π‘οΈAlaskaVaultβ’ Sovereign User Manual & Administrator Field Guide
Document Version: 2.0.0 (October 2026)
Classification: Official Product Documentation & Systems Administration Guide
Software Target: AlaskaVault Desktop & Server Editions (Windows 10/11, Windows Server 2022/2025, Linux)
Author: Alaska Systems Architecture & Field Deployment Engineering
Website: https://myalaska.me | White Papers
Β§Table of Contents
Β§Chapter 1: Welcome to AlaskaVault & Sovereign Architecture
1.1 The Sovereign Philosophy
AlaskaVault is an air-gapped, zero-cloud personal data fortress and decentralized storage hub designed for high-value intellectual property, classified deeds, cryptocurrency hardware seeds, and mission-critical enterprise secrets.
Unlike commercial password managers and cloud storage providers (such as Box, 1Password, or OneDrive), AlaskaVault is governed by four immutable architectural laws:
Β§Chapter 2: First-Run Setup & Genesis Initialization (State 1)
When AlaskaVault is launched on a fresh computer, it automatically detects that no master cryptographic token exists in local storage and greets you with State 1: First-Run Genesis Enclave.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β STATE 1: FIRST-RUN SETUP β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β 1. Enter Your Master Passphrase β
β β’ Live Entropy Meter (Weak -> Good -> Sovereign Strong) β
β β’ Optional: Click [π² Generate Diceware Passphrase] β
β 2. Confirm Master Passphrase β
β 3. Optional: Enable Windows Hello / Touch ID Biometrics β
β 4. Record 24-Word BIP-39 Emergency Recovery Seed β
β 5. Click [π‘οΈ Initialize & Encrypt My Sovereign Vault] β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β EVALUATOR BYPASS: [π Launch Demo Vault with Pre-loaded Sample Files] β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ2.1 Setting Your Master Passphrase
Sovereign Strong (Zero-Knowledge Grade).2.2 Instant Evaluation Mode (Demo)
If you are evaluating AlaskaVault for procurement or security testing, you do not need to create a permanent master key. Click π Launch Demo Vault with Pre-loaded Sample Files to immediately enter the unlocked vault loaded with 5 realistic sovereign test assets (Alaska Land Deed PDF, Cabin Solar CAD blueprint, Coldcard MK4 Seed, ProtonMail root credentials, and Winter Comms notes).
Β§Chapter 3: Daily Unlocking & The 6 Multi-Modal Channels (State 2)
Whenever the application closes, the auto-lock timer expires (default: 5 minutes), or you click Panic Lock, AlaskaVault locks immediately into State 2: Daily Operation.
To unlock, choose any of your 6 registered authentication channels:
Method 1: Master Passphrase
Enter your chosen master passphrase and click Decrypt Master Vault. The vault computes an Argon2id memory-hard verification against your stored cryptographic salt in under 400 milliseconds.
Method 2: Platform Biometrics (Windows Hello / Touch ID)
Click the Biometrics tab and select Authenticate with Windows Hello. The TPM 2.0 cryptoprocessor verifies your biometric token and releases the decryption key without exposing your passphrase.
Method 3: Physical USB Sentinel Keyfile
Insert your registered USB Sentinel flash drive containing AlaskaVault_Sentinel_Master.akkey. Click Authenticate Sentinel Hardware Key. The vault verifies the 512-bit cryptographic entropy anchor on the drive.
Method 4: BIP-39 24-Word Emergency Recovery
If you have forgotten your password, select 24-Word Seed. Enter your 24 words (or at least the first 12 words) to deterministically reconstruct your Master Encryption Key.
Method 5: Shamir 2-of-3 Threshold Shards
Select Shamir Shards. If family members, corporate executives, or legal counsel hold your 3 Shamir shards, enter any two of the three shards (AKSH-1, AKSH-2, or AKSH-3). AlaskaVault mathematically reconstructs the master key via Lagrange polynomial interpolation over \text{GF}(2^8).
Method 6: Air-Gapped TOTP 2FA
Select TOTP Authenticator. Enter the 6-digit dynamic code generated by your air-gapped hardware token (or enter an emergency one-time rescue code starting with AK-RESCUE-).
