no — is waited for, with “Waiting for your input in the terminal” on the card and no clock running, and the assistant then sees the whole result; a long upgrade that keeps printing is no longer cut off at a fixed minute, because the timeout counts silence. And your environment stays: a pager no longer stops at “Press RETURN”, and tools that keep their configuration in your home directory find it.
  • The assistant asks before a PowerShell line can do harm. It now classifies by PowerShell's own rules: a method call anywhere in the line — “$_.Delete()”, “(Get-Service x).Stop()” — a static member and every script block are judged, so “Get-ChildItem | ForEach-Object { $_.Delete() }” asks for the click instead of passing as a reading command. Reading a file that may hold secrets (the SAM and SECURITY hives, web.config, appsettings, keys, .ssh), any UNC path and “-ComputerName” ask too, because what is read goes to the AI provider with the output.
  • Findings of the pre-release audit. A single pasted line with a line break at its end ran on paste — the break is dropped now and you press Enter yourself, so a page with a hidden command cannot run it for you. A crash record waiting for the next start carried the raw error text, connection strings included, in a file that backup tools read; secrets are cut before it is written. A server that printed “tmux=on” in its banner could switch the tab into tmux mode; the marks are read only after this side has typed its own line. The connection's name, notes and tags reach the assistant as reference data rather than beside its rules, so nobody with edit rights on a shared folder can write rules of their own into them, and a “sed” script runs without the click only in its plainly non-executing forms. And the hints under plain HTTP and “proceed past certificate errors” now say what each actually gives up.
  • On screen and under the hood. Electron 43.5.1, taken for its fix to intermittent startup crashes on Linux during font initialisation. A connection whose username was “Administrator” showed it as “Администратор” — the localizer translated values, not only labels — and the broadcast banner and the last-session card were half English in every language because a number was pasted into the sentence; all three read right now.
Version 2.2.1
  • The AI assistant can now run interactive programs. “htop”, “top” and anything else that takes over the screen were refused outright — the assistant could only start a command and wait for it to finish, and htop never finishes, so the wait could end only in a timeout and a Ctrl+C nobody asked for. It now starts such a program, lets it draw its first screen and hands the terminal back to you.
  • Answers appear as they are written. The assistant collected the whole reply and showed it in one piece at the end, with the “thinking” line already switched off — so the panel sat empty for as long as the answer took, which reads as a hang.
  • The assistant's chat is far faster, and macOS felt it worst. A reasoning model writes its answer token by token, and every single token redrew the entire conversation — about fifteen hundred redraws for one answer, each of them re-reading every message in the chat and forcing the whole column to lay out again. Only what actually changed is redrawn now.
  • Code inside an answer reads as text again. Every backticked word became a full-width grey box with its own Copy button, so a file path named in the middle of a sentence cut that sentence into three stacked blocks. A command still gets its own block and its Copy button; a name inside a sentence stays inside the sentence — and the whole answer can be selected, which is how a path or a value is taken out of one.
  • The assistant is no longer frozen out by “sudo su”, “mysql”, “psql” and the like. Inside those the terminal cannot report that a command has finished, so the assistant refused every request and told you to press Enter or Ctrl+C over a command line you had never typed. It recognises their prompts now, says which case it is when it does refuse, and no longer claims the terminal is busy from its own memory of an earlier answer.
  • Problem reports, after two independent audits: identical faults group together whatever the privacy switches are set to — the grouping used to change with them; server names, logins and IPv6 addresses are masked more carefully while the stack itself stays readable; and declining one fault no longer silences a different one, so two alternating faults stop asking at every start.
  • Problem reports: closing the window cancels the send instead of leaving it running, the fields freeze while a report is in flight so the preview cannot drift away from what is being sent, and a report that arrives after you close the window is no longer recorded as declined.
Version 2.2.0
  • Report a problem, without leaving the app. When something goes wrong the app offers to send a report about it, and Help → Report a problem is there at any other time. You get a report number back, and we get the error itself instead of a description of it.
  • You see exactly what will be sent, before it is sent. “Show what will be sent” is not a summary of the report — it is the report, rebuilt as you type and as you tick the boxes. Nothing leaves the computer until you press Send: there is no background upload and no crash beacon.
  • Passwords, keys and tokens are stripped on your computer, before the preview. Server addresses, account names and IP addresses are replaced with placeholders as well — in a connection manager those are as private as a password — and a checkbox puts them back when you decide they help.
  • When the report already carries the error, writing anything is optional, and the fields say so. People who did not feel like writing used to press Cancel — and then nobody had the error either.
  • A crash is offered at the next start — and the window comes back by itself. A window that stops responding is now replaced instead of being left dead on screen, and the fault behind it is recorded; the same applies when the background service stops unexpectedly. The next launch asks whether to send the report, with the error already inside, and a no is remembered for a day so a fault that repeats does not ask at every start.
  • A screenshot only when there is something to see. It is taken at the instant of the fault, before any of our own windows are drawn — an earlier attempt photographed the very dialog that was asking about the error — it is off by default, and it is shown to you before it is sent. Reports from the Help menu and offers after a crash carry none.
  • A send that fails loses nothing. The dialog stays exactly as you left it, and “Save to file…” writes the whole report — the readable text and the raw data — ready to be mailed to support@bursucm.com.
  • Settings → Other has a switch that turns the offers off. Off means the app stops asking: no dialog after an error, no question at the next start, no entry in the Help menu. It never meant “report silently” — nothing was ever sent without Send.
Version 2.1.1
  • Local database: a database created by 1.8.x could not sign in after updating (“no such column: ai_enabled”), and one created by 2.0.0 lost its credential list in 2.1.0 (“no such column: kind”). Those versions had marked the database as fully migrated, so the step that adds the newer columns was skipped. It now runs again on the first open, and the client checks the columns themselves instead of trusting the version stamp.
  • User permissions: the example folders a new database starts with — and any folder typed into a record's folder box — were missing from the permissions screen, so no right could be granted on them even after a rename. The screen now lists every folder the tree shows.
  • PostgreSQL: editing or deleting a connection, credential or snippet failed with “could not determine data type of parameter”, and importing a backup was rolled back without a message. The statements now carry the type PostgreSQL needs.
  • PostgreSQL: a new, empty database now opens with the same example folders, connections, credentials and snippets as a new local file.
Version 2.1.0
  • SSH keys are now credentials. A record in the credential store can hold a private key, its passphrase, the public half and a comment, and you link it to a connection exactly as you link a password — jump hosts included. A connection pointed at a stored key used to fail with “key not found”, because only the connection’s own key field was read at connect time.
  • The connection editor is the desktop’s two-column dialog: what the connection is and where it is filed on the left, how it logs in on the right. The credential, the authentication method and the key used to sit a scroll apart in one narrow column, with the group, the owner and the notes below the fold entirely. The password row now follows the method actually in force rather than the stored column, so a key connection no longer shows an empty box under a “Password” label.
  • Choosing a credential is now a folder tree with a glyph for each kind, and key records are offered only where a key can be used. Picking one settles the authentication method and locks the fields it owns, each labelled with the record it comes from; unlinking fills those fields back from the connection itself instead of leaving another record’s material behind. Switching the protocol drops a link the new type cannot use, and “+ Add credential” asks which kind you want.
  • Access permissions have their own window with two tabs, and an administrator — who holds every folder — is no longer shown a table with nothing to say. One folder tree that folds, with search and “Only granted”, replaces two fixed-height tables that grew with the folder count and gave three scrollbars for a single gesture. Ticking “all folders” now ticks and locks the individual rows, because a right that comes from the wildcard cannot be taken back one folder at a time.
  • Folders come before records everywhere. Both trees and the credential picker walk depth-first — the folder’s heading, its subfolders, then its own records — and the picker follows the tree’s order and its shared collapsed state instead of building an alphabetical list of its own. A folder whose name is spelled with different capitalisation in a grant and in the tree is one folder again, not two rows with the rights on the wrong one.
  • Quitting moments after an RDP session closed could end the app with a crash instead of a clean exit: the shutdown waited only for the sessions it could still see, and a teardown that had begun a millisecond earlier was invisible to it. Every teardown is now tracked until it finishes, and the quit waits for the ones already in flight.
  • The owner picker never dead-ends: portal administrators are always offered, an owner chosen while offline survives the reconnect, and a duplicated connection belongs to whoever copied it. The Owner column also stopped flipping to “Unknown” after you opened a row without an owner, and the AI chat’s copy confirmation appears again — the translation layer was re-imposing a dictionary word over live text. Commands inside a finished AI reply are now copyable chips.
  • Fixes from two audit passes over the credential store: renaming a folder now re-checks every record that moves with it, so a rename can no longer carry a key into a folder where someone else may reveal it; a remote-to-remote FTP copy no longer stages the file body in a world-readable directory under /tmp; and the icon probe uses a private temporary directory instead of a fixed name another local account could create first.
Version 2.0.0
  • Meet the AI assistant for SSH sessions. It understands the active terminal, explains output, investigates failures and can carry out complete administration tasks without making you copy commands between windows.
  • Choose the intelligence that fits the job: OpenAI, Google Gemini, Anthropic Claude, DeepSeek, OpenRouter, Together and xAI are supported alongside local Ollama, LM Studio and llama.cpp models. Provider-specific clients, model discovery, connection testing and encrypted API-key storage are built in.
  • Automation is guarded by what a command actually does, not by a brittle list of command names. Read-only work can run automatically; anything that may change the system is clearly explained and waits for approval, with exit codes, timeouts and interactive commands handled explicitly.
  • Secret Shield detects and redacts passwords, API keys, private keys, cookies, tokens, database connection strings and .env contents before text is sent to an AI provider. Chat history is encrypted locally, and provider-side storage controls are shown only where the provider supports them.
  • AI chats are now a real workspace: create, rename, archive, restore and delete conversations; pin a chat to a connection; resize the panel and keep that size; see context usage; and compact a long conversation without losing its working summary.
  • Give the assistant the evidence it needs. Paste a screenshot from the clipboard or attach logs, configuration files, text files and documents; text is extracted for analysis, while images are sent only to a vision-capable provider.
  • When something fails, Find the cause of the error builds a focused diagnosis. Create report produces a copyable record of the problem, server and time, commands, results, changes and final checks, with detected secrets hidden.
  • Risky configuration work gains a safety net: the assistant can preserve the original state, show the diff, apply a change, validate the result and offer a one-click rollback when the check fails.
  • The interface has been rebuilt around the new workflow: a consistent chat and Settings design, live light and dark themes, clearer tabs and dialogs, reliable focus, movable modals, resizable pinned panels and layouts that remain usable in narrow windows.
  • Linux packages are freshly built for Debian/Ubuntu, Fedora/RHEL and Arch families, published through signed APT, DNF and Pacman repositories, and include a self-contained clipboard helper. macOS images are built for Intel and Apple Silicon, Developer ID signed, notarised by Apple and stapled for offline verification.
Version 1.8.6
  • Copy and paste in the terminal work again. Selecting text to copy it, right-click copy and right-click paste had done nothing since 1.8.2 — silently, on every platform; only Ctrl+V kept working. The “Copy Username” and “Copy Host” actions in the sidebar were broken by the same fault and are back as well.
  • Everyday actions no longer re-download the cloud catalog. Starring a favourite, connecting, saving or deleting used to trigger a full catalog fetch every time; now the app answers from its local snapshot, still picking up changes from your other devices within seconds — so these actions feel instant and the server sees a fraction of the traffic.
  • VNC no longer crawls on large screen updates: decoding a full-HD frame used to take almost half a second and now takes about 14 milliseconds, so busy screens repaint smoothly.
Version 1.8.5
  • On Linux the app now runs as a native Wayland client in Wayland sessions, instead of through the XWayland compatibility layer: text stays sharp at fractional scaling, and windows behave the way the desktop itself does. X11 sessions are unchanged.
  • Linux windows have a title bar drawn by the app itself, in the app's own theme — the name on the left, minimize, maximize and close on the right; drag it to move the window, double-click to maximize. The frame the system drew followed only the system colour scheme, so a dark app on a light desktop sat under a white bar.
  • The splash on every platform, and the window frame on macOS, now open in the app's own theme from the very first frame. Before, a dark app on a light desktop opened light and turned dark a second later, with a flicker — and closing the app at the login screen made the next launch forget the theme again.
  • On macOS the application menu is now the standard minimal one — the app menu, Edit and Window. The default menu that used to stay behind carried View → Reload, which reloaded the interface on Cmd+R.
  • Where a window opens on a Wayland desktop is decided by the desktop itself, as for every native app: GNOME 47 and newer centre new windows, while Ubuntu 22.04's GNOME 42 places them top-left. Under XWayland the app used to centre the splash on its own; a native Wayland client cannot position its windows.
Version 1.8.4
  • Quit now quits on the first try. On macOS, Quit from the Dock menu, the application menu or Cmd+Q used to close the windows yet leave the app running — the Dock kept its dot and only a second Quit ended it. On Linux the same flaw could survive a panel’s close. One press now ends the whole application, every way it can be asked to leave.
  • Nothing is left running after the app closes. The background service and the crash reporter now end the moment the app does — even if it crashed or was force-killed — where before that pair of processes could quietly stay behind until you signed out.
