Frequently asked questions
Can Tressyl lose my data? Is sync a backup?
Yes, it can, and no, sync is not a backup. Tressyl changes, moves and deletes files on all your devices: a bug, a wrong setting or a deletion made on one device can spread to the others. Keep your own backups of anything you care about. Tressyl is pre-release software, provided “as is”, without warranty of any kind, and its authors are not liable for any loss of data or other damage, to the extent permitted by law (sections 15 and 16 of the AGPL-3.0).
What is Tressyl?
Tressyl keeps folders in sync between your own devices, directly and end-to-end encrypted, without an account on a server. It is a native app: you add folders and devices with buttons and your system’s folder picker, not with a command line or a web page. The name comes from tresse, French for braid: your devices interlaced, bound together by one identity. The documentation shows how it works, step by step.
How is it different from Syncthing?
Tressyl belongs to the same family as Syncthing, which inspired it: peer-to-peer, self-hostable, end-to-end encrypted sync. The differences are in how you use it: a native app instead of a web interface, and one identity for all your devices instead of pairing each device with each other one. Tressyl also uses hybrid post-quantum cryptography. Syncthing is mature and widely used; Tressyl is in beta.
Is it free?
Yes. Tressyl is free software under the AGPL-3.0 licence: it costs nothing, and you may read, change and share its code under the terms of that licence. There is no account and nothing to pay. If you want to support the project, you can make a donation.
Which platforms does it run on?
Linux and Windows computers, in beta. An always-on Linux node, for example in an LXC container, can also keep a copy of your folders, in beta. Android is planned; iOS will come later.
Is there a server or a cloud?
No. Tressyl uses no public server by default: your devices connect directly to each other, and find each other on the local network or by IP address (a VPN works too). To connect from anywhere, you can run a relay and a discovery service on your own server. Even through a relay, your files stay end-to-end encrypted: the relay never sees them in clear.
Is my data encrypted?
Yes, between your devices: everything Tressyl sends is end-to-end encrypted, and only your own devices can read it. Each device has its own key, created on that device and never sent to another one. Tressyl does not encrypt the files on your disks: use your system’s disk encryption for that (for example BitLocker on Windows, LUKS on Linux).
What does "post-quantum" mean here?
Future quantum computers could break some of today’s encryption, and traffic recorded now could be decrypted later. When two devices connect, Tressyl combines a classic key exchange (X25519) with one designed to resist quantum computers (ML-KEM-768). Its signatures pair a classic one (Ed25519) with a post-quantum one (ML-DSA-65), and both must be valid. This hybrid approach is the one Signal and web browsers use today: the protection holds as long as either method holds.
Can I self-host the relay?
Yes. Tressyl can use your own relay and discovery services, running on a server you control, so nothing depends on someone else’s infrastructure. Without them, your devices still sync on the local network or by IP address. The setup guide is not published yet.
Is it ready to use?
Not yet: Tressyl is in beta and not released, so there is nothing to download for now. The desktop app runs on Linux and Windows and is being tested. Even once it is released, keep your own backups (see Can Tressyl lose my data?).
How do I report a bug or ask a question?
First look in this FAQ and in the documentation. The GitLab repository will open with the first public release; questions and bug reports will then go through its issues. Tressyl is a one-person project: there is no guaranteed response time.