External copies may still exist

This warning is monotonic for the current page lifetime: clearing page memory, cancelling, changing workflows, or switching modes cannot prove that a browser-managed download or pending object URL was deleted.

Create Archive

Select files once, and Quantum Vault will encrypt them and export successor shards plus archive JSON.

📄 File
→
🔒 Encrypt
→
🧩 Split

Select files to protect

Drag files here or use the file picker to select plaintext inputs for local encryption. Lite accepts 1–256 files and at most 8 MiB aggregate per operation.

🛡️ Fresh keys are generated per archive
Default is threshold-only recovery. This acknowledgement resets after every create attempt and must be made separately for each archive. If authorized, export or explicitly discard the pending key before creating another archive or switching modes.
Requested 60% -> Achievable 80% (>=4/5 shards) Discrete by RS/SSS constraints.
Choose whether restore should require detached archive approval.
Technical context
Lite creates successor lifecycle archives by default and exports successor .qcont shards, a signable .archive-state.json, and a mutable .lifecycle-bundle.json. Without an external archive-approval signature over the archive-state descriptor, restore verifies integrity only and does not claim archive approval. Same-state resharing stays in Pro as an optional maintenance tool and does not replace archive approval while the archive state stays unchanged.

Verify required archive artifacts

Each Download or Retry click requests exactly one artifact. A row remains unverified until you re-import the exact bytes through the file picker. Re-import verification does not prove durable storage.

Until completion or cancellation, this page temporarily holds the operation key and a complete recovery set. Re-importing every shard exposes that recovery set to this browser session.

    Custody and archive exports

    Recovery depends on independent shard custody and exported JSON descriptors, not on keeping browser keys around.

    • Store QVqcont-7 shards across separate locations or custodians.
    • Retain the archive-state descriptor and lifecycle bundle JSON; Review, Pro Attach, and Restore depend on them.
    • Browser download requests are not storage confirmation. Lite completes only after every required planned artifact is exactly re-import verified; separately confirm durable, independent custody.
    • Archive approval happens outside the browser: sign archive-state bytes, then use Pro Attach for signatures and evidence.
    • Optional 1-of-1 Key Backup bypasses the shard threshold; skip it when custody policy forbids retaining a unilateral ML-KEM recovery key.

    Last create export checklist

    Every required artifact passed exact name, size, and SHA3-512 digest re-import verification. This is not durable-storage evidence; confirm independent custody separately.

      Restore

      The restore decision updates as you load shards and evidence; details and selection follow below.

      🧩 Shards
      →
      ✨ Combine
      →
      📄 File

      Select Shards to Restore

      Load successor .qcont shards and any detached signatures, signer keys, or timestamp proofs you want checked.

      0 shards selected
      Review loaded archive details

      Artifacts

      Lifecycle

      Evidence

      Detached signatures, signer pins, and OTS proofs are listed under Artifacts. Verification counts appear in Lite restore output after you run restore.

      Technical

      Technical context
      Load successor .qcont shards plus any optional .archive-state.json, .lifecycle-bundle.json, detached signatures, .pqpk signer pins, and .ots proofs in the main selector above. A supplied .pqpk file counts as a pinned PQ signer key. Restore remains policy-gated and releases recovered outputs only after the selected archive policy is satisfied.
      Signer pins (optional)