  • Windows are back where they belong on Linux. An engine upgrade had quietly moved the app to native Wayland, where the opening splash landed wherever the desktop chose — off-centre on Ubuntu 22.04 among others. The app runs through XWayland again, and the splash opens centred on every desktop.
  • On Fedora, launching from GNOME could show no window at all while the processes ran on: GNOME 49 hands every app an environment variable that broke the graphics path, and the RPM’s menu entry skipped the launcher that guards against it. The launcher now neutralises the variable and the menu entry goes through it.
  • Quitting with sessions open is quicker and cleaner. Remote desktop sessions and the file-clipboard helper are now shut down in parallel with a firm upper bound of seven seconds, instead of two waits one after the other — and a helper that stopped answering is properly ended rather than left behind.
Version 1.8.3
  • Connecting through an RD Gateway now checks the gateway's own certificate, not only the server's. It is shown to you the first time and remembered under a name of its own, so approving a gateway is never read as approving a server — that leg carries the same user name and password as the target.
  • The built-in RDP engine is rebuilt from current sources for every architecture the packages carry, so every BURSUcm client — Windows, Linux and macOS — ships the same engine build rather than whichever one its own package happened to be made with.
  • An RDP host that is not answering is reported as exactly that, with the address and port named, instead of a message about a certificate that was never offered. How long to wait before that verdict is yours to set — 3 to 30 seconds, 5 by default.
  • Which engine an RDP connection uses is decided per connection. Ticking “remember” stores the answer on that connection alone, and the engine chosen in Settings seeds new connections only. “Ask again for every connection” now really does clear those answers: it says how many it cleared, leaves connections you may not edit alone, and takes effect on the next connection rather than the next start.
  • A connection created in the Windows client opens here on the engine it was saved with, and one created here opens there the same way. Both clients write the built-in engine under one name now and still understand the older spellings, so nothing has to be edited by hand.
  • The SSH, RDP and VNC pages in Settings are two equal columns, split the way the desktop client splits them: what decides whether the server is trusted on the left, what the session then does on the right. “Pinned FTPS certificates” moves to Security beside the FTPS policy it belongs with, and the dialog is sized to its longest tab, so a short tab no longer ends in a field of empty space and a long one no longer scrolls.
  • The helpers that carry files in and out of an RDP session are rebuilt from current sources on every platform. A slow server can no longer hold up a copy in the file manager, a read past the end of a file is reported honestly rather than as a success, and a file list that changes shape while a paste is still running is refused — so what arrives is what you copied.
Version 1.8.2
  • Signing in now also works with Apple and GitHub, next to Google and Microsoft — and every browser sign-in ends by showing the account it produced and asking whether it is yours. The callback arrives on a local port that any program on the machine can reach, so the session is handed over only after you say yes; saying no revokes the token that was already issued.
  • A whole folder can now be moved over SFTP — with F6, with the Move entry, or by cut and paste between the panes — and the app asks before it starts. The original tree is removed only after every single file has arrived: anything the walk had to skip, anything behind a shortcut, and a batch that was cancelled all leave it exactly where it was.
  • Deleting a folder on a server no longer walks through a shortcut that points outside it. Such a link used to have its target's contents deleted — files you never selected, elsewhere on the same server — while the whole operation reported success. The link itself is removed now, and copying had the same root cause.
  • The two file panes no longer share one refresh counter. The local pane discarded its own listing every time both panes refreshed together, so a folder you had just moved away stayed on screen with nothing behind it on disk, and synchronised browsing moved only the remote side.
  • The transfer queue keeps its books straight: a batch sent to the background no longer copies a folder and then removes nothing, a job that finishes twice no longer counts twice — a three-file folder could be called done with one file never started — and “Cancel all” no longer removes an empty source folder anyway.
  • What stayed behind is explained truthfully: the report used to blame a file in use, and pointed at the server you are attached to now rather than the one the transfer came from. The replace-and-merge warning — the one sentence between you and an overwritten tree — was English under Russian, Ukrainian and Georgian alike, and is now translated.
  • Nine findings from a security scan of the whole client: deleting a folder can no longer be used to move connections past the permissions you hold on it, the web tab's certificate answer belongs to the certificate you were actually shown instead of to the host, the Linux clipboard helper answers a read with its own session rather than whichever mount published last, and a file being edited is locked down before its contents are written.
  • Account passwords stored in the old single-round form are no longer accepted, and the stronger format the Windows client rewrites them into is now read here too. Both clients share one database, and only one of them understanding the upgrade was about to lock people out of the other.
Version 1.8.1
  • A folder can now be moved over SFTP as a whole — with F6, with cut and paste, or by dragging with Shift held. The app asks before it starts, and the original folder is removed only after every single file has arrived: anything put into it during the transfer, and anything behind a link, keeps it in place.
  • Deleting or copying a folder on the server no longer follows a symbolic link that points outside it. Such a link used to have its target's contents deleted or copied — files you never selected — and the whole thing was reported as a success; the link itself is handled now.
  • Moving a folder through the transfer queue really moves it. Sent to the background, the move copied everything and then removed nothing at all, silently, so the original stayed where it was.
  • Both panes of the file manager refresh after a transfer. The local one discarded its own listing every single time, so a folder that had just been moved away stayed on screen as though it were still on the disk — and synchronized browsing only ever moved one side of the window.
  • Pasting, and “Move to…”, now ask before replacing a file that is already there. Both of them replaced it without a word, with no dialog, no entry in the log and no way back.
  • A link that opens a new window works again in web tabs — since the feature shipped it had done nothing at all, opening neither a tab nor the system browser.
  • File copy and paste in RDP sessions, and the file manager, carry the fixes of four audit rounds: closing a tab no longer freezes the window, a large file is copied whole instead of arriving empty, and a file edited on the server keeps its permissions and its symlink.
  • The file editor's dialogs, the delete confirmations, the session-restore prompt and the FTPS certificate reset are translated into Russian, Ukrainian and Georgian.
Version 1.8.0
  • Files can now be copied through the RDP clipboard. Copy files inside a remote session and paste them on your computer, or the other way round — on Windows, Linux and macOS. They are transferred when you paste, not when you copy, so copying a large folder costs nothing until you use it.
  • The SFTP and FTP file manager matches the desktop app: a full transfer queue that can be paused and resumed, reordered, run immediately or cancelled, with live status, transferred size and remaining time.
  • Choose the RDP engine on your first connection — the built-in BURSUrdp or IronRDP — and let the app remember the choice. The prompt can be brought back at any time from Settings → RDP.
  • Clipboard support on Linux is now native to the desktop you use: Wayland (KDE, Sway, Hyprland, GNOME) and X11 are handled directly, and the packages no longer depend on GTK.
  • Remote sessions end cleanly on every platform, and closing the app leaves nothing running in the background.
  • Security: PostgreSQL connections verify the server certificate by default, and the handling of secrets stored in a cloud database has been hardened further.
Version 1.7.5
  • Backups taken on Linux and macOS were incomplete. A connection was written with only half of its fields, so the stored SSH key, its passphrase, the two-factor seed, the jump-host link, the timeouts and the RDP and terminal options were missing without a word, and a restored connection could not sign in. The record is complete now, restoring one no longer drops the two-factor seeds, and a database snapshot carries the identifier every encrypted secret is sealed to — without it a restored snapshot left every stored password permanently unreadable.
  • Saving a connection in a shared cloud database no longer destroys a password the account is not allowed to see. A member with permission to edit but not to reveal wiped a connection's password — and a credential's two-factor seed — simply by renaming it.
  • A user saved with no folder permissions is stored as "no access" instead of full access. Removing somebody's last permission, in order to take access away, handed them the entire catalog instead: a shell and file access on every server whose password is stored on the connection itself.
  • Moving or renaming a connection into a folder you are allowed to reveal secrets in no longer discloses a password that was refused a moment earlier, and deleting a folder now happens in a single step on the server instead of a series of calls that could stop halfway and leave the folder half-emptied.
  • Telnet now tells the server its terminal type and its window size, so full-screen programs — vi, top, appliance menus — draw at the right size and follow the window when it is resized.
  • Remote sessions stay on the certificate you approved: RDP verifies the pinned certificate on every reconnect, a VNC server can no longer talk the session down to an unencrypted one, and a connection through a jump host is refused instead of being made directly when the jump host cannot be resolved.
  • FTPS connections now remember the server's certificate on first use and report a change instead of accepting it. A folder's shared credential is also found when the folder name differs only in letter case — before, the connection dialled with no user name and no password at all.
  • RDP sessions open at the real size of the window. The first connection to a server always came up at 1280x800 stretched to fit, and only resizing the window or reconnecting corrected it.
  • Logging off inside a Windows RDP session no longer takes the whole application down with it. Ending a session on purpose — RDP, SSH, Telnet, a serial line or VNC — now simply closes the tab, and the red "connection lost" card is kept for a genuine break. The cursor is also placed in the terminal on every session, including the first connection to a host whose key had to be confirmed.
  • A change made on another device is no longer overwritten in silence: every online save and delete now carries the version it was based on, and a clash is reported as "changed on another device".
  • Changing the master password now re-encrypts the writes still waiting in the offline queue as well. They used to stay sealed under the key that no longer exists, which made them unreadable on every device.
  • Offline synchronisation: an edit made offline no longer comes back as a conflict against a change nobody made, and resolving a conflict with Keep my version no longer restores the values from before it.
  • Work done offline survives. A connection created offline no longer disappears when the server later rejects a follow-up change, a create whose reply was lost no longer blocks the queue for ever or adds a second copy of a snippet, and the passwords waiting in that queue are encrypted with the master password instead of being kept readable.
  • A copied password is never handed to a remote server's clipboard unless that host was trusted with "Trust & remember" — and the trust dialog now says so as part of the decision.
  • Imported connections: IPv6 addresses, ports and files saved by PuTTY or mRemoteNG on a non-English Windows are read correctly, and the port field rejects an impossible value while you type it instead of failing later at connect time.
  • Full-window and full-screen mode apply only while a session is on screen — leaving one with either still set used to leave the app with no tree, no menu and no way to undo it. The app also carries the same set of certificate pins as the mobile clients, so renewing the site certificate onto a different issuer cannot cut installed copies off from cloud sign-in and updates, and every native library in the packages is verified against a checksum while the package is built.
Version 1.7.4
  • The macOS app opens again. Its background service was signed without the permission macOS requires to run it, so the system stopped the service the moment the app started and the window reported that it was unavailable.
  • The macOS builds are signed with a Developer ID and notarised by Apple, so macOS opens them without warning about an unidentified developer and without the right-click workaround.
  • Right-clicking in a terminal now copies the selected text when there is a selection and pastes when there is none. This is the new default; the previous behaviour, where the right button always pastes, is still available in a connection's SSH options.
Version 1.7.3
  • The master password for a cloud database can now be set right in the app: every stored password is encrypted on your device before it is uploaded, so the master password itself never leaves your computer.
  • The master-password dialog gains a Generate button that creates a strong random password and shows it so you can write it down.
  • Setting a master password — in the app or on the website — now also encrypts the passwords that were saved before it existed; previously they quietly stayed unencrypted.
  • The database page on the website now shows a clear red warning while there is no master password, with a button to set one right there and a password generator.
Version 1.7.2
  • The master password is verified properly: a stored value that only looks like an encrypted secret no longer opens the vault, and the number of key-derivation rounds taken from the database is bounded at both ends.
  • The local key file is never replaced when it exists but cannot be read — it is kept aside and the loss is reported. Losing it silently meant every locally stored password became undecryptable.
  • Ctrl+L now clears a revealed password from the screen as well as locking the vault.
  • "Copy As" copies the connection's own password instead of the one resolved from a shared credential, so a shared secret is no longer duplicated into a new row.
  • File transfers: the guard follows symlinks, refuses network paths, and protects ~/.ssh, the auto-start folders, the shell startup files and the app's own configuration from being written into.
  • The channel token the shell hands to the backend is no longer readable from the process environment on Linux and macOS.
  • The macOS build no longer ships with developer tools enabled — the check they were tied to always reported "not packaged" inside a signed .app.
  • Changing the database mode asks for confirmation first: the drop-down alone used to clear the device configuration and sign the user out.
  • The messages confirming an import or a database snapshot are actually shown now, and remote file names are no longer run through the interface translator.
  • 38 previously untranslated strings — mostly backend error messages — are available in Russian, Ukrainian and Georgian.
  • Packaging: the .rpm now records real file permissions, the downloads on the site are signed with the same GPG key as the repositories, and all four package builds verify the Electron and koffi versions the same way.
Version 1.7.1
  • The terminal now colours what matters in the output: errors, warnings and success words, IP and MAC addresses and URLs. It paints the text already on screen, so full-screen programs like top or nano keep working and colours the server itself sent are left untouched. Switch it off in Settings → Appearance.
  • A tab can now be reset from its right-click menu: the session is dropped and the same connection is dialled again in place, for every protocol. A pinned tab stays pinned.
  • macOS on Apple Silicon: the app starts normally again. Everything inside the app bundle is now signed for arm64, so the background service is no longer stopped by the system on launch — the "backend unavailable" message on M-series Macs is gone.
  • Linux packages: the built-in RDP engine is back. A mismatched native module quietly disabled it, so RDP connections fell back to an external client.
