Vault & credentials
How NEO RDP Manager protects your passwords – and how to reuse credentials cleverly.
Master password
On first start you set a master password of at least 8 characters. It is stored nowhere – neither in plain text nor as a hash. The app knows it is correct because it can decrypt the vault key with it.
Change it under Settings → Security → Change master password …. That's instant, because only the vault key is re-wrapped, not every entry re-encrypted.
Encryption in detail
- Key derivation: scrypt (N = 215, r = 8, p = 1) derives a key from the master password. It deliberately costs computing time and makes guessing expensive.
- Vault key: a random 256-bit key encrypts the data; it is stored in the database only wrapped with the derived key (AES-GCM).
- Field encryption: every password – on connections, folders, stored credentials and gateways – is encrypted on its own with AES-256-GCM. GCM also detects any tampering.
- In memory: the vault key exists only while the vault is unlocked and is overwritten when it locks.
- In transit: RDP passwords reach the Windows Credential Manager only while the connection is set up, PowerShell passwords go as a PSCredential. They never show up in files or logs.
Names, hosts, user names, folders and tags are not encrypted – they aren't secrets, and this way the list builds up and searches quickly. If you need to protect those too, keep the database on an encrypted drive (e.g. BitLocker).
Locking & auto-lock
Ctrl+L or the lock at the bottom of the sidebar locks right away. With auto-lock after inactivity (default: 15 minutes, 0 = off) it happens by itself. The window locks together with all sessions – open connections keep running in the background and are back as soon as you unlock.
Stored credentials
Under stored credentials (key icon in the sidebar) you create accounts that many connections share – such as the domain admin or a service account: label, user, domain, password and a note. In a connection or on a folder you then choose “stored credential”. When the password changes, you update it in exactly one place; the list shows how many connections use an entry.
Alternatively, store credentials right on a folder and let the connections below inherit them.
Where the data lives
| What | Where |
|---|---|
| Database (connections, vault, settings) | %APPDATA%\NeoRDPManager\neordp.db |
| Log files | %APPDATA%\NeoRDPManager\logs |
| Screenshots from sessions | Pictures\NEO RDP Manager |
| Portable mode | the data subfolder next to the EXE, as soon as a portable.txt sits there |
About NEO RDP Manager at the bottom of the sidebar also shows the exact paths, plus an “open data folder” button.
Backup & restore
Import & export → Back up vault saves a copy of the database. The passwords inside stay encrypted with the master password, so the backup is useless without it. To restore, quit the app and replace neordp.db with the backup – on the next start, the master password from the time of the backup applies.