Universal Vault Logo🔒
Universal Vault
BINARY PROTOCOL SPECIFICATION — VAULTV05

Cryptographic Architecture & Container Format.

Universal Vault implements the open VAULTV05 binary specification. Built with bit-level deterministic alignment, it guarantees complete, bug-free interoperability between native C/Go binaries, Android Kotlin engines, and web browsers.

✨ HOW THE CIPHER WORKS

Three Simple Steps. Zero Compromises.

Universal Vault replaces complex corporate encryption setups with a lean, bit-perfect streaming engine.

164-Byte Header

Cryptographic Key Setup

A unique 32-byte cryptographic salt is combined with your passphrase through 600,000 PBKDF2-HMAC-SHA256 iterations to forge an unguessable 256-bit key.

Magic: "VAULTV05"Random Salt
2In-Place Stream

Zero-Bloat Transmutation

Bytes are encrypted directly on disk in 64 KB chunks via AES-256-CTR. Hardware POSIX barriers sync data every 1 MB to prevent corrupted files if power is lost.

0 KB Temp FilesPOSIX fsync sync
3104-Byte Footer

Tamper-Proof Seal

The process appends an atomic resumption checkpoint and an HMAC-SHA256 signature tag. If even 1 bit is altered or tampered with, Universal Vault detects it instantly.

HMAC-SHA256 TagInstant Checkpoint
🔬Developer Deep Dive: Inspect Raw Bit-Level Hex Offsets↓
Select Chunk:
● Bit-Aligned VAULTV05 Spec
00000000: 5641 554c 5456 3035  9a2b c481 0e55 f102  |VAULTV05.+...U..|
00000010: 7c88 d31a 4b90 ee11  ff7a 3209 bb84 a1c0  ||...K....z2.....|  (32B PBKDF2 Salt)
00000020: 0009 27c0 0100 0000  0000 0000 0000 0000  |..'.............|  (600,000 Iterations BE)
00000030: 2f7a 8812 00bc d4ea  90ff c144 0000 0000  |/z.........D....|  (AES-256 CTR IV)
        
BYTE SPECIFICATION

Container Memory Layout

A VAULTV05 container wraps encrypted payload blocks between an initialized 64-byte header and an atomic 104-byte trailing seal.

1. Cryptographic Header (Offset 0x0000 — 64 Bytes)

Fixed Size: 64B
OffsetLengthField NameCryptographic Function
0x0000 - 0x00078 BytesMagic SignatureASCII literal 'VAULTV05' identifying the valid container format
0x0008 - 0x00092 BytesFormat VersionBig-endian uint16 indicating format revision (current: 0x0005)
0x000A - 0x000D4 BytesPBKDF2 IterationsBig-endian uint32 iteration count (default: 600,000 rounds)
0x000E - 0x002D32 BytesCryptographic SaltCSPRNG cryptographic salt for HMAC-SHA256 key derivation
0x002E - 0x003D16 BytesAES-CTR Nonce/IV128-bit initialization vector counter base
0x003E - 0x003F2 BytesHeader FlagsReserved bitmask for compression, in-place mode, and integrity flags

2. In-Place Stream Engine (Offset 0x0040 to EOF - 104)

Payload encryption utilizes AES-256 in Counter (CTR) Mode. CTR turns a block cipher into a deterministic stream cipher, enabling byte-for-byte in-place mutation without padding overhead or ciphertext expansion.

Block Unit
1,048,576 Bytes (1 MB)

Chunk sized to align with modern NVMe page clusters and L3 CPU cache lines.

Hardware Barrier
POSIX fsync / FlushFileBuffers

Direct kernel system call committing dirty pages to non-volatile NAND silicon.

CTR Counter Base
Offset / 16 (Big-Endian)

Counter calculates exactly from byte offset, enabling arbitrary seek and resume.

3. Checkpoint & Integrity Footer (EOF - 104 Bytes)

Fixed Size: 104B
Relative OffsetLengthField NameCryptographic Function
0x00 - 0x078 BytesCheckpoint OffsetBig-endian uint64 recording last atomic 1 MB fsync sector boundary
0x08 - 0x2732 BytesPayload HMAC-SHA256Cryptographic MAC over the entire encrypted ciphertext payload
0x28 - 0x4732 BytesHeader HMAC-SHA256Authentication tag protecting the 64-byte header from bit-flip tampering
0x48 - 0x5F24 BytesRecovery MetadataOriginal file size, Unix timestamp epoch, and file attribute mask
0x60 - 0x678 BytesTrailing Magic SealASCII literal 'VAULTEND' validating complete container closure
AUDITABILITY & TRANSPARENCY

Inspect Containers with Standard Tooling

No proprietary black boxes. Because the format is openly specified, you can inspect any encrypted file using native command-line utilities like xxd, hexdump, or the built-in vault inspect command.

Try it in your shell:
vault inspect confidential_backup.pdf.vault
xxd -g 1 -l 64 secret.pdf.vault0x0000-0x0040
00000000: 56 41 55 4c 54 56 30 35  00 05 00 09 27 c0 4f a9  |VAULTV05....'.O.|
00000010: 12 8b d3 44 91 e2 a7 b0  bc 5e 31 d0 88 1a 9f 02  |...D.....^1.....|
00000020: e5 73 b9 64 a0 4d 71 c8  3b 11 fa 90 e1 34 db 88  |.s.d.Mq.;....4..|
00000030: a7 88 19 b2 c4 e0 f5 01  8e 3d 0b 72 00 00 00 00  |.........=.r....|
Magic: VAULTV05Rounds: 600,000 (0x000927c0)Salt: 32B CSRNG
UV

Sponsor Universal Vault or Feature Your Developer Tool

Reach security researchers, DevOps engineers, and privacy-conscious developers worldwide.

READY IN SECONDS • ZERO SETUP

Your Files Belong to You.
Keep Them That Way.

Zero setup. Zero accounts. Zero telemetry. Download the binary, run a single command, and lock your files with mathematical certainty.