Universal Vault Logo🔒
Universal Vault
OFFICIAL COMMAND MANUAL — v5.5.2

Command-Line Interface Manual.

Universal Vault is built for speed and scriptability. Master the command-line flags, batch automation workflows, and exit codes for seamless integration into server pipelines.

Quick Start in 30 Seconds

1Install Binary

Download and extract the static binary for your architecture.

curl -fsSL https://git.io/uvault | bash
2Lock a File

Encrypts instantly in-place without generating temporary files.

vault lock secret.pdf
3Unlock Anywhere

Restore plaintexts on Windows, Linux, macOS, or Android.

vault unlock secret.pdf.vault
CORE SUBCOMMANDS

Command Reference

Detailed options, argument signatures, and real-world examples for each CLI subcommand.

vault lock

Encrypts files or directories in-place using AES-256-CTR and writes the authenticated 64-byte header and 104-byte recovery footer.

vault lock [OPTIONS] <TARGET_PATH>
Options & Flags:
-p, --password <string>Provide encryption password directly. If omitted, prompts with hidden terminal masking.
-r, --rounds <uint32>PBKDF2 iteration count (default: 600000). Range: 100,000 to 2,000,000.
-w, --wipe-originalPerforms DoD 5220.22-M 3-pass zeroing wipe of original plaintext blocks.
-v, --verbosePrints streaming progress, throughput in MB/s, and chunk fsync milestones.
Example Usage:
$ vault lock ./confidential_data.tar.gz --rounds 600000

vault unlock

Decrypts a VAULTV05 file, validating HMAC-SHA256 authentication tags and handling crash checkpoints.

vault unlock [OPTIONS] <VAULT_FILE>
Options & Flags:
-p, --password <string>Passphrase for key derivation. Verified via header HMAC before payload write.
-r, --resumeResumes partial decryption from last verified 1 MB fsync checkpoint.
-o, --out <path>Specify an explicit destination path instead of restoring to original filename.
Example Usage:
$ vault unlock ./confidential_data.tar.gz.vault --resume

vault verify

Performs complete cryptographic integrity audit by calculating HMAC-SHA256 across all blocks without writing plaintext to disk.

vault verify [OPTIONS] <VAULT_FILE>
Options & Flags:
-p, --password <string>Key derivation password required to verify authenticated ciphertext MAC.
-q, --quietSuppresses output; exits with code 0 if authentic, non-zero if tampered.
Example Usage:
$ vault verify ./backup_2026.iso.vault

vault inspect

Parses and prints the 64-byte binary header, format revision, salt, and iteration counter without requiring password.

vault inspect <VAULT_FILE>
Options & Flags:
--jsonOutputs parsed header fields as machine-readable JSON.
Example Usage:
$ vault inspect ./legal_contract.pdf.vault --json

vault bench

Executes hardware-calibrated benchmark testing AES-CTR throughput and PBKDF2 hash speed on host CPU.

vault bench
Options & Flags:
--size <MB>Test payload buffer size in megabytes (default: 512 MB).
Example Usage:
$ vault bench --size 1024
AUTOMATION & CI/CD

Batch Processing & Server Scripts

Automate routine backup encryption across thousands of files with native shell scripts.

Linux Batch Encryption (bash)backup_vault.sh
#!/usr/bin/env bash
set -euo pipefail

# Lock all database dumps recursively
find /var/backups -type f -name "*.sql" | while read -r file; do
  echo "Encrypting: $file"
  vault lock "$file" --password "$VAULT_SECRET" --rounds 600000
done

Processes files sequentially with atomic 1 MB fsync write barriers.

Windows PowerShell PipelineLock-Backups.ps1
# Encrypt all log archives in C:\Exports
Get-ChildItem -Path "C:\Exports" -Filter *.zip | ForEach-Object {
    Write-Host "Locking: $($_.FullName)" -ForegroundColor Cyan
    vault lock $_.FullName -p $env:VAULT_KEY
    if ($LASTEXITCODE -ne 0) {
        throw "Encryption failed on $($_.Name)"
    }
}

Checks process exit codes for zero-error pipeline execution.

Process Exit Codes

Deterministic status codes for shell condition checking and monitoring alerts.

CodeNameDescription
0SUCCESSOperation completed successfully; all write barriers flushed.
1AUTH_FAILUREInvalid password supplied or HMAC-SHA256 authentication tag mismatch.
2IO_ERRORFile permission denied, sector read failure, or read-only filesystem.
3CORRUPT_HEADERFile does not begin with valid VAULTV05 magic signature.
4INTERRUPTEDProcess aborted (SIGINT/SIGTERM); checkpoint logged to footer.
UV

Sponsor Universal Vault or Feature Your Developer Tool

Reach security researchers, DevOps engineers, and privacy-conscious developers worldwide.

READY IN SECONDS • ZERO SETUP

Your Files Belong to You.
Keep Them That Way.

Zero setup. Zero accounts. Zero telemetry. Download the binary, run a single command, and lock your files with mathematical certainty.