NEO RDP Manager logoNEO RDP Manager

Vault & credentials

How NEO RDP Manager protects your passwords – and how to reuse credentials cleverly.

Master password

On first start you set a master password of at least 8 characters. It is stored nowhere – neither in plain text nor as a hash. The app knows it is correct because it can decrypt the vault key with it.

Change it under Settings → Security → Change master password …. That's instant, because only the vault key is re-wrapped, not every entry re-encrypted.

No reset: without the master password, the stored passwords can no longer be decrypted – not even by the developer. Keep it in your password manager, for example.

Encryption in detail

  • Key derivation: scrypt (N = 215, r = 8, p = 1) derives a key from the master password. It deliberately costs computing time and makes guessing expensive.
  • Vault key: a random 256-bit key encrypts the data; it is stored in the database only wrapped with the derived key (AES-GCM).
  • Field encryption: every password – on connections, folders, stored credentials and gateways – is encrypted on its own with AES-256-GCM. GCM also detects any tampering.
  • In memory: the vault key exists only while the vault is unlocked and is overwritten when it locks.
  • In transit: RDP passwords reach the Windows Credential Manager only while the connection is set up, PowerShell passwords go as a PSCredential. They never show up in files or logs.

Names, hosts, user names, folders and tags are not encrypted – they aren't secrets, and this way the list builds up and searches quickly. If you need to protect those too, keep the database on an encrypted drive (e.g. BitLocker).

Locking & auto-lock

Ctrl+L or the lock at the bottom of the sidebar locks right away. With auto-lock after inactivity (default: 15 minutes, 0 = off) it happens by itself. The window locks together with all sessions – open connections keep running in the background and are back as soon as you unlock.

Stored credentials

Under stored credentials (key icon in the sidebar) you create accounts that many connections share – such as the domain admin or a service account: label, user, domain, password and a note. In a connection or on a folder you then choose “stored credential”. When the password changes, you update it in exactly one place; the list shows how many connections use an entry.

Alternatively, store credentials right on a folder and let the connections below inherit them.

Where the data lives

WhatWhere
Database (connections, vault, settings)%APPDATA%\NeoRDPManager\neordp.db
Log files%APPDATA%\NeoRDPManager\logs
Screenshots from sessionsPictures\NEO RDP Manager
Portable modethe data subfolder next to the EXE, as soon as a portable.txt sits there

About NEO RDP Manager at the bottom of the sidebar also shows the exact paths, plus an “open data folder” button.

Backup & restore

Import & export → Back up vault saves a copy of the database. The passwords inside stay encrypted with the master password, so the backup is useless without it. To restore, quit the app and replace neordp.db with the backup – on the next start, the master password from the time of the backup applies.