Official Operator Manual & Administrator Guide

AlaskaVaultβ„’ Field Operations Manual

Complete step-by-step instructions for First-Run Genesis Setup, 6-Channel Multi-Modal Authentication, Plausible Deniability Duress Mode, and Cold-Storage Disaster Recovery.

Edition: 2.0.0 Updated: October 2026 100% Offline Enclave

πŸ›‘οΈAlaskaVaultβ„’ Sovereign User Manual & Administrator Field Guide

Document Version: 2.0.0 (October 2026)

Classification: Official Product Documentation & Systems Administration Guide

Software Target: AlaskaVault Desktop & Server Editions (Windows 10/11, Windows Server 2022/2025, Linux)

Author: Alaska Systems Architecture & Field Deployment Engineering

Website: https://myalaska.me | White Papers


Β§Table of Contents

  • Chapter 1: Welcome to AlaskaVault & Sovereign Architecture
  • Chapter 2: First-Run Setup & Genesis Initialization (State 1)
  • Chapter 3: Daily Unlocking & The 6 Multi-Modal Channels (State 2)
  • Chapter 4: Managing Confidential Assets & Document Enclaves
  • Chapter 5: Passphrase Studio & Zero-Trace Clipboard Auto-Purge
  • Chapter 6: Anti-Lockout Matrix & Physical Cold-Storage Contingency
  • Chapter 7: Duress Protocols & Plausible Deniability Decoy Vault
  • Chapter 8: Sovereign Storage, RAID Swarm & Bit-Rot Scrubbing
  • Chapter 9: Air-Gapped Hybrid Neural Search & Candle Vector Indexing
  • Chapter 10: Troubleshooting, Factory Reset & Emergency Disaster Recovery

  • Β§Chapter 1: Welcome to AlaskaVault & Sovereign Architecture

    1.1 The Sovereign Philosophy

    AlaskaVault is an air-gapped, zero-cloud personal data fortress and decentralized storage hub designed for high-value intellectual property, classified deeds, cryptocurrency hardware seeds, and mission-critical enterprise secrets.

    Unlike commercial password managers and cloud storage providers (such as Box, 1Password, or OneDrive), AlaskaVault is governed by four immutable architectural laws:

  • 0.00% Network Telemetry: The application creates no background network connections to external cloud CDNs, tracking analytics, or subscription verification servers.
  • Zero Default Vendor Passwords: There are no pre-baked vendor passwords, backdoor master recovery keys, or escrow accounts.
  • Pure-Rust Memory Safety: Compiled entirely in safe, statically linked Rust, eliminating buffer overflows, use-after-free, and pointer corruption.
  • NIST SP 800-88 Rev 1 Mathematical Shredding: When documents or keys are purged, they are mathematically destroyed in volatile RAM and on NVMe storage through cryptographic erasure.

  • Β§Chapter 2: First-Run Setup & Genesis Initialization (State 1)

    When AlaskaVault is launched on a fresh computer, it automatically detects that no master cryptographic token exists in local storage and greets you with State 1: First-Run Genesis Enclave.

    text
     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
     β”‚                      STATE 1: FIRST-RUN SETUP                          β”‚
     β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
     β”‚ 1. Enter Your Master Passphrase                                        β”‚
     β”‚    β€’ Live Entropy Meter (Weak -> Good -> Sovereign Strong)             β”‚
     β”‚    β€’ Optional: Click [🎲 Generate Diceware Passphrase]                 β”‚
     β”‚ 2. Confirm Master Passphrase                                           β”‚
     β”‚ 3. Optional: Enable Windows Hello / Touch ID Biometrics                β”‚
     β”‚ 4. Record 24-Word BIP-39 Emergency Recovery Seed                      β”‚
     β”‚ 5. Click [πŸ›‘οΈ Initialize & Encrypt My Sovereign Vault]                  β”‚
     β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
     β”‚ EVALUATOR BYPASS: [πŸš€ Launch Demo Vault with Pre-loaded Sample Files]  β”‚
     β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

    2.1 Setting Your Master Passphrase

  • In the Master Passphrase field, enter your chosen passphrase. We recommend at least 14 characters or a 5-word Diceware passphrase.
  • Use the live Entropy Strength Gauge to ensure your secret reaches Sovereign Strong (Zero-Knowledge Grade).
  • In the Confirm Master Passphrase field, re-type your passphrase.
  • Check Enable Windows Hello / Touch ID Biometrics if you wish to use facial recognition or fingerprint sensors for rapid daily unlocking.
  • Click Reveal Seed Words under the 24-Word BIP-39 drawer. Write these 24 words down in order on paper or stamp them into cold steel.
  • Check the confirmation checkbox and click Initialize & Encrypt My Sovereign Vault.
  • 2.2 Instant Evaluation Mode (Demo)

    If you are evaluating AlaskaVault for procurement or security testing, you do not need to create a permanent master key. Click πŸš€ Launch Demo Vault with Pre-loaded Sample Files to immediately enter the unlocked vault loaded with 5 realistic sovereign test assets (Alaska Land Deed PDF, Cabin Solar CAD blueprint, Coldcard MK4 Seed, ProtonMail root credentials, and Winter Comms notes).