  • Signing in with Google or Microsoft now exchanges a one-time code instead of carrying the session token in the address bar, and the browser tab finishes on a clean page.
  • New sign-in window: the BURSUcloud flow is now two clear steps — sign in, then pick a database from a proper list — and the window no longer needs a scroll bar.
  • The first-run setup window now asks for the interface language and starts in the language of your system.
  • Certificate verification is now configured separately for RDP, VNC and other TLS transfers, each on its own settings tab, instead of following the SSH host-key setting.
  • File transfers over SFTP now go through the jump host configured for the connection, like the terminal does. FTPS in implicit mode and the passive-mode setting are applied as chosen.
  • Clearing a password, an SSH key, a passphrase or a two-factor code now really removes it — in the app, in the cloud catalog and on the web portal.
  • Quick Connect asks for credentials when a connection needs them, and opens RDP in the built-in engine instead of an external client.
  • The file manager reports a failed download instead of leaving an empty file behind, and its delete confirmation is no longer titled "Replace file?".
  • User management: the Delete button works again — its confirmation dialog was never shown.
  • Clearer feedback where the app used to stay silent: a refused password reveal, a failed vault unlock and a rejected offline change now say what happened instead of doing nothing.
  • The About window was rebuilt around what the app actually does today, including VNC, offline mode and two-factor codes.
  • A round of security and reliability fixes across the app, the cloud portal and the mobile client.
Version 1.7.0
  • SSH private keys can now be stored in the connection itself, encrypted with your master password. The key travels with your database, so a connection that needs a key works on every computer you sign in from — no more copying key files around or fixing paths that only existed on one machine.
  • The private key box sits in the connection dialog with a Browse button that reads a key file straight in, and a Delete key button that removes a stored key for good.
  • Authentication is now chosen in the connection dialog itself, and only the fields that choice needs are shown: username and password for password sign-in, the key and its passphrase for key sign-in.
  • A connection that signs in with a key and has no password is no longer shown as if it had no credentials — the connection list and the details panel now mark it with a key.
  • Connections and credentials record who created them, shown in the details panel. Ownership can be handed to any user allowed to edit that folder, so a leaver's entries need not stay in their name.
  • Stronger protection for saved secrets: every stored password, key and two-factor code is now cryptographically tied to the entry it belongs to, so it can only ever be opened in its own place.
  • The connection list now refreshes by itself when another device changes something — and only when something actually changed, so your selection and open folders stay where you left them.
  • Every confirmation and message now uses the app's own dialogs instead of the browser boxes Electron shows, so they follow the app theme and no longer freeze the window while open.
Version 1.5.3
  • Right-click menu in the app's dialogs: Cut, Copy, Paste and Select all now work in the connection and credential forms, just like on Windows.
  • Offline-mode hardening: on a shared computer, signing in with a different account now clears the previous account's offline cache and queued changes, so one user can never see another's cached catalog. The database health-check is also rate-limited.
Version 1.5.2
  • Offline mode: when the network — or the database itself — is unreachable, BURSUcm keeps working from an encrypted local copy of your catalog, including a full start with no connection at all.
  • Changes made offline are queued and uploaded automatically as soon as the database is reachable again — items created offline get their real identity on sync, with linked credentials and jump hosts preserved.
  • A status bar shows what is happening: red while offline (with an offline-changes counter and a Retry button), amber while synchronizing, green Synchronized for a moment when done.
  • If the same item was changed both on this device and on the server, a conflict window shows the two versions side by side and lets you keep either one — passwords are never displayed there.
  • Availability is detected by pinging your database itself — every 30 seconds in the background and instantly when you act — so a dead server is noticed even while the internet is fine, and recovery is picked up within half a minute.
  • Signing out while offline now warns how many changes are still waiting to be uploaded.
  • Works for both BURSUcloud and direct PostgreSQL databases — PostgreSQL keeps an up-to-date local mirror on this computer.
Version 1.5.1
  • Changing, enabling or turning off the master password now re-encrypts every stored secret in a single atomic step, and re-keying a cloud vault no longer loses saved two-factor (TOTP) codes.
  • Backups are safer: restoring a snapshot is atomic and no longer drops connection options, two-factor codes or snippets, and a portable export of a database that is currently in use is now written correctly.
  • VNC and native RDP sessions are sturdier: stricter limits while decoding a remote screen, held keys are released when the window loses focus, and sessions stop cleanly when their window closes.
  • If the backend ever stops, the app now restarts it and restores your session instead of leaving dead tabs behind.
  • The terminal has a slim scrollbar, SSH agent authentication works again on Linux and macOS, and a connection that fails now reports the error instead of leaving a tab that looks connected.
Version 1.5.0
  • VNC support: connect to VNC servers with TLS/VeNCrypt encryption, Tight, ZRLE and Hextile encodings, view-only mode, clipboard sharing and scaling — and import your existing .vnc files in one click.
  • TOTP two-factor codes in credentials: store a Base32 or otpauth:// secret and get a live 6-digit code with one-click "Copy TOTP code", protected by the master-password vault.
  • Built-in password generator in the credential dialog: choose the length and character classes and copy a strong password in one click.
  • Customisable terminal appearance: pick a colour scheme (Classic, Dracula, Solarized and more), font family and size for your SSH, Telnet and Serial sessions.
  • Log session output to a file: turn on per-connection logging to keep a transcript of a terminal session; the log folder is configurable in Settings.
  • More native RDP options in the UI: RemoteFX, UDP transport, smart-card redirection and the GFX pipeline are now exposed in the RDP options dialog and as global defaults.
  • Wake-on-LAN: send a magic packet to a connection's MAC address straight from its right-click menu to power on a sleeping machine.
  • The BURSUcloud account card now shows the logo of the provider your account signs in with — Google, Microsoft or BURSUcloud.
  • The app now reconnects to its backend automatically if the link drops, showing a clear status banner while it does, and every request now has a timeout so the interface can't hang forever.
  • Consistent menus and cursors across the app: menu bars and pop-up menus use the standard arrow cursor, matching the desktop app.
  • Reliability and security fixes: closed several backend resource leaks, tightened access checks so restricted users can't see folders they aren't allowed to, and made restored sessions and file transfers more robust.
Version 1.3.1
  • The built-in BURSUrdp RDP engine is now on macOS too, on both Intel and Apple Silicon Macs: remote desktops render directly inside the app with H.264 graphics, remote audio, clipboard and multi-monitor support — no extra software to install.
  • Stronger at-rest security on Linux and macOS: the machine-local encryption key is now bound to this computer instead of being stored in the clear, so copying your configuration to another machine no longer exposes your saved secrets.
  • The connection to bursucm.com is now certificate-pinned, adding protection against network interception when you sign in or check for updates.
  • Telnet connections now warn that the session is unencrypted, matching the Windows app.
  • The "Open logs folder" button in Settings now creates the folder if it doesn't exist yet, plus additional hardening across local file access, SSH port forwards and the RDP certificate prompt.
Version 1.3.0
  • Our own built-in RDP engine (BURSUrdp) now on Linux: the remote desktop is drawn directly inside the app from one self-contained library that works the same on every distribution — no extra packages to install.
  • Multi-monitor RDP: each extra monitor opens as its own movable window you can drag onto a second screen and switch to full screen (F11); its resolution follows the window size and its position is remembered.
  • Smoother remote desktop: H.264 video decoding and remote audio, all built into the app.
Version 1.2.1
  • Serial (COM port) connections work again, and Telnet sessions now accept keyboard input reliably.
  • Open with Remote Desktop on Linux is fixed: the system RDP client starts reliably, the password is passed securely, and if it is missing the app shows the exact install command for your distribution.
  • The app now starts with a proper splash screen and launches noticeably faster.
  • The main window remembers its size and maximized state, and launching the app again focuses the running window instead of opening a second copy.
  • All local files now live in one BURSUcm config folder with tidy subfolders for data, security and logs — existing files, including the local encryption key, are migrated automatically.
  • Security hardening: internal IPC requests are accepted only from the app's own interface, and trusted web tab certificates are pinned by fingerprint.
Version 1.2.0
  • You can now arrange connections and credentials inside folders in any order you like — hover a row and use the up/down arrows. The order is saved in your database and synced everywhere: the Windows app, the portal and the Android app show the exact same order.
Version 1.1.1
  • Fixed the application icon on Linux: on GNOME desktops the dock and taskbar showed a generic placeholder instead of the BURSUcm icon. It now displays correctly (KDE was already fine).
Version 1.1.0
  • A deep security-hardening pass across the whole app: the internal UI-to-backend channel is now authenticated, every permission is enforced by the backend itself, the interface runs under a strict Content-Security-Policy, external links only open over safe schemes, and the Electron runtime was upgraded to version 43.
  • Stronger secret protection: sign-in attempts are throttled even across restarts, older password hashes upgrade to PBKDF2 automatically, portable backups use a stronger key derivation, and on Windows the local key file is bound to your OS user.
  • Safer terminal paste: pasting multiple lines asks for confirmation with a preview on every path — Ctrl+V, Shift+Insert, right click or the context menu — line endings are normalized, and bracketed paste is supported, so nothing runs before you press Enter.
  • RDP: copy and paste through the system clipboard, reliable reconnect after a dropped session, and proper detection of GNOME Remote Desktop hosts.
  • If the vault is locked when you connect, the app now asks for the password on the spot instead of failing the connection.
  • Split view layout fixes, and folders and FTP connections got their own colored icons.
  • A much leaner install: the backend ships as a single file and the interface as one archive — packages are smaller, install far fewer files, and the macOS disk image shrank by about a third.
Version 1.0.0
  • First release of BURSU Connection Manager for Linux (Debian/Ubuntu, Arch/CachyOS, Fedora/RHEL) and macOS — the same connection manager, now native on your desktop.
  • All protocols in tabs: SSH (with jump hosts / bastions, local and remote port forwarding and tunnels), RDP, Telnet, Serial, Web (a built-in browser for device admin panels), and FTP / SFTP with a dual-pane file manager and drag-and-drop.
  • BURSUcloud sync: keep your connections and credentials in a zero-knowledge cloud — your master password never leaves your device — and sign in with email, Google or Microsoft.
  • Encrypted credential vault protected by a master password, unlockable at startup or later in Settings.
  • OLED-optimised dark theme and four interface languages: English, Russian, Ukrainian and Georgian.
  • Split view, broadcast input to every open session, reusable command snippets, and last-session restore.
Version 2.7.0
  • Direct PostgreSQL setup now uses clear host, port, database, user, password and TLS fields, can test the saved connection, and can export or import a password-protected configuration file for a colleague.
  • Shared PostgreSQL vaults now use one portable data key per database. Changing the master password no longer re-encrypts every secret, and concurrent changes cannot be silently overwritten.
  • Legacy vaults migrate safely without losing access, including databases with older KDF metadata; remembered master passwords remain attached to the correct database and survive migration or temporary connection failures.
  • Folder permissions are safer and clearer: moving or deleting folders preserves grants, partial rights are displayed correctly, root-level items have their own grant, and members can edit their own account and password.
  • Deleting a folder through BURSUcloud is atomic, so a failed request cannot leave the catalogue half-modified; an outdated portal is refused before any destructive step.
  • Smaller fixes across database and account screens: setup saves a PostgreSQL catalogue only after it has answered, “Remember master password” works during initial setup, portable backups contain a complete vault, TLS labels say what is actually verified, and the account card shows the provider that really signed you in.
Version 2.5.1
  • Streamed replies reach the screen once per frame instead of once per token, and the assistant panel follows the stream only while you are at the end, so an earlier answer can be re-read while the model is still writing.
  • Closing a WinRM tab, or losing its connection, now stops its assistant as an SSH tab does; it used to keep running against a terminal that was gone.
  • Roll back restores the change of the card you clicked. It always restored the most recent change, whichever card's button was pressed.
  • Reset on an SSH tab gives the assistant a fresh session. It used to keep the old one and answer “Start the AI assistant for this SSH session first”.
  • Name lookups ask before running: nslookup, getent hosts, ping of a host name and openssl s_client wait for your click like curl and wget do, because every label of a queried name reaches whoever runs that zone. An address such as ping -c 3 8.8.8.8 still runs on its own. Secret Shield also hides values named DB_PASS, ROOT_PW or MYSQL_PWD and keys from xAI, Groq, GitLab and DigitalOcean.
  • A command is no longer reported as finished before it was typed. A completion mark from the previous prompt that arrived while the assistant waited for the screen to settle counted as the new command's result, and the “> ” prompt of an open quote was taken for an idle shell, which typed the next command into the string.
  • Provider failures are shown, not swallowed: a timed-out request looked like a pressed Stop, an error in the middle of a streamed reply ended it as if complete, and a rejected key was retried three times before you saw it. A reply that quotes a YAML block before its shell command no longer proposes the prose between them as the command.
  • Smaller things: 37 messages the panel and the AI settings showed in English are translated; archiving a chat holds across tabs; long reasoning text wraps instead of widening the panel.
Version 2.5.0
  • Libraries updated to their latest long-term-support versions. Nothing changes on screen, and the packages carry everything they need inside them, as before. From this version the app needs macOS 14 or newer; on Linux every distribution it already supported stays supported.
