FAQ
Short answers about accounts, what runs on your servers, what models see, where data is kept, and how Gatesys SSH works with your existing setup.
Short answers to the questions people ask most. Each links to the page with the details.
Accounts and plans
Do I need an account?
No. The Free plan is a full SSH client, with no account and no time limit. Gatesys Pro, which adds Farabi, the AI features and more than one terminal per session, is activated with your account’s plan or with a licence key, which needs no account. See Plans.
What happens when my trial ends?
Your account drops back to Free. Nothing is removed, including your providers, hooks and skills, every Free feature keeps working, and terminals already open stay open. Pro comes back whenever you subscribe. See Plans.
Does Pro include a model?
No. Pro unlocks the features, and you bring the model: a free local one such as Ollama, your own API key for Claude, OpenAI or Gemini, or a Claude Code or Codex CLI you are signed in to. See AI providers.
Are terminal tabs and split panes free?
Free has one terminal in each session, and you can open sessions to as many hosts as you like, each with its SFTP and tunnels. More terminal tabs and split panes in the same session are part of Gatesys Pro. If a licence ends, terminals already open stay open. See Terminal.
Can I use Gatesys SSH on several computers?
Yes. Free has no limit. Gatesys Pro is active on one computer at a time. To move it, click Deactivate this device in the app, or remove the computer on gatesys.ai/account/devices, then activate Pro on the other one. Team plans have one seat per computer they bought. See Seats.
Does it work offline?
Every SSH feature works without reaching gatesys.ai. A Pro licence is checked once a day and keeps working for 14 days after the last successful check. See The daily check and offline grace.
Do I type my password into the app?
No. You sign in on Gatesys’s own page in your browser, and the app gets back a one-time code, never your password. See Sign in and licence.
Does signing out end Pro?
No. The licence belongs to the device and stays after you sign out. Click Deactivate this device to end it and free the seat. See Sign out.
Servers
Does it install anything on my servers?
No agent, no daemon. What the app learns about a host, it reads over the session you opened, with fixed read-only commands, as your own login. It writes to the server only when you ask: uploads and saves, and a Safe Change’s staged copy, backup and safety net. See What runs on the server.
Will my server’s monitoring see it?
Yes, and that is by design. The host-facts read shows up as a short sh -s process tree in session logs, auditd or an EDR, and the service map’s connection listing may be flagged by endpoint security. The exact commands are in Settings › Hosts › Host facts › Show the exact probe commands, ready for an allowlist. See Host facts.
Can I stop it reading facts about a host?
Yes: untick Remember facts about this host in the host editor’s Advanced tab, or turn off Remember host facts in Settings › Hosts › Host facts for every host. Production hosts ask before their first read.
Which servers does it work with?
Any SSH server. Metrics read Linux /proc, with BSD sysctl fallbacks. The service map reads ss on Linux and netstat on macOS and BSD. Safe Change’s safety net is built for Linux with systemd, and is best effort elsewhere.
Your existing setup
Does it use my ~/.ssh/config?
You can import it: File › Import from ~/.ssh/config…. ProxyJump entries become real jump chains, and Match exec is never run. Import again to pick up changes; what you set in the app is kept. See Your first connection.
Does it use ~/.ssh/known_hosts?
No. Gatesys SSH keeps its own list of trusted host keys, so you confirm each server’s fingerprint once in the app. See Host keys.
Does it work with my SSH agent, 1Password or Pageant?
Yes. It uses the agent named by SSH_AUTH_SOCK, and on Windows the OpenSSH agent or Pageant. See Authentication.
AI and privacy
Can I use it without any AI?
Yes. Turn off Settings › Farabi › Use the assistant and no model is called at all. Hop Doctor’s checks, host facts, watches and drafts read by rules, and Safe Change without Farabi all keep working.
Is my terminal output sent to the model?
Only to the one provider you pick, and only with Send host context on: the last 4,000 characters, as the screen showed them. Hidden text is removed first and secrets are masked. Turn Send host context off for a provider you would not show your terminal to. See What runs on the server.
Can the model run a command on my server?
No. A suggested command reaches your shell only when you click Insert (typed, not run) or Run. Its risk is rated on your computer, from its text and never by the model: a dangerous command needs a second click, a critical one needs the host’s name typed, and attacks such as reverse shells are blocked outright. See Command safety.
Can text on a server trick Farabi?
The Injection Shield removes text you could not see, strips invisible characters and chat-template tokens, and fences the rest as data. It does not recognise every paraphrase, which is why command safety and your click stand behind it. Test this model measures how often your model follows a planted line.
Can I change how Farabi answers?
Yes, with Pro. Write your own instructions, such as the language to answer in or your house rules, and turn on skills for kinds of work such as Docker or PostgreSQL. They go below Farabi’s safety core, which you cannot change, and no skill can make Farabi run a command. See Instructions and skills.
Which model should I use?
A small local model of about 8B parameters, such as qwen3:8b, is enough: every feature keeps the model’s job small. Run Test this model to see how yours compares with the rules.
Can I send what happens in the app to my own tools?
Yes, with Pro: hooks send session, command, file, tunnel, watch and AI events to your own webhook, a local command or a JSONL file, and nowhere else. Conversation text is left out unless you turn it on, and hosts, addresses, paths and logins are masked by default.
Data
Where is my data kept?
On your computer: hosts, snippets, the audit log (90 days), host facts and the service map in the app’s own data folder, with passwords, passphrases, API keys, host facts and the service map sealed in the local vault. Preferences, AI providers and hooks are in ~/.gatesys-ssh/settings.json, which never holds a secret, and Farabi’s instructions and your skills are in ~/.gatesys-ssh/farabi/ and ~/.gatesys-ssh/skills/. See Credential storage and The settings file.
What does gatesys.ai know about me?
Your account (email and name), your plan, and the devices you activated: each one’s random device id, computer name, OS and app version, and its daily licence checks. Your hosts, keys, sessions, files, commands, audit log and Farabi conversations stay on your computer. Settings › Account › What GateSys sends to Gatesys lists every call. See What the app sends to Gatesys.
Are session recordings safe to share?
Recordings hold what the shell printed, never your keystrokes, so passwords you type stay out. Anything the server printed is in them, so check before sharing. See Record a session.
Something unclear or wrong? Tell us.