Overview
Learn how Prox Deck protects credentials, verifies connections, and keeps sensitive information on your device. These controls reduce risk but do not make a claim of absolute security.
1. Credentials and Sessions
Keychain Protection
Passwords, API Token secrets, SSH keys, and passphrases are stored through Keychain. Other connection details—including custom HTTP Header values—can be stored in SwiftData.
In-Memory Sessions
PVE Ticket, CSRF token, cookies, authorization headers, and active SSH sessions stay in memory and are not written to persistent app storage.
2. Connection Security
TLS Verification
HTTPS certificates are verified by default. Allowing a self-signed certificate applies only to the selected server route; it never disables TLS checks globally.
SSH Host Verification
SSH Host Keys are checked before trust is saved. Trust decisions remain on this device and should be confirmed against a source you trust.
Tailnet Isolation
Tailnet connectivity is used only for Prox Deck requests. It does not configure a system-wide VPN or route traffic from other apps.
3. Device Protection
Biometric Lock
Face ID or Touch ID can protect selected servers and sensitive setting changes. Prox Deck receives only the authentication result, never your biometric data.
Automatic Re-Lock
The re-lock interval is stored only on this device. After you leave the app, remaining in the background past the selected interval can require authentication again.
Redacted Logs
Saved operation logs contain summaries only. Passwords, tokens, authorization headers, raw certificates, and complete task output are excluded.
Your responsibilities
Keep your device protected, verify self-signed certificates and SSH Host Keys carefully, and remove server access if a device is lost. Use only the PVE permissions each account needs.
Contact
For security questions, email apps.mccray@gmail.com. Do not include passwords, API Token secrets, SSH private keys, authorization headers, raw certificates, or complete task output in an email.
Trademark notice
Prox Deck is an independent third-party client for Proxmox VE. It is not affiliated with, endorsed by, or sponsored by Proxmox Server Solutions GmbH. Proxmox and Proxmox VE are trademarks of Proxmox Server Solutions GmbH. Tailscale and Tailnet are trademarks of Tailscale Inc. Apple, iCloud, App Store, Face ID and Touch ID are trademarks of Apple Inc.