  • A tunnel that cannot listen says why. On Linux and macOS a local (-L) or dynamic (-D, SOCKS5) tunnel on a port below 1024 fails because those ports belong to root — the terminal showed only “Permission denied”, and the same connection worked on Windows, which has no such limit. The failure line is now followed by a plain explanation, and the connection editor warns while such a port is being typed. 1080 is the customary SOCKS5 port.
  • The User Management window opens complete. On a BURSUcloud database it used to assemble itself in stages — an empty list, then the accounts, then the groups, then the buttons — because its content was five round-trips to the portal served one after another. It is now fetched as one answer, in parallel, before the window opens; what appears is the finished window, and an edit refreshes it in place.
  • A right inherited from a group is drawn green in the person's card, locked and labelled “Inherited from group” — as designed, and as the Windows edition draws it. It came out in the same blue as the account's own rights, so the two could not be told apart.
  • The note “tmux is not installed on this server — plain shell” no longer vanishes a second after connecting. The files panel's bootstrap, which follows the shell's current directory, ended by erasing the screen from a row above the prompt and ran on a timer at every connect, landing exactly on the note. It now runs only when the files panel is open, as in the Windows edition.
  • Smaller things. The assistant reads a streamed reply to its end without holding the service on the network; the tunnel status lines at the top of a terminal can no longer carry control sequences from a stored host name; and a renamed BURSUcloud database shows its new handle in the User Management window at once.
Version 2.3.2
  • The app remembers who signed in again. In 2.3.1 every start asked for the password afresh: the note saying who was here last, and the folder holding each account's own settings, host keys, logs and offline copy of the catalog, were both swept aside at launch before anything could read them — and re-created, so nothing ever looked missing. They are left alone now, and whatever an earlier start put aside is moved back the first time this version runs. Nothing was lost: the sign-in saved before the update is found again.
  • A cloud account is no longer shown as holding every folder. An account created in the portal carries an explicit list of what it was granted, and an empty list means it was granted nothing of its own — which is exactly an account whose rights come from a group. The user's card read that as the old rule for accounts from before per-folder rights, “never restricted, so it sees everything”, and drew a ticked “All connection folders”: Read on every folder, for someone who had been given none. Saving the card would have written that as a real grant. Accounts on a local database from before per-folder rights keep the old meaning.
Version 2.3.1
  • User groups. A group is a named set of per-folder rights, and everyone in it inherits them — so a team's access is granted once instead of being re-entered for every account. Rights that come from a group show in the person's card as a green tick, locked and labelled “Inherited from group”, beside the ones granted to them personally. Groups work the same way in the local database, in your own PostgreSQL and in a BURSUcloud database; a group never makes anyone an administrator.
  • One folder per account on this computer. Everything the app keeps outside the database that belongs to a person — trusted host keys and certificates, logs and session transcripts, the offline copy of the catalog, the assistant's chats, the browser tabs' profile, the remembered vault key and “remember me” — now lives in that account's own folder, and the app switches to it the moment someone signs in. Nothing is deleted when the next person signs in: come back and your own state is where you left it. An install updating from an earlier version hands its files to the first account that signs in, and an administrator can remove a person's folder from the users window.
  • The Settings modal is everyone's, and it matches the Windows edition tab for tab — the same sections, labels, option texts and hints. Because those preferences are now a person's own on this computer, every user edits and saves the SSH, RDP, VNC and WinRM policies, the session defaults and the logging; before, a non-administrator's changes were dropped silently while the dialog said “Saved.” Remembering and forgetting the master password is now each signed-in user's own decision, and the whole-database Data tab is the administrator's alone.
  • A folder is picked from the tree, not typed as a path. Everywhere a record's folder is chosen — the connection editor, the credential and SSH-key editors, the parent folder in Edit Folder, and “Move to folder” — the field is now a drop-down of the folders you already have, in the tree's own order and folded the way the tree is folded. Folders you may not save into are shown greyed rather than hidden, so the ones under them keep their place, and the root row reads “(root — top level)”.
  • A right taken away stops working at once. Until now a demotion, a deletion or a withdrawn group membership held until the app was restarted, administrators included. The signed-in person's rights are now re-read on every catalog reload and again by every request that hands out a secret: revealing a password, a one-time code, the parameters of a remote-desktop session, a CSV or database export, the portable copy and every call to the assistant. Stopping a running assistant still works without the right — taking the right away must not leave anyone unable to interrupt it — and a group dialog left open cannot restore rights withdrawn meanwhile.
  • A session through an RD Gateway now pins the gateway's certificate. The app checked that certificate before connecting and then told the engine nothing about it, so the engine accepted whatever the gateway presented during the real handshake; and when the certificate could not be obtained at all, the check was skipped and the session went ahead — a machine answering on the gateway's address would have received the username and the password. The approved fingerprint now travels to the engine, which refuses a gateway that presents anything else, and under the “trust on first use” and “strict” policies a gateway whose certificate cannot be read is refused with an explanation.
  • Smaller things. A web tab's “ignore this certificate” answer belongs to the person who gave it: the trust is keyed to their own profile and cleared when the profile changes, so one person's answer no longer decides for the next, and a web tab that fails to start shows the error instead of a blank page. The service's own error messages arrive in all four languages — they used to come in English whatever the app was set to. Electron 43.6.0.
Version 2.3.0
  • Windows servers, over WinRM. A new connection type beside SSH: PowerShell runs over PowerShell Remoting and cmd.exe over WinRS, on plain HTTP or over HTTPS, where the server's certificate is trusted once and pinned the way an SSH host key is. Output streams while a command is still running, Ctrl+C stops the pipeline, errors arrive as errors with the line they happened on, and Read-Host, -Confirm and a missing mandatory parameter ask and wait — a password is answered under the session key, never as text on the screen.
  • The WinRM terminal behaves like a terminal. “clear” and “cls” clear this window at once instead of answering with two paragraphs of red; Write-Host keeps its colours and “-NoNewline”, and what a script writes through $host.UI is drawn rather than dropped; a cmd.exe session can be set to a codepage such as 866, so Cyrillic typed into it comes back readable; a paste of several lines runs all of them; and a “Password:” prompt from a cmd program hides what you type. The trust questions — the certificate on HTTPS, the once-per-server confirmation on plain HTTP — now get the three minutes they may take instead of the tab giving up after one while the dialog was still open, and the plain-HTTP one no longer poses as an untrusted certificate with a fingerprint to verify.
  • Keep an SSH session in tmux. A checkbox in the SSH options, with a session name beside it, makes the connection attach to that tmux session when the shell opens — created the first time, rejoined after that, so a dropped connection returns you to the same screen with the same programs still running. Detaching (Ctrl+B, D) returns to the plain shell rather than closing the tab; the tab reads “(tmux)” while you are inside, the wheel scrolls tmux's own history, the Files panel still follows “cd”, and the assistant still sees when a command ends. A server without tmux says so in the terminal, and the session goes on without it.
  • A SOCKS5 proxy through the SSH connection (ssh -D). A third kind of tunnel beside local and remote forwards: the tunnels editor now offers “dynamic”, which opens a SOCKS5 proxy on 127.0.0.1 at the port you choose and carries every connection made to it through the session. A browser, curl or a database client pointed at the proxy reaches hosts only the SSH server can route to, and names are resolved on the server side as well (socks5h). The proxy listens on 127.0.0.1 only — it is never offered to the network the computer is on.
  • The assistant's terminal is your terminal. While one of its commands ran, whatever you typed was held back until the command finished — a password typed at a sudo prompt never reached sudo, and once you pressed Ctrl+C it was typed into the shell in clear. Keystrokes now go to the terminal at once, always. A prompt meant for you — a password, a yes/no — is waited for, with “Waiting for your input in the terminal” on the card and no clock running, and the assistant then sees the whole result; a long upgrade that keeps printing is no longer cut off at a fixed minute, because the timeout counts silence. And your environment stays: a pager no longer stops at “Press RETURN”, and tools that keep their configuration in your home directory find it.
  • The assistant asks before a PowerShell line can do harm. It now classifies by PowerShell's own rules: a method call anywhere in the line — “$_.Delete()”, “(Get-Service x).Stop()” — a static member and every script block are judged, so “Get-ChildItem | ForEach-Object { $_.Delete() }” asks for the click instead of passing as a reading command. Reading a file that may hold secrets (the SAM and SECURITY hives, web.config, appsettings, keys, .ssh), any UNC path and “-ComputerName” ask too, because what is read goes to the AI provider with the output.
  • Findings of the pre-release audit. A single pasted line with a line break at its end ran on paste — the break is dropped now and you press Enter yourself, so a page with a hidden command cannot run it for you. A crash record waiting for the next start carried the raw error text, connection strings included, in a file that backup tools read; secrets are cut before it is written. A server that printed “tmux=on” in its banner could switch the tab into tmux mode; the marks are read only after this side has typed its own line. The connection's name, notes and tags reach the assistant as reference data rather than beside its rules, so nobody with edit rights on a shared folder can write rules of their own into them, and a “sed” script runs without the click only in its plainly non-executing forms. And the hints under plain HTTP and “proceed past certificate errors” now say what each actually gives up.
  • On screen and under the hood. Electron 43.5.1, taken for its fix to intermittent startup crashes on Linux during font initialisation. A connection whose username was “Administrator” showed it as “Администратор” — the localizer translated values, not only labels — and the broadcast banner and the last-session card were half English in every language because a number was pasted into the sentence; all three read right now.
Version 2.2.1
  • The AI assistant can now run interactive programs. “htop”, “top” and anything else that takes over the screen were refused outright — the assistant could only start a command and wait for it to finish, and htop never finishes, so the wait could end only in a timeout and a Ctrl+C nobody asked for. It now starts such a program, lets it draw its first screen and hands the terminal back to you.
  • Answers appear as they are written. The assistant collected the whole reply and showed it in one piece at the end, with the “thinking” line already switched off — so the panel sat empty for as long as the answer took, which reads as a hang.
  • The assistant's chat is far faster, and macOS felt it worst. A reasoning model writes its answer token by token, and every single token redrew the entire conversation — about fifteen hundred redraws for one answer, each of them re-reading every message in the chat and forcing the whole column to lay out again. Only what actually changed is redrawn now.
  • Code inside an answer reads as text again. Every backticked word became a full-width grey box with its own Copy button, so a file path named in the middle of a sentence cut that sentence into three stacked blocks. A command still gets its own block and its Copy button; a name inside a sentence stays inside the sentence — and the whole answer can be selected, which is how a path or a value is taken out of one.
  • The assistant is no longer frozen out by “sudo su”, “mysql”, “psql” and the like. Inside those the terminal cannot report that a command has finished, so the assistant refused every request and told you to press Enter or Ctrl+C over a command line you had never typed. It recognises their prompts now, says which case it is when it does refuse, and no longer claims the terminal is busy from its own memory of an earlier answer.
  • Problem reports, after two independent audits: identical faults group together whatever the privacy switches are set to — the grouping used to change with them; server names, logins and IPv6 addresses are masked more carefully while the stack itself stays readable; and declining one fault no longer silences a different one, so two alternating faults stop asking at every start.
  • Problem reports: closing the window cancels the send instead of leaving it running, the fields freeze while a report is in flight so the preview cannot drift away from what is being sent, and a report that arrives after you close the window is no longer recorded as declined.
Version 2.2.0
  • Report a problem, without leaving the app. When something goes wrong the app offers to send a report about it, and Help → Report a problem is there at any other time. You get a report number back, and we get the error itself instead of a description of it.
  • You see exactly what will be sent, before it is sent. “Show what will be sent” is not a summary of the report — it is the report, rebuilt as you type and as you tick the boxes. Nothing leaves the computer until you press Send: there is no background upload and no crash beacon.
  • Passwords, keys and tokens are stripped on your computer, before the preview. Server addresses, account names and IP addresses are replaced with placeholders as well — in a connection manager those are as private as a password — and a checkbox puts them back when you decide they help.
  • When the report already carries the error, writing anything is optional, and the fields say so. People who did not feel like writing used to press Cancel — and then nobody had the error either.
  • A crash is offered at the next start — and the window comes back by itself. A window that stops responding is now replaced instead of being left dead on screen, and the fault behind it is recorded; the same applies when the background service stops unexpectedly. The next launch asks whether to send the report, with the error already inside, and a no is remembered for a day so a fault that repeats does not ask at every start.
  • A screenshot only when there is something to see. It is taken at the instant of the fault, before any of our own windows are drawn — an earlier attempt photographed the very dialog that was asking about the error — it is off by default, and it is shown to you before it is sent. Reports from the Help menu and offers after a crash carry none.
  • A send that fails loses nothing. The dialog stays exactly as you left it, and “Save to file…” writes the whole report — the readable text and the raw data — ready to be mailed to support@bursucm.com.
  • Settings → Other has a switch that turns the offers off. Off means the app stops asking: no dialog after an error, no question at the next start, no entry in the Help menu. It never meant “report silently” — nothing was ever sent without Send.
Version 2.1.1
  • Local database: a database created by 1.8.x could not sign in after updating (“no such column: ai_enabled”), and one created by 2.0.0 lost its credential list in 2.1.0 (“no such column: kind”). Those versions had marked the database as fully migrated, so the step that adds the newer columns was skipped. It now runs again on the first open, and the client checks the columns themselves instead of trusting the version stamp.
