RC14 BuildFix9 · Production-audited source

Secure local network

Your network is the fast lane.

Move files between Desktop, Android, browser and always-on servers without making someone else’s cloud the middleman. Localynk keeps the transfer path on networks you control.

Protocol 2 authenticated device sessionsResumable uploads & downloadsPrivate-first LAN / VPN scope
LOCALYNK SERVEROnline
▱
DesktopClient
▯
AndroidMobile
⌁
BrowserWeb Client
report.zip72%
photos✓
01Direct transferNo mandatory cloud relay
02Device trustPair, approve, revoke
03Granular sharesBrowse, upload, delete
04Always-onProxmox / Debian / Ubuntu

How it works

One server. The devices you trust.

Localynk is built around an explicit trust model: run a server, approve a device, then grant only the shares that device should see.

  1. 01

    Run your server

    Use Desktop Server for a visual setup, or Headless Server for Proxmox, Debian and Ubuntu.

  2. 02

    Approve the device

    Desktop, Android and Web clients request access. You decide which devices become trusted.

  3. 03

    Transfer with boundaries

    Grant browse, download, upload or delete rights per shared folder, then move files directly across your network.

Localynk ecosystem

Use the interface that fits the machine.

The same Localynk identity and Protocol 2 model across client, server, mobile and headless deployments.

Desktop ClientWindows · Linux

A focused local workspace.

Discover servers, pair once, browse folders, search, upload, download and resume interrupted transfers.

Desktop ServerWindows · Linux

Visual administration.

Manage pairing, shares, permissions, transfers, diagnostics and Web Admin from a desktop UI.

  • System tray controls
  • Per-device permissions
  • 2FA-protected Web Admin
AndroidMobile

Your files from the phone in your hand.

Discovery, pairing, share-aware browsing and resumable transfers in a mobile client built for Protocol 2.

Headless ServerProxmox · Debian · Ubuntu

Turn a small server into a private file hub.

Qt-free headless service, systemd integration, health checks, database backups and browser-based administration.

Open the complete Proxmox guide

Security model

Trust is explicit, not assumed.

Localynk separates administrator access from device access. Admin sessions use password + TOTP 2FA; trusted clients use device bearer sessions with share-level permissions.

Network boundary: use Localynk on a trusted LAN, Tailscale or another private VPN. Do not directly port-forward TCP 8742 to the public Internet.
01
Admin protectionPassword, TOTP enrollment, recovery codes and CSRF-protected sessions.
2FA
02
Device pairingShort-lived pairing codes, explicit approval and revocable trusted devices.
PAIR
03
Share permissionsBrowse, download, upload and delete are controlled per device and share.
ACL
04
Transfer hardeningSize limits, quota checks, path protections and post-download integrity verification.
SHA

Always-on Localynk

Built for a quiet Proxmox LXC.

Run the Headless Server in an unprivileged Debian 13 LXC with systemd, Web Admin, health checks and scheduled SQLite backups. Mount large storage separately and keep the application container small.

localynk-server
root@localynk:~# ./proxmox/INSTALL-PROXMOX.sh
✓ dependencies verified
✓ localynk.service enabled
✓ backup timer enabled
✓ health check passed

root@localynk:~# localynk-ctl health
status: ok
protocol: 2
port: 8742

Release center

Choose your Localynk role.

RC14 · BuildFix9Production-audited source
Current qualification

BuildFix9 passed the source, API, security and packaging-definition audit. Platform installer buttons remain disabled until a real hosted package URL is configured—no fake downloads.

Loading release configuration…

Questions

Clear boundaries make better software.

The important parts of Localynk are intentionally explicit: where it runs, who gets access, and what “production ready” means for this RC.

Does Localynk send my files through a cloud relay?

No mandatory cloud relay is required for the normal Localynk transfer path. It is designed to move files directly across networks you control, such as your LAN or private VPN.

Can I use Localynk outside my home or office?

Yes, through a private VPN such as Tailscale. Automatic LAN discovery may not cross the VPN, so manually enter the Localynk server address.

Should I expose port 8742 to the Internet?

No. The built-in Localynk HTTP server is intended for trusted LAN, Tailscale or another private VPN. Do not directly port-forward TCP 8742 to the public Internet.

What does “production-audited source” mean?

The BuildFix9 source, security behavior, API and packaging definitions passed the current audit. Native installers still need to be compiled and qualified on their target operating systems before being published as final binaries.

What happens if I lose my authenticator?

Use a saved recovery code, or on a Headless/Proxmox server run localynk-ctl reset-2fa from the server console and enroll a new authenticator.

Localynk

Keep the transfer path yours.

Desktop. Android. Browser. Proxmox. One private-first file sharing system for the network you already own.

Explore releases