-
Notifications
You must be signed in to change notification settings - Fork 0
Encrypted Vaults
Zero-Knowledge, RAM-Only Authenticated Encryption (AES-256-GCM & Argon2id)
Brum Transparent Encrypted Vaults (.cdvault / .cdv) provide self-contained, password-protected virtual filesystem containers. Vaults decrypt files on-the-fly entirely in volatile system RAM without ever writing unencrypted temporary files or plaintext data to the physical disk.
- Core Security Architecture
- Creating an Encrypted Vault
- Unlocking & Accessing a Vault
- In-Vault Operations & Transparent Editing
- Auto-Lock Timers & Memory Purging
- Portable Cloud & Backup Workflows
- REST API Reference
graph TD
UserPass["User Master Passphrase"] -->|Argon2id (16-byte Salt)| UserKey["256-bit Derived Key"]
UserKey -->|AES-256-GCM Decrypt| MasterKey["256-bit Vault Master Key (In RAM Only)"]
MasterKey -->|AES-256-GCM Decrypt Blocks| Plaintext["RAM-Only Decrypted Files (Zero Disk Leakage)"]
MasterKey -->|AES-256-GCM Encrypt Blocks| EncryptedContainer["Single-File .cdvault Container on Disk"]
- Authenticated Symmetric Cipher: AES-256-GCM (Galois/Counter Mode) with a unique 96-bit random IV (nonce) and 128-bit authentication tag per data block.
- Key Derivation Function (KDF): Argon2id (memory-hard, resistant to GPU/ASIC brute-force and side-channel timing attacks) with a cryptographically secure 16-byte random salt.
-
Two-Tier Key Hierarchy:
- Each vault container contains an independent 256-bit random Master Key.
- The Master Key is encrypted using the user's derived Argon2id key.
- When modifying passwords or re-wrapping keys, data blocks do not need full re-encryption.
-
Zero Disk Artifacts:
- Files read or edited inside a vault are decrypted directly in memory buffers.
- No temporary files, unencrypted swap artifacts, or cleartext remnants are written to the host filesystem.
You can create an encrypted vault anywhere in Brum (local storage, external drives, or remote mounts):
- Navigate to the desired parent folder in any directory pane.
- Right-click on empty space (or tap the Actions button on mobile).
- Select Create Encrypted Vault (.cdvault)....
- In the modal:
- Enter the destination file path (e.g.
/home/bolt/Documents/Confidential_2026.cdvault). - Enter and confirm your master passphrase.
- Enter the destination file path (e.g.
- Click Create Encrypted Vault.
- Press Ctrl+K anywhere in Brum.
- Type
vaultorcreate vault. - Press Enter to open the creation dialog.
Unlocked vaults are mounted seamlessly as a virtual filesystem under the vault:// protocol scheme.
- Locate any
.cdvault,.cdv, or.vaultfile in the file browser (marked with the ambershield-checkbadge). - Double-click or press Enter on the vault container.
- In the Unlock Encrypted Vault dialog:
- Enter the vault's master password.
- Select an Auto-Lock Inactivity Timer:
5 Minutes Inactivity-
15 Minutes Inactivity(Default & Recommended) 30 Minutes Inactivity1 Hour Inactivity4 Hours InactivityUntil Session Ends / Manual Lock
- Click Unlock Vault (or press Enter).
- Brum derives the key using Argon2id, verifies the authentication tag, and navigates immediately into
vault:///path/to/my_vault.cdvault#.
Inside the vault, you have full access to Brum's suite of power tools:
-
Navigating Subfolders: Browse virtual directories transparently (e.g.
vault:///path/to/my.cdvault#finance/taxes/). - Live In-Memory Editing: Open text files, Markdown, JSON, YAML, code, and config files with the built-in Editor. When pressing Ctrl+S, changes are encrypted in RAM with AES-256-GCM and written back atomically.
- Creating Folders & Files: Use F7 to create virtual folders or right-click to create new documents inside the encrypted container.
- Uploading Files: Drag & drop files from your desktop or use the Upload button to encrypt external files directly into the vault.
- Downloading & Streaming: Download decrypted files or stream media directly through the browser without saving temporary copies on the server.
-
Deleting: Remove files or folders inside the vault with F8 or right-click
$\rightarrow$ Delete.
Brum implements strict memory hygiene for open vault sessions:
-
Inactivity Auto-Lock:
- Every access (read, write, list) updates the session's
last_accessedtimestamp. - If no requests occur within the configured duration (e.g. 15 minutes), the vault locks automatically and purges the 256-bit Master Key from RAM.
- Every access (read, write, list) updates the session's
-
1-Click Breadcrumb Lock:
- While browsing inside a vault, a red [ Lock ] button appears in the breadcrumb bar next to the vault name.
- Clicking [ Lock ] purges the Master Key immediately and returns the pane to the parent directory.
-
Session Lock Integration:
- Locking your overall Brum session (Ctrl+Alt+L) immediately invalidates all active vault keys in memory.
Because Brum vaults are self-contained container files (.cdvault), they are 100% portable:
-
USB & External Drives: Copy your
.cdvaultcontainer to any FAT32/exFAT/NTFS/ext4 drive. -
Cloud Storage & Offsite Backup: Upload
.cdvaultcontainers to AWS S3, Cloudflare R2, MinIO, SFTP, SMB, or Proton Drive without revealing folder names or file contents to third-party cloud providers. - Bit-for-Bit Verification: Use Brum's built-in SHA-256 hash calculator (Shift+F7) to verify container integrity before and after transfers.
For custom automation, CI/CD scripts, or headless integrations:
POST /api/vault/create
Content-Type: application/json
Authorization: Bearer <TOKEN>
{
"path": "/home/bolt/Documents/Secrets.cdvault",
"password": "MyStrongMasterPassphrase123!"
}POST /api/vault/unlock
Content-Type: application/json
Authorization: Bearer <TOKEN>
{
"path": "/home/bolt/Documents/Secrets.cdvault",
"password": "MyStrongMasterPassphrase123!",
"auto_lock_secs": 900
}GET /api/vault/status?path=/home/bolt/Documents/Secrets.cdvault
Authorization: Bearer <TOKEN>
Response:
{
"unlocked": true,
"path": "/home/bolt/Documents/Secrets.cdvault"
}POST /api/vault/lock
Content-Type: application/json
Authorization: Bearer <TOKEN>
{
"path": "/home/bolt/Documents/Secrets.cdvault"
}-
List contents:
GET /api/fs/list?path=vault:///home/bolt/Documents/Secrets.cdvault#finance -
Read file:
GET /api/fs/read?path=vault:///home/bolt/Documents/Secrets.cdvault#passwords.txt -
Write file:
POST /api/fs/writewith{ "path": "vault:///home/bolt/Documents/Secrets.cdvault#passwords.txt", "content": "..." } -
Download file:
GET /api/fs/download?path=vault:///home/bolt/Documents/Secrets.cdvault#tax_return.pdf -
Delete file:
POST /api/fs/deletewith{ "paths": ["vault:///home/bolt/Documents/Secrets.cdvault#old.txt"] }
Brum — Multi-Pane Web Environment (File Commander/Manager)
Creator & Lab: Bolt J Woofson @ Woofsons Lab (www.arf.ac) • MIT License