  • User permissions: the example folders a new database starts with — and any folder typed into a record's folder box — were missing from the permissions screen, so no right could be granted on them even after a rename. The screen now lists every folder the tree shows.
  • PostgreSQL: editing or deleting a connection, credential or snippet failed with “could not determine data type of parameter”, and importing a backup was rolled back without a message. The statements now carry the type PostgreSQL needs.
  • PostgreSQL: a new, empty database now opens with the same example folders, connections, credentials and snippets as a new local file.
Version 2.1.0
  • SSH keys are now credentials. A record in the credential store can hold a private key, its passphrase, the public half and a comment, and you link it to a connection exactly as you link a password — jump hosts included. A connection pointed at a stored key used to fail with “key not found”, because only the connection’s own key field was read at connect time.
  • The connection editor is the desktop’s two-column dialog: what the connection is and where it is filed on the left, how it logs in on the right. The credential, the authentication method and the key used to sit a scroll apart in one narrow column, with the group, the owner and the notes below the fold entirely. The password row now follows the method actually in force rather than the stored column, so a key connection no longer shows an empty box under a “Password” label.
  • Choosing a credential is now a folder tree with a glyph for each kind, and key records are offered only where a key can be used. Picking one settles the authentication method and locks the fields it owns, each labelled with the record it comes from; unlinking fills those fields back from the connection itself instead of leaving another record’s material behind. Switching the protocol drops a link the new type cannot use, and “+ Add credential” asks which kind you want.
  • Access permissions have their own window with two tabs, and an administrator — who holds every folder — is no longer shown a table with nothing to say. One folder tree that folds, with search and “Only granted”, replaces two fixed-height tables that grew with the folder count and gave three scrollbars for a single gesture. Ticking “all folders” now ticks and locks the individual rows, because a right that comes from the wildcard cannot be taken back one folder at a time.
  • Folders come before records everywhere. Both trees and the credential picker walk depth-first — the folder’s heading, its subfolders, then its own records — and the picker follows the tree’s order and its shared collapsed state instead of building an alphabetical list of its own. A folder whose name is spelled with different capitalisation in a grant and in the tree is one folder again, not two rows with the rights on the wrong one.
  • Quitting moments after an RDP session closed could end the app with a crash instead of a clean exit: the shutdown waited only for the sessions it could still see, and a teardown that had begun a millisecond earlier was invisible to it. Every teardown is now tracked until it finishes, and the quit waits for the ones already in flight.
  • The owner picker never dead-ends: portal administrators are always offered, an owner chosen while offline survives the reconnect, and a duplicated connection belongs to whoever copied it. The Owner column also stopped flipping to “Unknown” after you opened a row without an owner, and the AI chat’s copy confirmation appears again — the translation layer was re-imposing a dictionary word over live text. Commands inside a finished AI reply are now copyable chips.
  • Fixes from two audit passes over the credential store: renaming a folder now re-checks every record that moves with it, so a rename can no longer carry a key into a folder where someone else may reveal it; a remote-to-remote FTP copy no longer stages the file body in a world-readable directory under /tmp; and the icon probe uses a private temporary directory instead of a fixed name another local account could create first.
Version 2.0.0
  • Meet the AI assistant for SSH sessions. It understands the active terminal, explains output, investigates failures and can carry out complete administration tasks without making you copy commands between windows.
  • Choose the intelligence that fits the job: OpenAI, Google Gemini, Anthropic Claude, DeepSeek, OpenRouter, Together and xAI are supported alongside local Ollama, LM Studio and llama.cpp models. Provider-specific clients, model discovery, connection testing and encrypted API-key storage are built in.
  • Automation is guarded by what a command actually does, not by a brittle list of command names. Read-only work can run automatically; anything that may change the system is clearly explained and waits for approval, with exit codes, timeouts and interactive commands handled explicitly.
  • Secret Shield detects and redacts passwords, API keys, private keys, cookies, tokens, database connection strings and .env contents before text is sent to an AI provider. Chat history is encrypted locally, and provider-side storage controls are shown only where the provider supports them.
  • AI chats are now a real workspace: create, rename, archive, restore and delete conversations; pin a chat to a connection; resize the panel and keep that size; see context usage; and compact a long conversation without losing its working summary.
  • Give the assistant the evidence it needs. Paste a screenshot from the clipboard or attach logs, configuration files, text files and documents; text is extracted for analysis, while images are sent only to a vision-capable provider.
  • When something fails, Find the cause of the error builds a focused diagnosis. Create report produces a copyable record of the problem, server and time, commands, results, changes and final checks, with detected secrets hidden.
  • Risky configuration work gains a safety net: the assistant can preserve the original state, show the diff, apply a change, validate the result and offer a one-click rollback when the check fails.
  • The interface has been rebuilt around the new workflow: a consistent chat and Settings design, live light and dark themes, clearer tabs and dialogs, reliable focus, movable modals, resizable pinned panels and layouts that remain usable in narrow windows.
  • Linux packages are freshly built for Debian/Ubuntu, Fedora/RHEL and Arch families, published through signed APT, DNF and Pacman repositories, and include a self-contained clipboard helper. macOS images are built for Intel and Apple Silicon, Developer ID signed, notarised by Apple and stapled for offline verification.
Version 1.8.6
  • Copy and paste in the terminal work again. Selecting text to copy it, right-click copy and right-click paste had done nothing since 1.8.2 — silently, on every platform; only Ctrl+V kept working. The “Copy Username” and “Copy Host” actions in the sidebar were broken by the same fault and are back as well.
  • Everyday actions no longer re-download the cloud catalog. Starring a favourite, connecting, saving or deleting used to trigger a full catalog fetch every time; now the app answers from its local snapshot, still picking up changes from your other devices within seconds — so these actions feel instant and the server sees a fraction of the traffic.
  • VNC no longer crawls on large screen updates: decoding a full-HD frame used to take almost half a second and now takes about 14 milliseconds, so busy screens repaint smoothly.
Version 1.8.5
  • On Linux the app now runs as a native Wayland client in Wayland sessions, instead of through the XWayland compatibility layer: text stays sharp at fractional scaling, and windows behave the way the desktop itself does. X11 sessions are unchanged.
  • Linux windows have a title bar drawn by the app itself, in the app's own theme — the name on the left, minimize, maximize and close on the right; drag it to move the window, double-click to maximize. The frame the system drew followed only the system colour scheme, so a dark app on a light desktop sat under a white bar.
  • The splash on every platform, and the window frame on macOS, now open in the app's own theme from the very first frame. Before, a dark app on a light desktop opened light and turned dark a second later, with a flicker — and closing the app at the login screen made the next launch forget the theme again.
  • On macOS the application menu is now the standard minimal one — the app menu, Edit and Window. The default menu that used to stay behind carried View → Reload, which reloaded the interface on Cmd+R.
  • Where a window opens on a Wayland desktop is decided by the desktop itself, as for every native app: GNOME 47 and newer centre new windows, while Ubuntu 22.04's GNOME 42 places them top-left. Under XWayland the app used to centre the splash on its own; a native Wayland client cannot position its windows.
Version 1.8.4
  • Quit now quits on the first try. On macOS, Quit from the Dock menu, the application menu or Cmd+Q used to close the windows yet leave the app running — the Dock kept its dot and only a second Quit ended it. On Linux the same flaw could survive a panel’s close. One press now ends the whole application, every way it can be asked to leave.
  • Nothing is left running after the app closes. The background service and the crash reporter now end the moment the app does — even if it crashed or was force-killed — where before that pair of processes could quietly stay behind until you signed out.
  • Windows are back where they belong on Linux. An engine upgrade had quietly moved the app to native Wayland, where the opening splash landed wherever the desktop chose — off-centre on Ubuntu 22.04 among others. The app runs through XWayland again, and the splash opens centred on every desktop.
  • On Fedora, launching from GNOME could show no window at all while the processes ran on: GNOME 49 hands every app an environment variable that broke the graphics path, and the RPM’s menu entry skipped the launcher that guards against it. The launcher now neutralises the variable and the menu entry goes through it.
  • Quitting with sessions open is quicker and cleaner. Remote desktop sessions and the file-clipboard helper are now shut down in parallel with a firm upper bound of seven seconds, instead of two waits one after the other — and a helper that stopped answering is properly ended rather than left behind.
Version 1.8.3
  • Connecting through an RD Gateway now checks the gateway's own certificate, not only the server's. It is shown to you the first time and remembered under a name of its own, so approving a gateway is never read as approving a server — that leg carries the same user name and password as the target.
  • The built-in RDP engine is rebuilt from current sources for every architecture the packages carry, so every BURSUcm client — Windows, Linux and macOS — ships the same engine build rather than whichever one its own package happened to be made with.
  • An RDP host that is not answering is reported as exactly that, with the address and port named, instead of a message about a certificate that was never offered. How long to wait before that verdict is yours to set — 3 to 30 seconds, 5 by default.
  • Which engine an RDP connection uses is decided per connection. Ticking “remember” stores the answer on that connection alone, and the engine chosen in Settings seeds new connections only. “Ask again for every connection” now really does clear those answers: it says how many it cleared, leaves connections you may not edit alone, and takes effect on the next connection rather than the next start.
  • A connection created in the Windows client opens here on the engine it was saved with, and one created here opens there the same way. Both clients write the built-in engine under one name now and still understand the older spellings, so nothing has to be edited by hand.
  • The SSH, RDP and VNC pages in Settings are two equal columns, split the way the desktop client splits them: what decides whether the server is trusted on the left, what the session then does on the right. “Pinned FTPS certificates” moves to Security beside the FTPS policy it belongs with, and the dialog is sized to its longest tab, so a short tab no longer ends in a field of empty space and a long one no longer scrolls.
  • The helpers that carry files in and out of an RDP session are rebuilt from current sources on every platform. A slow server can no longer hold up a copy in the file manager, a read past the end of a file is reported honestly rather than as a success, and a file list that changes shape while a paste is still running is refused — so what arrives is what you copied.
Version 1.8.2
  • Signing in now also works with Apple and GitHub, next to Google and Microsoft — and every browser sign-in ends by showing the account it produced and asking whether it is yours. The callback arrives on a local port that any program on the machine can reach, so the session is handed over only after you say yes; saying no revokes the token that was already issued.
  • A whole folder can now be moved over SFTP — with F6, with the Move entry, or by cut and paste between the panes — and the app asks before it starts. The original tree is removed only after every single file has arrived: anything the walk had to skip, anything behind a shortcut, and a batch that was cancelled all leave it exactly where it was.
  • Deleting a folder on a server no longer walks through a shortcut that points outside it. Such a link used to have its target's contents deleted — files you never selected, elsewhere on the same server — while the whole operation reported success. The link itself is removed now, and copying had the same root cause.
  • The two file panes no longer share one refresh counter. The local pane discarded its own listing every time both panes refreshed together, so a folder you had just moved away stayed on screen with nothing behind it on disk, and synchronised browsing moved only the remote side.
  • The transfer queue keeps its books straight: a batch sent to the background no longer copies a folder and then removes nothing, a job that finishes twice no longer counts twice — a three-file folder could be called done with one file never started — and “Cancel all” no longer removes an empty source folder anyway.
  • What stayed behind is explained truthfully: the report used to blame a file in use, and pointed at the server you are attached to now rather than the one the transfer came from. The replace-and-merge warning — the one sentence between you and an overwritten tree — was English under Russian, Ukrainian and Georgian alike, and is now translated.
  • Nine findings from a security scan of the whole client: deleting a folder can no longer be used to move connections past the permissions you hold on it, the web tab's certificate answer belongs to the certificate you were actually shown instead of to the host, the Linux clipboard helper answers a read with its own session rather than whichever mount published last, and a file being edited is locked down before its contents are written.
  • Account passwords stored in the old single-round form are no longer accepted, and the stronger format the Windows client rewrites them into is now read here too. Both clients share one database, and only one of them understanding the upgrade was about to lock people out of the other.
Version 1.8.1
  • A folder can now be moved over SFTP as a whole — with F6, with cut and paste, or by dragging with Shift held. The app asks before it starts, and the original folder is removed only after every single file has arrived: anything put into it during the transfer, and anything behind a link, keeps it in place.
  • Deleting or copying a folder on the server no longer follows a symbolic link that points outside it. Such a link used to have its target's contents deleted or copied — files you never selected — and the whole thing was reported as a success; the link itself is handled now.
  • Moving a folder through the transfer queue really moves it. Sent to the background, the move copied everything and then removed nothing at all, silently, so the original stayed where it was.
  • Both panes of the file manager refresh after a transfer. The local one discarded its own listing every single time, so a folder that had just been moved away stayed on screen as though it were still on the disk — and synchronized browsing only ever moved one side of the window.
  • Pasting, and “Move to…”, now ask before replacing a file that is already there. Both of them replaced it without a word, with no dialog, no entry in the log and no way back.
  • A link that opens a new window works again in web tabs — since the feature shipped it had done nothing at all, opening neither a tab nor the system browser.
  • File copy and paste in RDP sessions, and the file manager, carry the fixes of four audit rounds: closing a tab no longer freezes the window, a large file is copied whole instead of arriving empty, and a file edited on the server keeps its permissions and its symlink.