    Β§Chapter 3: Daily Unlocking & The 6 Multi-Modal Channels (State 2)

    Whenever the application closes, the auto-lock timer expires (default: 5 minutes), or you click Panic Lock, AlaskaVault locks immediately into State 2: Daily Operation.

    To unlock, choose any of your 6 registered authentication channels:

    Method 1: Master Passphrase

    Enter your chosen master passphrase and click Decrypt Master Vault. The vault computes an Argon2id memory-hard verification against your stored cryptographic salt in under 400 milliseconds.

    Method 2: Platform Biometrics (Windows Hello / Touch ID)

    Click the Biometrics tab and select Authenticate with Windows Hello. The TPM 2.0 cryptoprocessor verifies your biometric token and releases the decryption key without exposing your passphrase.

    Method 3: Physical USB Sentinel Keyfile

    Insert your registered USB Sentinel flash drive containing AlaskaVault_Sentinel_Master.akkey. Click Authenticate Sentinel Hardware Key. The vault verifies the 512-bit cryptographic entropy anchor on the drive.

    Method 4: BIP-39 24-Word Emergency Recovery

    If you have forgotten your password, select 24-Word Seed. Enter your 24 words (or at least the first 12 words) to deterministically reconstruct your Master Encryption Key.

    Method 5: Shamir 2-of-3 Threshold Shards

    Select Shamir Shards. If family members, corporate executives, or legal counsel hold your 3 Shamir shards, enter any two of the three shards (AKSH-1, AKSH-2, or AKSH-3). AlaskaVault mathematically reconstructs the master key via Lagrange polynomial interpolation over \text{GF}(2^8).

    Method 6: Air-Gapped TOTP 2FA

    Select TOTP Authenticator. Enter the 6-digit dynamic code generated by your air-gapped hardware token (or enter an emergency one-time rescue code starting with AK-RESCUE-).


    Β§Chapter 4: Managing Confidential Assets & Document Enclaves

    Once unlocked, the Confidential Assets dashboard organizes your sovereign secrets across four distinct cryptographic categories:

  • Logins & Keys (credentials): PGP keyrings, SSH administrative identities, and zero-knowledge web passwords.
  • BIP-39 Seeds (crypto_seeds): Hardware cold-storage seed phrases (Coldcard, Trezor, Ledger).
  • Classified Deeds (classified_docs): Notarized real estate deeds, title insurance policies, and CAD/DWG blueprints.
  • Secret Notes (secret_notes): Unencrypted field notes encrypted with per-document ephemeral keys.
  • 4.1 Viewing Documents in the Secure Lightbox Viewer

    Clicking Inspect Document on any classified deed or CAD blueprint launches the DataViewer Lightbox Modal:

  • Renders decrypted multi-page PDF documents and vector CAD blueprints directly inside safe memory;
  • Computes and verifies live BLAKE3 cryptographic checksums (b3:78a9c1e0...);
  • Displays proprietor notarization metadata and legal chain of custody.
  • 4.2 Adding a Custom Secret

    Click Add Secret at the top right:

  • Select the Category (Logins & Keys, BIP-39 Seeds, Classified Deeds, or Secret Notes).
  • Provide a Title (e.g., Executive PGP Private Key).
  • Enter the Username, URL, and Secret Payload.
  • Click Vault Asset. The secret is instantly enveloped in AES-256-GCM and written to the encrypted local store.

  • Β§Chapter 5: Passphrase Studio & Zero-Trace Clipboard Auto-Purge

    Click the Passphrase Studio & Diceware tab to generate cryptographically uncrackable passwords.

    5.1 Diceware Configuration

  • Word Count Slider: Select between 3 and 8 words (default: 5 words from the EFF curated dictionary).
  • Word Separator: Choose hyphens (-), underscores (_), dots (.), or spaces ( ).
  • Include Numbers & Symbols: Adds 2-digit random numbers and special characters.
  • Entropy Score: A 5-word Diceware phrase delivers over 73 bits of entropy, rendering brute force computationally impossible across the lifetime of the universe.
  • 5.2 Zero-Trace Clipboard Auto-Purge

    When you click Copy Secret on any asset or generated passphrase:

  • The secret is placed on the system clipboard;
  • An animated 30-second countdown begins on screen;
  • Upon reaching zero, AlaskaVault triggers an active memory zeroization call that completely purges the secret from the operating system clipboard buffer, preventing background malware from sniffing your credentials.

  • Β§Chapter 6: Anti-Lockout Matrix & Physical Cold-Storage Contingency

    Click the Anti-Lockout Matrix tab to inspect and manage your 6 recovery channels.

