It’s free, it’s in the menu bar, and it does more SSH than we do.

Let’s say it straight away: on pure SSH tunnels, Secure Pipes goes further, it composes remote forwards and SOCKS proxies, which Kestro does not. If that is your need, this page can stop here, and it will cost you nothing.

macOS 11+ · Windows soon

Two scopes

The same spot, two different questions.

What each one puts in its list.

Secure Pipes

Local forwards
Remote forwards (-R)
SOCKS proxies (-D)
Restarts what drops
 
Free
 
and that is the scope.

Kestro

Local forwards
No -R, no -D
 
Cloud SQL, IAP, Session Manager
Green only once the port answers
Your repos, scripts and services
A boundary for your assistant
 
one payment, per machine

Point by point

What each one covers.

Secure PipesKestro
Pricefree€29.99$29.99£25.99CHF 25.90CA$40.99A$45.99 once, per machine
Where it livesmenu barmenu bar
Local forwardsyesyes
Remote forwards (-R)yesno
SOCKS proxies (-D)yesno
Restart after a dropyesyes, with growing backoff
Checks the port is listeningnot advertisedyes: green waits for the first successful connect
Google Cloud SQLnoyes, via the official proxy
Google VMs over IAPnoyes, via gcloud
EC2 over Session Managernoyes, via the aws CLI
Beyond tunnelsnothingGit repos, scripts, monitoring, sharing a port
Access for an AI assistantnoyes, within limits you set
Command linenothe kestro command, composable

Recorded on 7 August 2026 from the Secure Pipes product page and public download listings: version 0.99.10, free, and a page that still describes Intel-based Macs running OS X.

What Kestro adds

Four things outside a tunnel manager’s scope.

They do not make it a better SSH tool: on that ground Secure Pipes goes further, and costs nothing.

  1. The access that isn’t SSH

    A Cloud SQL database through Google’s official proxy, a VM with no public address over IAP, an EC2 instance over Session Manager. Three tools, three syntaxes, three sets of docs: here, one list and one switch.

  2. Green does not lie

    An ssh -L takes one to three seconds to authenticate and then listen: during that window the process is alive and the port still refuses. Kestro probes the local port and only shows “open” on the first successful connect.

  3. A boundary for your assistant

    Claude or Cursor see the tunnels you open to them, one object at a time. Production is closed by default, and a refusal says which one: something a tunnel manager has no reason to offer.

  4. The rest of the day

    Your repos and their branch, your services watched from your own machine, your pinned scripts, a port exposed to the web for the length of a demo.

CodeFileView14:43
Kestro1 tunnel open · 1 service isn’t answering
Filter tunnels⌘FNew tunnel
bastion-prodprodSSHshellbastion.kestro.internalclosed
notes-dbstagingPostgreslocalhost:5432pg-staging.eu-west-1.rdsopen
run-eventsprodMongolocalhost:27017mongo-prod.atlasclosed
⌘K palette↑↓ navigate␣ togglecloses if you click elsewhere
run-tracker , zsh
Applying 2 migrations to shop-staging-db…
20240612_add_orders_index ok
done in 1.4s
run-tracker , zsh
# every door, and which ones are open
tunnel notes-db ouvert :5432
tunnel run-events ouvert :27017
tunnel bastion-prod fermé

On your machine

Everything stays with you.

Your connections run from your computer to your servers, never through us.

  • No account

    Nothing to create, no password.

  • Your keys stay put

    SSH, Google Cloud, AWS: Kestro uses your own tools, locally.

  • No usage statistics

    We don’t know what you open, or when.

  • One exception

    Your licence renews with us. Nothing else leaves.

What Kestro does not do

Three gaps, and the third one is the price.

Better read here than discovered after paying.

  • No -R, no -D

    Kestro only opens local forwards: a door from your machine to a remote service. A remote forward or a SOCKS proxy, it does not compose. Secure Pipes does, and for free.

  • One machine per seat

    Every computer uses up a seat. Secure Pipes installs wherever you like without asking: that is the comfort that comes with being free.

  • You have to pay

    Seven full days, no card and no account, then you need a licence. There is no permanent free tier, and against a free tool that already covers your need, that is an argument we will not try to talk around.

Pricing

You pay once. That’s it.

A tool you open forty times a day shouldn’t send an invoice every month.

Kestro licence

€29.99$29.99£25.99CHF 25.90CA$40.99A$45.99€39.99$39.99£34.99CHF 33.90CA$54.99A$61.99 · Launch offer · upcoming price

1 computer · one-time

  • Every feature of the app, no tiers, no “Pro” edition
  • One year of updates included, then renew if you want to
  • The app stays yours, renewed or not
  • One key, the same on all your computers
  • Switch machines whenever you like, no limit
  • No account to create: the key arrives by email

Or download it for free first →

Refunded within 14 days, no questions asked.

Questions we get asked

I only set up SSH tunnels. Which one should I take?

Secure Pipes, most likely. It is free, it lives in the same place, it restarts what drops, and it composes forwards Kestro does not. The question only tips if your access stops being purely SSH: a Cloud SQL database, a VM over IAP, an EC2 instance over Session Manager, or if you want the rest of the day in the same list.

Can the two coexist?

Yes, as long as they do not open the same local port at once. Both launch your ssh with your keys and store nothing on the server side. Kestro will in fact tell you a port is already taken before trying.

Is Secure Pipes still maintained?

We do not know and will not speculate: that is for its author to say. What the product page states as of 7 August 2026, and what anyone can check, is version 0.99.10 and a description aimed at Intel-based Macs running OS X. Make of that what you will; the software itself works.

Is this table current?

It was recorded on 7 August 2026 from the product page and public download listings. We have not audited the code: “not advertised” means the documentation does not mention it, and nothing more. Write to us if you find a discrepancy and we will correct it.