  • The file editor's dialogs, the delete confirmations, the session-restore prompt and the FTPS certificate reset are translated into Russian, Ukrainian and Georgian.
Version 1.8.0
  • Files can now be copied through the RDP clipboard. Copy files inside a remote session and paste them on your computer, or the other way round — on Windows, Linux and macOS. They are transferred when you paste, not when you copy, so copying a large folder costs nothing until you use it.
  • The SFTP and FTP file manager matches the desktop app: a full transfer queue that can be paused and resumed, reordered, run immediately or cancelled, with live status, transferred size and remaining time.
  • Choose the RDP engine on your first connection — the built-in BURSUrdp or IronRDP — and let the app remember the choice. The prompt can be brought back at any time from Settings → RDP.
  • Clipboard support on Linux is now native to the desktop you use: Wayland (KDE, Sway, Hyprland, GNOME) and X11 are handled directly, and the packages no longer depend on GTK.
  • Remote sessions end cleanly on every platform, and closing the app leaves nothing running in the background.
  • Security: PostgreSQL connections verify the server certificate by default, and the handling of secrets stored in a cloud database has been hardened further.
Version 1.7.5
  • Backups taken on Linux and macOS were incomplete. A connection was written with only half of its fields, so the stored SSH key, its passphrase, the two-factor seed, the jump-host link, the timeouts and the RDP and terminal options were missing without a word, and a restored connection could not sign in. The record is complete now, restoring one no longer drops the two-factor seeds, and a database snapshot carries the identifier every encrypted secret is sealed to — without it a restored snapshot left every stored password permanently unreadable.
  • Saving a connection in a shared cloud database no longer destroys a password the account is not allowed to see. A member with permission to edit but not to reveal wiped a connection's password — and a credential's two-factor seed — simply by renaming it.
  • A user saved with no folder permissions is stored as "no access" instead of full access. Removing somebody's last permission, in order to take access away, handed them the entire catalog instead: a shell and file access on every server whose password is stored on the connection itself.
  • Moving or renaming a connection into a folder you are allowed to reveal secrets in no longer discloses a password that was refused a moment earlier, and deleting a folder now happens in a single step on the server instead of a series of calls that could stop halfway and leave the folder half-emptied.
  • Telnet now tells the server its terminal type and its window size, so full-screen programs — vi, top, appliance menus — draw at the right size and follow the window when it is resized.
  • Remote sessions stay on the certificate you approved: RDP verifies the pinned certificate on every reconnect, a VNC server can no longer talk the session down to an unencrypted one, and a connection through a jump host is refused instead of being made directly when the jump host cannot be resolved.
  • FTPS connections now remember the server's certificate on first use and report a change instead of accepting it. A folder's shared credential is also found when the folder name differs only in letter case — before, the connection dialled with no user name and no password at all.
  • RDP sessions open at the real size of the window. The first connection to a server always came up at 1280x800 stretched to fit, and only resizing the window or reconnecting corrected it.
  • Logging off inside a Windows RDP session no longer takes the whole application down with it. Ending a session on purpose — RDP, SSH, Telnet, a serial line or VNC — now simply closes the tab, and the red "connection lost" card is kept for a genuine break. The cursor is also placed in the terminal on every session, including the first connection to a host whose key had to be confirmed.
  • A change made on another device is no longer overwritten in silence: every online save and delete now carries the version it was based on, and a clash is reported as "changed on another device".
  • Changing the master password now re-encrypts the writes still waiting in the offline queue as well. They used to stay sealed under the key that no longer exists, which made them unreadable on every device.
  • Offline synchronisation: an edit made offline no longer comes back as a conflict against a change nobody made, and resolving a conflict with Keep my version no longer restores the values from before it.
  • Work done offline survives. A connection created offline no longer disappears when the server later rejects a follow-up change, a create whose reply was lost no longer blocks the queue for ever or adds a second copy of a snippet, and the passwords waiting in that queue are encrypted with the master password instead of being kept readable.
  • A copied password is never handed to a remote server's clipboard unless that host was trusted with "Trust & remember" — and the trust dialog now says so as part of the decision.
  • Imported connections: IPv6 addresses, ports and files saved by PuTTY or mRemoteNG on a non-English Windows are read correctly, and the port field rejects an impossible value while you type it instead of failing later at connect time.
  • Full-window and full-screen mode apply only while a session is on screen — leaving one with either still set used to leave the app with no tree, no menu and no way to undo it. The app also carries the same set of certificate pins as the mobile clients, so renewing the site certificate onto a different issuer cannot cut installed copies off from cloud sign-in and updates, and every native library in the packages is verified against a checksum while the package is built.
Version 1.7.4
  • The macOS app opens again. Its background service was signed without the permission macOS requires to run it, so the system stopped the service the moment the app started and the window reported that it was unavailable.
  • The macOS builds are signed with a Developer ID and notarised by Apple, so macOS opens them without warning about an unidentified developer and without the right-click workaround.
  • Right-clicking in a terminal now copies the selected text when there is a selection and pastes when there is none. This is the new default; the previous behaviour, where the right button always pastes, is still available in a connection's SSH options.
Version 1.7.3
  • The master password for a cloud database can now be set right in the app: every stored password is encrypted on your device before it is uploaded, so the master password itself never leaves your computer.
  • The master-password dialog gains a Generate button that creates a strong random password and shows it so you can write it down.
  • Setting a master password — in the app or on the website — now also encrypts the passwords that were saved before it existed; previously they quietly stayed unencrypted.
  • The database page on the website now shows a clear red warning while there is no master password, with a button to set one right there and a password generator.
Version 1.7.2
  • The master password is verified properly: a stored value that only looks like an encrypted secret no longer opens the vault, and the number of key-derivation rounds taken from the database is bounded at both ends.
  • The local key file is never replaced when it exists but cannot be read — it is kept aside and the loss is reported. Losing it silently meant every locally stored password became undecryptable.
  • Ctrl+L now clears a revealed password from the screen as well as locking the vault.
  • "Copy As" copies the connection's own password instead of the one resolved from a shared credential, so a shared secret is no longer duplicated into a new row.
  • File transfers: the guard follows symlinks, refuses network paths, and protects ~/.ssh, the auto-start folders, the shell startup files and the app's own configuration from being written into.
  • The channel token the shell hands to the backend is no longer readable from the process environment on Linux and macOS.
  • The macOS build no longer ships with developer tools enabled — the check they were tied to always reported "not packaged" inside a signed .app.
  • Changing the database mode asks for confirmation first: the drop-down alone used to clear the device configuration and sign the user out.
  • The messages confirming an import or a database snapshot are actually shown now, and remote file names are no longer run through the interface translator.
  • 38 previously untranslated strings — mostly backend error messages — are available in Russian, Ukrainian and Georgian.
  • Packaging: the .rpm now records real file permissions, the downloads on the site are signed with the same GPG key as the repositories, and all four package builds verify the Electron and koffi versions the same way.
Version 1.7.1
  • The terminal now colours what matters in the output: errors, warnings and success words, IP and MAC addresses and URLs. It paints the text already on screen, so full-screen programs like top or nano keep working and colours the server itself sent are left untouched. Switch it off in Settings → Appearance.
  • A tab can now be reset from its right-click menu: the session is dropped and the same connection is dialled again in place, for every protocol. A pinned tab stays pinned.
  • macOS on Apple Silicon: the app starts normally again. Everything inside the app bundle is now signed for arm64, so the background service is no longer stopped by the system on launch — the "backend unavailable" message on M-series Macs is gone.
  • Linux packages: the built-in RDP engine is back. A mismatched native module quietly disabled it, so RDP connections fell back to an external client.
  • Signing in with Google or Microsoft now exchanges a one-time code instead of carrying the session token in the address bar, and the browser tab finishes on a clean page.
  • New sign-in window: the BURSUcloud flow is now two clear steps — sign in, then pick a database from a proper list — and the window no longer needs a scroll bar.
  • The first-run setup window now asks for the interface language and starts in the language of your system.
  • Certificate verification is now configured separately for RDP, VNC and other TLS transfers, each on its own settings tab, instead of following the SSH host-key setting.
  • File transfers over SFTP now go through the jump host configured for the connection, like the terminal does. FTPS in implicit mode and the passive-mode setting are applied as chosen.
  • Clearing a password, an SSH key, a passphrase or a two-factor code now really removes it — in the app, in the cloud catalog and on the web portal.
  • Quick Connect asks for credentials when a connection needs them, and opens RDP in the built-in engine instead of an external client.
  • The file manager reports a failed download instead of leaving an empty file behind, and its delete confirmation is no longer titled "Replace file?".
  • User management: the Delete button works again — its confirmation dialog was never shown.
  • Clearer feedback where the app used to stay silent: a refused password reveal, a failed vault unlock and a rejected offline change now say what happened instead of doing nothing.
  • The About window was rebuilt around what the app actually does today, including VNC, offline mode and two-factor codes.
  • A round of security and reliability fixes across the app, the cloud portal and the mobile client.
Version 1.7.0
  • SSH private keys can now be stored in the connection itself, encrypted with your master password. The key travels with your database, so a connection that needs a key works on every computer you sign in from — no more copying key files around or fixing paths that only existed on one machine.
  • The private key box sits in the connection dialog with a Browse button that reads a key file straight in, and a Delete key button that removes a stored key for good.
  • Authentication is now chosen in the connection dialog itself, and only the fields that choice needs are shown: username and password for password sign-in, the key and its passphrase for key sign-in.
  • A connection that signs in with a key and has no password is no longer shown as if it had no credentials — the connection list and the details panel now mark it with a key.
  • Connections and credentials record who created them, shown in the details panel. Ownership can be handed to any user allowed to edit that folder, so a leaver's entries need not stay in their name.
  • Stronger protection for saved secrets: every stored password, key and two-factor code is now cryptographically tied to the entry it belongs to, so it can only ever be opened in its own place.
  • The connection list now refreshes by itself when another device changes something — and only when something actually changed, so your selection and open folders stay where you left them.
  • Every confirmation and message now uses the app's own dialogs instead of the browser boxes Electron shows, so they follow the app theme and no longer freeze the window while open.
Version 1.5.3
  • Right-click menu in the app's dialogs: Cut, Copy, Paste and Select all now work in the connection and credential forms, just like on Windows.
  • Offline-mode hardening: on a shared computer, signing in with a different account now clears the previous account's offline cache and queued changes, so one user can never see another's cached catalog. The database health-check is also rate-limited.
Version 1.5.2
  • Offline mode: when the network — or the database itself — is unreachable, BURSUcm keeps working from an encrypted local copy of your catalog, including a full start with no connection at all.
  • Changes made offline are queued and uploaded automatically as soon as the database is reachable again — items created offline get their real identity on sync, with linked credentials and jump hosts preserved.
  • A status bar shows what is happening: red while offline (with an offline-changes counter and a Retry button), amber while synchronizing, green Synchronized for a moment when done.
  • If the same item was changed both on this device and on the server, a conflict window shows the two versions side by side and lets you keep either one — passwords are never displayed there.
  • Availability is detected by pinging your database itself — every 30 seconds in the background and instantly when you act — so a dead server is noticed even while the internet is fine, and recovery is picked up within half a minute.
  • Signing out while offline now warns how many changes are still waiting to be uploaded.
  • Works for both BURSUcloud and direct PostgreSQL databases — PostgreSQL keeps an up-to-date local mirror on this computer.
Version 1.5.1
  • Changing, enabling or turning off the master password now re-encrypts every stored secret in a single atomic step, and re-keying a cloud vault no longer loses saved two-factor (TOTP) codes.
  • Backups are safer: restoring a snapshot is atomic and no longer drops connection options, two-factor codes or snippets, and a portable export of a database that is currently in use is now written correctly.
  • VNC and native RDP sessions are sturdier: stricter limits while decoding a remote screen, held keys are released when the window loses focus, and sessions stop cleanly when their window closes.
  • If the backend ever stops, the app now restarts it and restores your session instead of leaving dead tabs behind.
  • The terminal has a slim scrollbar, SSH agent authentication works again on Linux and macOS, and a connection that fails now reports the error instead of leaving a tab that looks connected.
Version 1.5.0
  • VNC support: connect to VNC servers with TLS/VeNCrypt encryption, Tight, ZRLE and Hextile encodings, view-only mode, clipboard sharing and scaling — and import your existing .vnc files in one click.
  • TOTP two-factor codes in credentials: store a Base32 or otpauth:// secret and get a live 6-digit code with one-click "Copy TOTP code", protected by the master-password vault.
  • Built-in password generator in the credential dialog: choose the length and character classes and copy a strong password in one click.
  • Customisable terminal appearance: pick a colour scheme (Classic, Dracula, Solarized and more), font family and size for your SSH, Telnet and Serial sessions.
  • Log session output to a file: turn on per-connection logging to keep a transcript of a terminal session; the log folder is configurable in Settings.
  • More native RDP options in the UI: RemoteFX, UDP transport, smart-card redirection and the GFX pipeline are now exposed in the RDP options dialog and as global defaults.
  • Wake-on-LAN: send a magic packet to a connection's MAC address straight from its right-click menu to power on a sleeping machine.
  • The BURSUcloud account card now shows the logo of the provider your account signs in with — Google, Microsoft or BURSUcloud.
  • The app now reconnects to its backend automatically if the link drops, showing a clear status banner while it does, and every request now has a timeout so the interface can't hang forever.
  • Consistent menus and cursors across the app: menu bars and pop-up menus use the standard arrow cursor, matching the desktop app.
  • Reliability and security fixes: closed several backend resource leaks, tightened access checks so restricted users can't see folders they aren't allowed to, and made restored sessions and file transfers more robust.
Version 1.3.1
  • The built-in BURSUrdp RDP engine is now on macOS too, on both Intel and Apple Silicon Macs: remote desktops render directly inside the app with H.264 graphics, remote audio, clipboard and multi-monitor support — no extra software to install.
  • Stronger at-rest security on Linux and macOS: the machine-local encryption key is now bound to this computer instead of being stored in the clear, so copying your configuration to another machine no longer exposes your saved secrets.
  • The connection to bursucm.com is now certificate-pinned, adding protection against network interception when you sign in or check for updates.
  • Telnet connections now warn that the session is unencrypted, matching the Windows app.
  • The "Open logs folder" button in Settings now creates the folder if it doesn't exist yet, plus additional hardening across local file access, SSH port forwards and the RDP certificate prompt.
Version 1.3.0
  • Our own built-in RDP engine (BURSUrdp) now on Linux: the remote desktop is drawn directly inside the app from one self-contained library that works the same on every distribution — no extra packages to install.
  • Multi-monitor RDP: each extra monitor opens as its own movable window you can drag onto a second screen and switch to full screen (F11); its resolution follows the window size and its position is remembered.
  • Smoother remote desktop: H.264 video decoding and remote audio, all built into the app.
Version 1.2.1
  • Serial (COM port) connections work again, and Telnet sessions now accept keyboard input reliably.
  • Open with Remote Desktop on Linux is fixed: the system RDP client starts reliably, the password is passed securely, and if it is missing the app shows the exact install command for your distribution.
  • The app now starts with a proper splash screen and launches noticeably faster.
  • The main window remembers its size and maximized state, and launching the app again focuses the running window instead of opening a second copy.
  • All local files now live in one BURSUcm config folder with tidy subfolders for data, security and logs — existing files, including the local encryption key, are migrated automatically.
  • Security hardening: internal IPC requests are accepted only from the app's own interface, and trusted web tab certificates are pinned by fingerprint.
Version 1.2.0
  • You can now arrange connections and credentials inside folders in any order you like — hover a row and use the up/down arrows. The order is saved in your database and synced everywhere: the Windows app, the portal and the Android app show the exact same order.
Version 1.1.1
  • Fixed the application icon on Linux: on GNOME desktops the dock and taskbar showed a generic placeholder instead of the BURSUcm icon. It now displays correctly (KDE was already fine).
Version 1.1.0
  • A deep security-hardening pass across the whole app: the internal UI-to-backend channel is now authenticated, every permission is enforced by the backend itself, the interface runs under a strict Content-Security-Policy, external links only open over safe schemes, and the Electron runtime was upgraded to version 43.
  • Stronger secret protection: sign-in attempts are throttled even across restarts, older password hashes upgrade to PBKDF2 automatically, portable backups use a stronger key derivation, and on Windows the local key file is bound to your OS user.
  • Safer terminal paste: pasting multiple lines asks for confirmation with a preview on every path — Ctrl+V, Shift+Insert, right click or the context menu — line endings are normalized, and bracketed paste is supported, so nothing runs before you press Enter.
  • RDP: copy and paste through the system clipboard, reliable reconnect after a dropped session, and proper detection of GNOME Remote Desktop hosts.
  • If the vault is locked when you connect, the app now asks for the password on the spot instead of failing the connection.
  • Split view layout fixes, and folders and FTP connections got their own colored icons.
  • A much leaner install: the backend ships as a single file and the interface as one archive — packages are smaller, install far fewer files, and the macOS disk image shrank by about a third.
Version 1.0.0
  • First release of BURSU Connection Manager for Linux (Debian/Ubuntu, Arch/CachyOS, Fedora/RHEL) and macOS — the same connection manager, now native on your desktop.
  • All protocols in tabs: SSH (with jump hosts / bastions, local and remote port forwarding and tunnels), RDP, Telnet, Serial, Web (a built-in browser for device admin panels), and FTP / SFTP with a dual-pane file manager and drag-and-drop.
  • BURSUcloud sync: keep your connections and credentials in a zero-knowledge cloud — your master password never leaves your device — and sign in with email, Google or Microsoft.
  • Encrypted credential vault protected by a master password, unlockable at startup or later in Settings.
  • OLED-optimised dark theme and four interface languages: English, Russian, Ukrainian and Georgian.
  • Split view, broadcast input to every open session, reusable command snippets, and last-session restore.
Version 1.8.8
  • Keep an SSH session in tmux, from the phone too. A checkbox and a session name in the editor's SSH section make the connection attach to that tmux session when the shell opens — the same line the desktop clients type, byte for byte, so a session started here is ready for the desktop and the other way round. The title shows “(tmux)” while the shell is inside, a dropped connection returns you to the same screen with the same programs still running, and a server without tmux says so and carries on without it.
  • A SOCKS5 proxy set up on the desktop survives a save from the phone. A dynamic (-D) forward has no target host or port by design — the SOCKS client names one per connection — and this screen used to keep only forwards that had both, so merely renaming such a connection here wrote the tunnels back with the proxy gone. It is drawn now as a sentence with a delete button rather than as two red “fix me” boxes, and it is kept as it is; the phone itself does not start it, because on Android a proxy on 127.0.0.1 could serve no other app.
  • The desktop's settings are never lost in a save from the phone. A protocol-options value of a shape this app did not expect — a key of a new kind, a wrong-typed one written by another client — made the whole block unreadable, and the next save wrote exactly that back: the desktop's tunnels, proxy and tmux choice gone, silently. The editor now knows when it could not read the block, says so in the advanced section, and keeps it untouched on save.
  • WinRM connections show up as themselves. A WinRM row from the catalog had SSH's blue and SSH's icon, tapping it did nothing, and the type picker could not create one — or change a row back once its type was changed by mistake. The row now carries the desktop's WinRM colour and glyph, SSH and WinRM are told apart at a glance, the picker offers WinRM so a row can be prepared here for the desktop, and tapping a WinRM row says plainly that it opens on the desktop — this app cannot start one yet.
  • Terminal details. The echo filter hid every line carrying its marker, so a line in a file you read with cat could keep its tail from you; it now hides only the one line this side typed. A server that printed “tmux=on” in its banner could put “(tmux)” in the title of a session that never asked for tmux; the marks are read only in a session that did. And the tmux line sets the mouse for the session it joins rather than for every session on the server.
Version 1.8.7
  • A connection now says HOW it logs in — with a password or with a private key — and asks for that one only. Until now both boxes stood open at once and the app decided for itself by looking for a key on file, so a connection the desktop logs into with a password, keeping a key on file for something else, logged in here with the key. The choice is stored with the connection, in the same field the desktop has always written, so both agree about the same row.
  • Choosing a saved record settles that choice with it. Pointing a connection at a “login and password” record used to leave a private-key box on screen underneath it, with nothing on the form able to turn it off — and a key record still supplies its own key, as before.
  • Removing a stored key, its passphrase or the password is a button now, with a confirmation and an undo. It was a checkbox, and a ticked box said nothing about whether anything had happened — it has not, until you save. Once pressed, the row says what will happen on Save and offers to take it back.
  • A password this app cannot read can now be removed. Emptying the box is how a password is deleted, and the box is empty anyway while the vault is locked or the server withholds the secret — so until now such a password could not be removed from the phone at all. The key and its passphrase have worked that way for a while; the password had been left behind.
  • A private key left on a connection you have since switched to password login stays removable. The key boxes go, because the connection is not asking for a key any more; the delete buttons stay, and the form says why they are there.
  • Smaller fixes: the two authentication choices are told apart at a glance — the one in force is filled, the other outlined — and the app is a little smaller on disk.
Version 1.8.5
  • An SSH private key can now be saved in the credential store and used by any SSH connection, its passphrase included. Both are sealed on your device like every other secret, and a connection pointed at a stored key no longer fails with “key not found” while that key sits in the list beside it.
  • Choosing a credential is now the folder tree itself — its folders, their order, the way you left them folded — instead of a flat list forced open. A fold made here is a fold everywhere: it is the same state the desktop and iPhone clients write, so the tree comes up as you left it on whichever client you left it.
  • Private-key and passphrase fields appear only where a key can be used. An RDP, VNC, telnet, FTP or serial row was drawn with boxes no session of that kind could ever present, while the credential picker beside them already refused to offer key records for the same row.
  • RDP and VNC: dragging with a finger moves the pointer instead of drawing a selection rectangle. Whether a touch was the second tap of a double-tap was decided from “did any gesture end recently?” — which is just as true after a drag, a right click or a two-finger scroll as after a tap.
  • The folder now sits beside the name, and the username and the password stay together. Both editors and both detail cards used to wedge “where does this live” and “whose is it” between the username and the password, splitting the one pair on the screen that belongs together.
  • A connection whose key this session may not read now refuses to connect, and so does one whose jump host has an unreadable secret. Until now an empty password went to the target and to every jump host instead, so a withheld, deleted or locked-away key arrived at the server as a wrong password.
  • When the server refuses a save you see what it said. The portal answers in a sentence — that a connection uses a credential you cannot see, that a field is too long — and all of it used to arrive as “Save failed (400)”. Key fields also have a size limit now, so pasting a whole file no longer freezes the app while it is encrypted.
  • Smaller fixes: the notification permission is asked once at first launch instead of at the moment you connect; a stored key can be removed while the vault is locked; replacing a key clears the passphrase that belonged to the old one; an exported connection remembers which credential it logs in from; a database with no master password no longer describes itself as “locked”; and key fields ask for a plain keyboard, so autocorrection cannot rewrite a key or keep it in the keyboard's learning cache.
Version 1.8.4
  • Sign in with Apple or GitHub, alongside Google and Microsoft.
  • An RDP server now has to prove it holds the private key for the certificate it presents. Until now a matching fingerprint was accepted on its own, so anyone able to place themselves between you and the server could copy that server's certificate and pass the check with it.
  • The app opens your remembered database immediately on start. It used to show the databases list for the length of a network round trip — about a second on every cold start — even though the database to open and its contents were already on the device.
  • A database that keeps secrets in the vault now always asks for the master password. Whether sealing applies is decided from the database itself rather than from a single field in the server’s reply, so a reply that says nothing can no longer be read as “no vault here”.
  • Text pasted into a terminal is cleaned of control characters, and if it would run a command by itself you are asked first.
  • On a shared device, signing in as a different account starts every session clean — no scrollback, file listing or remote screen left from the previous account, in all five kinds of session.
  • Connections through a jump host no longer pass through a local port that any app on the phone with internet permission could reach; they are dialled inside the SSH connection itself.
  • Smaller fixes: rdp:// links can no longer smuggle in settings you did not choose, such as turning off network-level authentication or sharing your drives; the app lock asks for the same kind of unlock that armed it; masked fields no longer teach the keyboard your secrets; and a folder named “,-1” no longer breaks the saved order of your connections.
Version 1.8.2
  • A vault saved with older security settings now opens instead of reporting a wrong master password. Such vaults are still served on purpose, and every other client already explained the real reason — only here a correct password was called wrong.
  • Changes made offline survive an offline copy that cannot be read. That copy used to be treated as no copy at all, and the queue of edits the server has never seen went with it; it is now set aside rather than overwritten, and a copy that cannot be written is reported instead of passing unnoticed.
  • Changing the master password can no longer leave queued changes locked under the old one if the app stops midway through the change.
  • Connections keep the order you arrange them in by hand.
Version 1.8.1
  • Pinch-to-zoom and panning work again in a VNC session: the gesture used to advance one step and then freeze until you lifted both fingers off the screen.
  • A correct master password now opens the vault even when you dismiss the fingerprint prompt. It used to leave the vault closed without saying anything, which read as a wrong password.
  • After you edit a connection, its card shows the new name and address straight away instead of the values from before the edit.
  • An FTPS session is now marked as encrypted, so a connection running in clear text is recognisable at a glance, and FTP transfers show which file is moving and how far it has got.
  • A running session shows its notification again on Android 13 and newer. Without it a session could hold the device awake with nothing on screen to say so.
  • A connection that fails no longer leaves anything behind it: an SFTP session that could not open its channel used to keep the SSH connection, and every jump host along the way, open until the app was closed.
  • The app now installs on 32-bit devices as well.
  • Security and reliability: the master password is wiped from memory as soon as the vault key is derived, a malformed image from a VNC server can no longer end the session, and the synchronisation banner no longer reports success when the catalog could not be refreshed.
Version 1.8.0
  • Rotate the phone during an RDP session and the desktop follows: the app now asks the server for a matching resolution on the fly, without reconnecting, and the picture fills the screen edge-to-edge in both orientations.
  • Direct touch for RDP and VNC: a new input mode where a tap clicks exactly where your finger lands and dragging moves what is under it — switch between the trackpad pointer and direct touch from the session panel, and your choice is remembered.
  • A session the remote side ends — a logout in Windows, an exit in the shell — now closes its own window with a notice, instead of leaving a dead screen that looks like a hang.