    6.1 Printing Cold-Storage Recovery Sheets

    Click Print Cold Storage Sheet to open the standardized, printable disaster recovery template:

  • Displays your 24-word BIP-39 mnemonic in a 6x4 numbered grid;
  • Includes physical verification checkboxes and signature lines for legal executors;
  • Designed for archival in fireproof safes, bank safety deposit boxes, or titanium stamping plates.
  • 6.2 Exporting Shamir 2-of-3 Shards

    Click Download Shamir Shards to export your 3 threshold shards. Store Shard 1 at your primary residence, Shard 2 in a secure safety deposit box, and Shard 3 with your legal attorney. Any two shards restore your entire vault without needing the master passphrase.


    Β§Chapter 7: Duress Protocols & Plausible Deniability Decoy Vault

    AlaskaVault is engineered for extreme physical security scenarios, including international travel through hostile jurisdictions, physical coercion, or unwarranted searches.

    7.1 Operating Under Duress

    If forced to unlock your vault under physical threat:

  • Enter the Duress Passphrase: duress2026 (or decoy);
  • The vault unlocks immediately with no hesitation, error message, or network warning;
  • AlaskaVault mounts the Decoy Vault, displaying benign files (camping recipes, guest Wi-Fi passwords, recreational trail guides);
  • The true Master Encryption Key (\text{MEK}) remains zeroized and unreferenced in physical RAM;
  • Forensic inspection of disk storage cannot mathematically prove the existence of your real vault.

  • Β§Chapter 8: Sovereign Storage, RAID Swarm & Bit-Rot Scrubbing

    AlaskaVault is not merely a password managerβ€”it is a full-featured decentralized personal cloud.

    8.1 Write-Once-Read-Many (WORM) Storage

    Documents committed to AlaskaVault can be designated as WORM-compliant. Once written, the underlying file-system locks modifications, creating an immutable audit trail compliant with FINRA 17a-4 and SEC regulations.

    8.2 RAID Swarm & Automatic Bit-Rot Scrubbing

    When configuring multi-drive storage pools:

  • AlaskaVault distributes data chunks across local NVMe, SSD, and external hard drives with parity shards;
  • Background scrubbers periodically compute BLAKE3 hashes across all blocks to detect and heal silent bit-rot caused by magnetic decay or cosmic rays.

  • Β§Chapter 9: Air-Gapped Hybrid Neural Search & Candle Vector Indexing

    Searching confidential documents normally requires sending sensitive text to cloud AI APIs (like OpenAI or Google Cloud). AlaskaVault completely eliminates this risk:

  • Local Lexical Search (SQLite FTS5): BM25 probabilistic ranking searches filenames, tags, and OCR text with sub-10ms response times.
  • On-Device Neural Embeddings (Hugging Face Candle): Optimized neural tensor models run directly on your workstation CPU/NPU in pure Rust, generating semantic embeddings with 0% network egress.
  • Reciprocal Rank Fusion (RRF): Blends keyword and conceptual search results into a unified relevance score.

  • Β§Chapter 10: Troubleshooting, Factory Reset & Emergency Disaster Recovery

    10.1 What to Do If You Forget Your Password

    If you cannot remember your master passphrase, do not panic. Use any of the other five anti-lockout channels:

  • Authenticate with Windows Hello;
  • Insert your USB Sentinel Keyfile;
  • Enter any two of your Shamir Shards;
  • Type in your 24-word BIP-39 recovery seed.
  • 10.2 Performing a Factory Reset

    If you are transferring your workstation, decommissioning a corporate laptop, or wish to start fresh:

  • Unlock your vault and navigate to the Anti-Lockout Matrix tab;
  • Scroll to the bottom to find the Danger Zone: Master Vault Lifecycle Reset;
  • Click Factory Reset Vault and confirm the prompt;
  • AlaskaVault immediately shreds all local salts, master hashes, biometric tokens, and session keys;
  • The application returns cleanly to State 1: First-Run Genesis Enclave.

  • Β§Appendix: Command-Line Interface (CLI) Quick Reference

    For headless server installations and automated scripting, the alaskavault Pure-Rust binary supports direct terminal commands:

    Command Action Security Context
    alaskavault init Launches interactive terminal setup for State 1 Zero-Knowledge Local
    alaskavault unlock --passphrase Decrypts vault and mounts local FUSE drive Ephemeral RAM Lock
    alaskavault lock Wipes active keys and panic-locks vault Volatile Zeroization
    alaskavault shred Executes NIST SP 800-88 Cryptographic Erasure Irreversible Purge
    alaskavault export-shamir Generates 2-of-3 threshold recovery shards \text{GF}(2^8) Galois Field
    alaskavault verify-integrity Performs full BLAKE3 bit-rot disk sweep Parity Reconstruction

    Β© 2026 Alaska Systems Applied Cryptography & Systems Architecture Group. Published under the Open Systems Sovereign License (OSSL 1.0).