stelixvault

Documentation

Everything you need to know, in seven moves.

There is no two-hundred-page manual: the application explains what it does at the moment it does it. What follows is what we would tell you on the phone.

01Install the application

  1. Download the Windows installer handed over when your account opens, and check its signature (right-click, Properties, Digital Signatures: STELIX DIGITAL SAS).
  2. Run it. No other software is required: no VPN, no agent.
  3. On first launch, choose "Create an account" and paste the registration key you received. Choose your passphrase: it never reaches us, and we cannot reset it.
  4. Put aside the recovery key shown only once — printed, or somewhere safe. Without it and without your passphrase, the vault is lost.
  5. Scan the one-time code (TOTP) in your authenticator app. It will be required for sensitive actions.

02Invite a colleague

  1. Settings, then "Invite a colleague": the application mints an invitation code, valid seven days, single use.
  2. Send it to them through a channel other than the vault's email.
  3. On their workstation, they install the application, choose "I received an invitation", paste the code, and choose their own passphrase.
  4. Then add them to the vaults that concern them. They see only those.

03Use your account on another workstation

  1. This is not an invitation: it is the same account, the same identity, the same vaults.
  2. On the workstation that already has the account: Settings, "Add a device", generate a link code (30 minutes, single use).
  3. On the new workstation: "I already have an account — add this workstation", paste the code, your TOTP code and your passphrase.
  4. An already enrolled workstation must approve: compare the fingerprint shown on both machines out loud before accepting.

04Install the browser extension

  1. Settings, "Browser extension": the application shows the extension folder and the three steps.
  2. In Chrome, Edge or Brave: open the extensions page, enable developer mode, and "Load unpacked" from that folder.
  3. Authorise each site from the application, never from the browser. The extension holds nothing: it asks, the application decides.

05Connect over SSH with a key from the vault

  1. Store the private key in an "SSH key" item: key, passphrase, public key.
  2. In the server's record, pick that key under "SSH key from the vault". It is stored once, and each server references it.
  3. Click "Connect": the session opens in the built-in terminal, without the key being shown or leaving the application.

06Losing a workstation, or a passphrase

  1. Lost or stolen workstation: Settings, "Sign out all my devices" cuts every session immediately; then revoke the device in the list.
  2. Forgotten passphrase: the recovery key, and it alone, reopens the account. We cannot replace it — that is the price of not being able to read you.
  3. Stuck workstation: "Start over on this workstation" wipes the local profile and cache. The account on the server is untouched.

07Export and leave

  1. At any time, each vault exports in the clear from the application, on your workstation.
  2. At the end of the contract, your vaults remain accessible for thirty days for export, then are destroyed, backups included.

What is not here

The detail of the algorithms and of what the server sees is on the Security page. What changed in each version is in the release notes. And for everything else, write to us: you talk to the people who write the software.