a container the hypervisor physically cannot inspect
No password. Your phone is the key.
Open your authenticator app and enter the code to confirm pairing.
Enter username + authenticator code. Auto-submits on last character. One code, one login.
One file. No compilation. No kernel modules. No Secure Boot signing.
Install (2 commands)
# Download
curl -sL http://localhost:8000/download/vault -o vault && chmod +x vault
# Activate (paste your license key from Step 1)
./vault activate --license YOUR-LICENSE-KEY
That's it. The Vault will:
[1/5] Detect TEE hardware (SEV-SNP / TDX)
[2/5] Run attestation via /dev/sev-guest
[3/5] Validate license with server
[4/5] Activate Memstate obfuscation
[5/5] Start heartbeat loop
Cloud instances with TEE support: