CipherVault

Zero-Knowledge

Decentralized Secret Backup & Disaster Recovery Inspector

VAULT Loading...
Probing Cluster...
SSE Stream: Connecting...
Cluster Durability
Unverified
--/3 Replicas
No completed recovery verification
Retention Runway
Immutable
90 Days Min
Automated Lease Self-Repair Active
Arbitrum Checkpoint
L2 Inclusion
#--
Sequencer Confirmed
Protected Secrets
Encrypted
-- Files
-- chunks encrypted

Independent Storage Operators

Three-way Byzantine replica topology with signed challenge-response authentication and immutable leases.

Avg Cluster Latency: -- ms

Live Geographic Quorum Topology (GCP Multi-Region)

3-Node Byzantine Fault Tolerant Cluster across Iowa and South Carolina (~1,000 miles physical isolation).

Quorum 3/3 Healthy (2-of-3 Required)
πŸ‡ΊπŸ‡Έ us-central1 (Iowa, USA)
cv-operator-1 us-central1-a
136.65.43.84
Ping: -- ms
cv-operator-2 us-central1-b
34.9.157.167
Ping: -- ms
~1,000 Miles Physical Isolation
πŸ‡ΊπŸ‡Έ us-east1 (South Carolina, USA)
cv-operator-3 us-east1-b
34.73.53.40
Ping: -- ms
Probing operator nodes...

Real-Time Operator Roundtrip Latency (RTT)

Snapshot DAG & History Timeline

Cryptographically chained snapshots signed by device keys with encrypted manifest Merkle CIDs.

Loading snapshot DAG...

Secret Revision Diff Engine

Format-aware semantic diffing with sensitive value masking and zero-disk plaintext security.

vs
0 + Added Keys
0 ~ Modified Keys
0 - Removed Keys
0 Files Changed

Select snapshot targets and click Calculate Diff to inspect confidential changes.

Protected Confidential Inventory

Tracked secret files chunked into 1 MiB blocks with PKCS#7 zero-leak padding and XChaCha20-Poly1305 AEAD.

Relative Path File ID (SHA-256) Plaintext Size Chunking & Padding Replication State Action
Loading tracked secrets...
Need to track more secrets? Add confidential files to vault tracking using the CLI:
ciphervault track <path/to/file>
Automated L2 Relayer: Active
Arbitrum One / Sepolia

Arbitrum One Checkpoint Verification

Opaque on-chain commitments anchoring snapshot heads without leaking secret plaintexts or tree structures.

commitment = SHA-256("CIPHERVAULT-ANCHOR-V1" || salt || head_record_cid)
Contract Address --
Target Chain Arbitrum One (Chain ID 42161)
Inclusion Block --
Finality Status SequencerConfirmed
Salt Preimage (Hex) --
Opaque Commitment --
Transaction Hash --

Live Cryptographic Proof Verifier

Verify client-side in WebCrypto that the local salt preimage and head record CID independently compute the exact 32-byte Arbitrum commitment without relying on external trust.

Arbitrum Relayed Checkpoints Ledger

Immutable ledger of L2 anchored heads with verified Arbiscan explorer links.

Block # Sequencer Tx Hash Finality Status Opaque Commitment Explorer
Loading checkpoint ledger...

Threshold Guardian Ceremony & Distributed Recovery

Shamir M-of-N threshold secret sharing over GF(2⁸). Master recovery secret is partitioned into isolated guardian shares with zero plaintext leakage.

3 / 5

Active Quorum Policy: 3-of-5 Guardians Required

Any 3 distinct guardian descriptor shares can mathematically reconstruct the recovery signing key. Fewer than 3 shares yield zero information about the secret.

Vault Locator: --
Loading threshold guardian sheets...

Zero-Knowledge In-Memory Share Recombination Simulator

Paste M or more printable guardian share blocks below to mathematically verify polynomial reconstruction against the registered recovery signing key. Reconstruction is computed in zeroized volatile RAM; the master recovery secret R is never displayed or stored.

Maintenance Fleet & Self-Repair Monitor

Autonomous heartbeat monitoring, operator latency tracking, and SQLite-backed self-repair audit history.

Tracked Vaults
1
Active in fleet registry
Active Operators
3 / 3
Replica quorum intact
Cluster Latency (Avg)
-- ms
Roundtrip probe time
Audits Completed
--
SQLite audit log entries

Operator Node Topology & Latency

Querying operator node health...

Fleet Vault Registrations

Locally tracked vaults synchronized with fleet maintenance database

Vault ID Head CID Storage Allowance Registered At
Loading registered vaults...

Autonomous Self-Repair Audit History

Historical verification and repair runs recorded in SQLite fleet.db

Timestamp Vault ID Status Healthy Objects Degraded Repaired Duration
Loading audit log...

Offline Disaster Recovery Kit

Print two physical copies for secure offline storage. Never commit or upload this document.

CRITICAL SECURITY INVARIANT: Store this document in TWO physically separate, secure locations. Loss of this secret means permanent, unrecoverable loss of your encrypted vault.
Master Recovery Secret R (Confidential)
β€’β€’β€’β€’ β€’β€’β€’β€’ β€’β€’β€’β€’ β€’β€’β€’β€’ β€’β€’β€’β€’ β€’β€’β€’β€’ β€’β€’β€’β€’ β€’β€’β€’β€’

Disaster Recovery Procedure on a Clean Machine:

  1. Install or copy the standalone ciphervault.exe binary to your clean machine.
  2. Execute the clean recovery command with your paper recovery secret:
ciphervault recover --kit recovery_kit.txt

FastCDC Content-Defined Chunking & Deduplication Inspector

Pure-Rust Gear-hash dual-mask normalized chunk boundary detection with Shannon entropy analysis and boundary-shift resilience.

Algorithm: FastCDC (Gear-64) Dual-Mask Normalized
Live Axum Server-Sent Events (SSE) Telemetry Stream
Awaiting telemetry packet...
Operator 1 -- ms
Operator 2 -- ms
Operator 3 -- ms
PIV Smartcard / Token Checking...
Inspect Active Vault Files:
0 bytes
Total Slices
--
-- unique
Deduplication Savings
--%
-- bytes pruned
Content Payload
-- KB
-- KB wire transfer
Boundary Shift Resilience
100% Normalized
Fixed-chunk failure: 0%
Fixed Chunks (16 KiB)
--
Rigid Block Baseline
Interactive Content-Defined Chunk Ribbon Low Entropy (<4.0) Medium Entropy (4.0-7.0) High Entropy (>7.0) Duplicate Chunk
Click any block to inspect chunk metadata
Click "Slice & Inspect Chunks" or select a preset to visualize Content-Defined boundaries.
❯_ CipherVault Live Terminal & Telemetry Console STREAM ACTIVE
0 events