Β§Chapter 4: Managing Confidential Assets & Document Enclaves
Once unlocked, the Confidential Assets dashboard organizes your sovereign secrets across four distinct cryptographic categories:
credentials): PGP keyrings, SSH administrative identities, and zero-knowledge web passwords.crypto_seeds): Hardware cold-storage seed phrases (Coldcard, Trezor, Ledger).classified_docs): Notarized real estate deeds, title insurance policies, and CAD/DWG blueprints.secret_notes): Unencrypted field notes encrypted with per-document ephemeral keys.4.1 Viewing Documents in the Secure Lightbox Viewer
Clicking Inspect Document on any classified deed or CAD blueprint launches the DataViewer Lightbox Modal:
b3:78a9c1e0...);4.2 Adding a Custom Secret
Click Add Secret at the top right:
Logins & Keys, BIP-39 Seeds, Classified Deeds, or Secret Notes).Executive PGP Private Key).Β§Chapter 5: Passphrase Studio & Zero-Trace Clipboard Auto-Purge
Click the Passphrase Studio & Diceware tab to generate cryptographically uncrackable passwords.
5.1 Diceware Configuration
-), underscores (_), dots (.), or spaces ( ).5.2 Zero-Trace Clipboard Auto-Purge
When you click Copy Secret on any asset or generated passphrase:
Β§Chapter 6: Anti-Lockout Matrix & Physical Cold-Storage Contingency
Click the Anti-Lockout Matrix tab to inspect and manage your 6 recovery channels.
6.1 Printing Cold-Storage Recovery Sheets
Click Print Cold Storage Sheet to open the standardized, printable disaster recovery template:
6.2 Exporting Shamir 2-of-3 Shards
Click Download Shamir Shards to export your 3 threshold shards. Store Shard 1 at your primary residence, Shard 2 in a secure safety deposit box, and Shard 3 with your legal attorney. Any two shards restore your entire vault without needing the master passphrase.
Β§Chapter 7: Duress Protocols & Plausible Deniability Decoy Vault
AlaskaVault is engineered for extreme physical security scenarios, including international travel through hostile jurisdictions, physical coercion, or unwarranted searches.
7.1 Operating Under Duress
If forced to unlock your vault under physical threat:
duress2026 (or decoy);\text{MEK}) remains zeroized and unreferenced in physical RAM;Β§Chapter 8: Sovereign Storage, RAID Swarm & Bit-Rot Scrubbing
AlaskaVault is not merely a password managerβit is a full-featured decentralized personal cloud.
8.1 Write-Once-Read-Many (WORM) Storage
Documents committed to AlaskaVault can be designated as WORM-compliant. Once written, the underlying file-system locks modifications, creating an immutable audit trail compliant with FINRA 17a-4 and SEC regulations.
8.2 RAID Swarm & Automatic Bit-Rot Scrubbing
When configuring multi-drive storage pools:
Β§Chapter 9: Air-Gapped Hybrid Neural Search & Candle Vector Indexing
Searching confidential documents normally requires sending sensitive text to cloud AI APIs (like OpenAI or Google Cloud). AlaskaVault completely eliminates this risk:
Β§Chapter 10: Troubleshooting, Factory Reset & Emergency Disaster Recovery
10.1 What to Do If You Forget Your Password
If you cannot remember your master passphrase, do not panic. Use any of the other five anti-lockout channels:
10.2 Performing a Factory Reset
If you are transferring your workstation, decommissioning a corporate laptop, or wish to start fresh:
Β§Appendix: Command-Line Interface (CLI) Quick Reference
For headless server installations and automated scripting, the alaskavault Pure-Rust binary supports direct terminal commands:
| Command | Action | Security Context |
|---|---|---|
alaskavault init |
Launches interactive terminal setup for State 1 | Zero-Knowledge Local |
alaskavault unlock --passphrase |
Decrypts vault and mounts local FUSE drive | Ephemeral RAM Lock |
alaskavault lock |
Wipes active keys and panic-locks vault | Volatile Zeroization |
alaskavault shred |
Executes NIST SP 800-88 Cryptographic Erasure | Irreversible Purge |
alaskavault export-shamir |
Generates 2-of-3 threshold recovery shards | \text{GF}(2^8) Galois Field |
alaskavault verify-integrity |
Performs full BLAKE3 bit-rot disk sweep | Parity Reconstruction |
Β© 2026 Alaska Systems Applied Cryptography & Systems Architecture Group. Published under the Open Systems Sovereign License (OSSL 1.0).