  • Better on tablets: the side-by-side layout now works in portrait too, and while nothing is open the right pane shows a welcome panel with quick actions, live catalog numbers and your minimized sessions. A new Home button in the catalog bar always brings you back to it.
  • A limit on simultaneous sessions keeps the app fast: up to 5 run at once by default, adjustable from 1 to 20 in Settings.
  • Creating an account is now one tap from the sign-in screen, full-screen sessions use the whole display on devices with a camera cutout, and the on-screen keyboard opens reliably in remote-desktop sessions.
  • Security hardening and smaller fixes across the app, including stricter validation of connection settings.
Version 1.7.0
  • A connection can now carry its SSH private key with it, encrypted with your master password. Add the key once on any device and the connection works from the phone too — no key file to copy onto it.
  • A connection that signs in with a key and has no password is marked with a key instead of looking as if it had no credentials, and the jump-host picker lists only the connections marked as jump hosts.
  • Connections and credentials show who created them.
  • Stronger protection for saved secrets: every stored password, key and two-factor code is now cryptographically tied to the entry it belongs to, so it can only ever be opened in its own place.
  • While the vault is locked, password and key fields stay empty instead of showing the stored ciphertext, so saving a form can no longer overwrite a secret you could not read.
  • Signing in with Google or Microsoft is more robust: the reply is matched to the request your device started, so another app on the phone cannot interrupt a sign-in in progress.
  • Connecting to a VNC server is sturdier against a server that sends malformed or oversized data.
Version 1.5.2
  • Offline-mode hardening: on a shared device, signing in with a different account now clears the previous account's offline cache and queued changes, so one account can never see another's cached catalog.
Version 1.5.1
  • Offline mode: the app now opens your database from an encrypted local copy when there is no connection — including the databases list after a restart.
  • Changes made offline are queued and uploaded automatically when the connection returns; conflicting edits are resolved side by side, and items created offline get their real identity on sync.
  • A status stripe shows the connection state: red while offline with an offline-changes counter and a Retry button, amber while synchronizing, green when synchronized.
  • Availability is detected by pinging the database itself, so a dead server is noticed even while the internet works.
  • Signing out while offline warns about unsynced changes.
Version 1.5.0
  • Remote desktop, built in: connect to Windows machines over RDP directly inside the app — no separate remote-desktop app needed. A trackpad-style pointer, an on-screen keyboard, Ctrl+Alt+Del and automatic resolution scaling make a full desktop usable on a phone, and the connection is protected with network-level authentication (NLA/CredSSP).
  • VNC, built in: view and control any VNC server from your phone, with VeNCrypt/TLS encryption, all the common encodings (Raw, CopyRect, RRE, Hextile, Zlib, ZRLE and Tight/JPEG) and trust-on-first-use verification of the server's certificate. Pinch to zoom and drag to pan around the desktop.
  • SFTP and FTP file managers: browse a server's files and download, upload, rename, delete, create folders or change permissions (chmod) — over SSH (SFTP) or FTP/FTPS.
  • A rebuilt SSH terminal: the terminal now runs on a real, battle-tested VT engine for accurate colours, cursor handling and full-screen text apps like Midnight Commander. A one-tap on-screen keyboard button and a fixed CTRL key make it comfortable to use on a phone.
  • Jump hosts and port forwarding: reach a server through one or more bastion/jump hosts — with the host key verified against the real target — and open the local (-L) and remote (-R) port forwards you defined, just like the desktop app.
  • SSH key authentication: connect with a private key, not only a password.
  • Run several sessions at once: press Back to minimize a session — its SSH tunnels and port forwards keep running in the background — then switch freely between your active sessions and disconnect explicitly when you're done.
  • Web connections now open in your device's default browser, which handles logins, downloads and certificates the way you expect.
  • More secure sign-in: signing in with Google or Microsoft now uses verified app links on bursucm.com instead of a custom link scheme, closing off a class of link-hijacking attacks.
  • Optional screenshot protection: a new setting (off by default) can block screenshots and screen recording of sensitive screens, and the app locks itself after a period of inactivity.
  • Export and import your connections, to keep a backup or move to another device.
  • Made for tablets: in landscape and on tablets a two-pane layout shows your catalog and the open session side by side, and connections can be reordered by drag-and-drop.
  • Smoother throughout: animated screen transitions and a loading skeleton instead of a blank screen while the catalog loads.
Version 1.4.1
  • Connections and credentials inside folders now follow the manual order you set — arrange them once in the desktop app or on the portal, and the phone shows the exact same order.
Version 1.4.0
  • Sign in with Microsoft: personal and work Microsoft accounts now work in the Android app too
  • The app now follows your device's light or dark theme by default — a fixed Light or Dark theme is still available in Settings
  • Signing out no longer resets your theme and language back to defaults
Version 1.3.0
  • Security: biometric unlock is now hardware-backed — the vault key is protected by a key inside the Android Keystore that physically cannot be used without a successful fingerprint scan (BiometricPrompt CryptoObject)
  • Security: sensitive screens (terminal, password views, editors) are protected from screenshots and screen recording, and their content is hidden in the Recents app switcher
  • Security: certificate pinning for bursucm.com — connections are refused if anyone tries to substitute the server certificate (man-in-the-middle protection)
  • Security: the vault now locks automatically after 5 minutes in the background — returning to the app asks for your fingerprint or master password again
  • Security: new optional “Lock App on Start” setting — require a fingerprint immediately on launch, before anything is shown
  • Security: app data is excluded from cloud backups (encrypted keys never leave the device)
  • Security: signing in again now revokes the previous session on the server, so the “Connected devices” list on the portal stays accurate
  • Search now automatically expands the folders that contain matches
Version 1.2.2
  • Added support for the FTP and FTPS protocols
  • Folders now follow the order saved on your other devices
Version 1.2.1
  • Security: biometric unlock now stores a locally derived encryption key instead of your master password — your master password is never written to the device anymore
  • If the stored key no longer matches (e.g. after a master-password change), biometric unlock safely resets and asks for the password again
Version 1.2.0
  • New: biometric unlock for your master password — sign in with fingerprint or face instead of typing it
  • The Android app leaves beta
  • Additional security and stability improvements
Version 1.1.0
  • New: multi-language support (English, Russian, Ukrainian, Georgian)
  • Security improvements across the app
  • Various cosmetic and UI polish
Version 0.1.0
  • First initialization of the Android app
Version 1.2.8
  • Keep an SSH session in tmux, from the iPhone and iPad too. A toggle and a session name in the editor's SSH section make the connection attach to that tmux session when the shell opens — the same line the desktop clients type, byte for byte, so a session started here is ready for the desktop and the other way round. The screen title shows “(tmux)” while the shell is inside, a dropped connection returns you to the same screen with the same programs still running, and a server without tmux says so and carries on without it.
  • A SOCKS5 proxy set up on the desktop survives a save from the phone. A dynamic (-D) forward has no target host or port by design — the SOCKS client names one per connection — and this app used to keep only forwards that had both, so merely renaming such a connection here wrote the tunnels back with the proxy gone. It is drawn now as a sentence with a delete button rather than as two “incomplete” boxes, the detail card shows it as “-D 1080 (SOCKS5)” instead of a broken local forward, and it is kept as it is; the app itself does not start it, because on iOS a proxy on 127.0.0.1 could serve no other app.
  • WinRM connections show up as themselves. A WinRM row from the catalog was drawn with SSH's glyph and SSH's blue, tapping it did nothing, and the type picker could not create one — or change a row back once its type was changed by mistake. The row now carries the desktop's WinRM colour and the command-prompt glyph, SSH and WinRM are told apart at a glance, the picker offers WinRM so a row can be prepared here for the desktop, and tapping a WinRM row says plainly that it opens on the desktop — this app cannot start one yet.
  • Terminal details. The echo filter hid every line carrying its marker for the whole session, so a line in a file you read with cat could keep its tail from you; it now hides only the one line this side typed, and an echo that never came back no longer hides a later line. And the tmux line sets the mouse for the session it joins rather than for every session on the server.
Version 1.2.7
  • RSA keys work with modern servers again. An RSA key that read perfectly was refused by every OpenSSH 8.8 and newer — the key was being offered with a SHA-1 signature, which those servers stopped accepting in 2021. It is now offered as rsa-sha2-512, then rsa-sha2-256, then the old name, one per attempt, the way OpenSSH's own client does. Ed25519 and ECDSA keys were never affected, which is why the same catalog worked row by row and not for this one.
  • The keys people actually have now open. A key with Windows line endings — the ordinary result of copying one through the clipboard — was reported as damaged, and so was a PKCS#8 Ed25519 key, the shape OpenSSL and Go write. Anything outside one container shape got a message naming a cause it did not have: “ECDSA keys are not supported yet”, for keys that were not ECDSA. Every refusal now names its own reason, and each key is proved usable rather than merely readable — it signs a message and is checked against its own public half.
  • A connection now says how it logs in — with a password or with a private key — and shows one box at a time, as the desktop and Android do. Before, both boxes stood open and the app decided for itself by asking whether the row had a key, so a connection the desktop logs into with a password could log in here with a key it was keeping for something else. Connections saved before this keep behaving exactly as they did.
  • Your own stored key is visible again. The editors fill in the key and its passphrase for an account the server lets see them — what the desktop and Android have always done, while the phone showed nothing at all, so there was no way to get your own key back out of it. A box you do not touch is left alone rather than re-sealed, so opening an editor no longer marks a key as changed when nothing changed.
  • Removing a stored key — or a stored password — is a button with a confirmation instead of a switch. A switch describes a state the row is in; removing is something you do once, and it has not happened until you press Save. The row now says what will happen and offers to take it back, and taking it back really does put the key back in the box.
  • A session that fails says why. “The operation couldn’t be completed. (Citadel.SSHClientError error 4.)” was a number in English naming a list nobody can see. Every failure a person can actually meet now has a sentence, in all four languages, shared by the terminal, the file browser and port forwarding — and a server that cannot be reached says so instead of reporting an error code.
  • Three faults in the connection editor, all reported from a phone. A key belonging to a saved credential could be written onto the connection as its own when the link was dropped; the hint “the password comes from the saved credential” stayed under the box after unlinking; and the username sat above the credential picker that fills it.
  • Credentials read like the catalog does. The picker is the catalog's own tree, folded the way the database says, and the detail cards follow the editors: where the connection lives first, then who logs in. The folder now sits with the name instead of between the username and the password.
Version 1.2.4
  • BURSU Connection Manager is on the App Store. It installs on iPhone and iPad like any other app — no invitation, no build that stops working after ninety days, and updates arrive the ordinary way instead of through a separate testing app.
  • An account can now be closed from the phone: Settings — Delete account removes the account, every database in it, and every connection and credential those databases hold. Until now the whole operation lived on the website only, so a device could sign out but never close the account it was signed in to.
  • The delete button sits in a section of its own below Sign out and the confirmation names exactly what goes, so a mis-tap cannot end an account by accident. For an account created with Sign in with Apple the app also withdraws its Apple authorisation, so the app stops appearing in the list of apps you have signed in to with Apple.
Version 1.2.1 (28)
  • An RDP server proves that it holds the private key for the certificate it presents, so the fingerprint you trusted on the first connection identifies the machine itself and not merely a copy of its certificate. A peer that cannot prove it is refused before anything is sent.
  • Whether your secrets are sealed is decided on the device. The app judges by the sealed data it is already holding rather than by what a server tells it, so a saved password or a private key always leaves the phone encrypted. Unlocking is also checked against the master password in force at the moment it finishes, so one changed on another device mid-unlock is noticed.
  • A VNC connection's encryption setting — off, prefer or require — is now read on iPhone and iPad exactly as it is on the desktop. Connections that never carried one keep behaving as they did.
  • Agreeing to reach a VNC server without encryption covers only the kind of session you were asked about. A weaker one — no authentication at all, or an older version of the protocol — is a separate question and is asked separately.
  • Large catalogs are quick again: a tree of 6,000 folders took over eight seconds to order and now takes under a tenth of a second. Text arriving from a server is capped before the app tidies it for display, so a connection screen cannot be slowed down by what the other end sends.
  • Status lines the app writes into the terminal itself are shown as plain text, so a name carried by a connection cannot act on the terminal. What the shell prints is untouched — its escape sequences are the terminal doing its job.
  • The private-key field is a proper secure editor: no autocorrect, no spell check, no autocapitalisation and no smart punctuation. It keeps the key out of the system keyboard's learning cache, and it stops a smart dash or a capitalised letter from quietly corrupting a pasted key.
Version 1.2.0 (27)
  • Sign in with Apple and with GitHub, next to Google and Microsoft. Apple's sign-in runs through the system sheet, so an account already on the device needs nothing typed.
  • Face ID is asked for the moment the catalog appears from the cache, instead of one round trip to the portal later — the prompt now arrives with the tree rather than a beat behind it.
Version 1.1.22 (24)
  • A connection's folder is picked from the tree instead of typed. Typing it meant knowing a separator the app never shows, and a single different character quietly created a second folder beside the intended one; a new connection now also starts in the folder you added it from.
  • Manual ordering survives two devices at once: rearranging on one device while the other saved its own order — or seconds after a folder was renamed — used to destroy the other's work without a word.