v6
Vault Format
64 MB
Default Chunk
auto
Workers
10s
Skip Amount
2 GB
Preview Limit
5s
Auto-Next Delay
🌐 Deployments Live
EnvironmentURLBranchStatus
Production vaults.codes main ● Live
Staging dev.vaults.codes dev ● Staging
GitHub Mohan454522/stealthvault main, dev ● Public
⚡ Quick Actions
📋 How Production Releases Work
1️⃣
Code on dev branch
All new features go to dev. This deploys to dev.vaults.codes automatically.
2️⃣
Test on staging
Open dev.vaults.codes, test every feature, confirm everything works.
3️⃣
Run Promote workflow
GitHub Actions → promote.yml → fill version + notes → Run. dev merges into main.
4️⃣
Auto deploy to vaults.codes
Cloudflare Pages sees the push to main, deploys within ~30 seconds. Done.
🔧 Encryption Defaults
Default Chunk Size
Larger = faster for big files but uses more RAM. Old vaults auto-detect their own chunk size.
Worker Count
Parallel crypto workers. 0 = auto (match CPU cores). More workers = faster on multi-core.
Preview Size Limit
Files larger than this show "Too large to preview" and require export.
🎬 Viewer Settings
Skip Amount
How many seconds to skip forward/backward in videos/audio.
Auto-Play Next
Automatically play the next video/audio file when current one ends.
Off On
Auto-Next Delay
Countdown seconds before automatically going to next file.
Prefetch Ahead
How many files ahead to pre-decrypt in the background.
🤖 Automated Workflows
✅

CI — Validate on every push

Runs automatically when you push to dev or main. Checks file existence, JS syntax, critical functions. Takes ~10 seconds.

Auto
🚀

Promote dev → main (Release)

Manually triggered. You fill in the version number and release notes, choose dry_run=no, and it merges dev into main + creates a GitHub Release. Cloudflare then auto-deploys to vaults.codes.

Manual
☁️

Cloudflare Pages — Auto deploy

Every push to dev → dev.vaults.codes (within 30s). Every push to main → vaults.codes (within 30s). No action required.

Auto
📋 Step-by-step: Release to Production
Step 1: Push your code to dev (I do this for you automatically after each session)
git push origin dev
Step 2: Test on staging at dev.vaults.codes — encrypt a file, open it, test every button
Step 3: Go to GitHub Actions → promote.yml → Run workflow
Fill in: version (e.g. v1.2.0), release notes, dry_run=no
Step 4: Wait 30 seconds → vaults.codes is updated. Done ✔
🏢 How Real Companies Do This
WhatHow companies do itStealthVault version
Branchesmain (prod), staging, feature/* branchesmain + dev
Code reviewPull Request reviewed by 2 engineers before mergeYou are the engineer — just test on staging
CILint, unit tests, integration tests, build, security scanFile check + JS syntax check
DeployJenkins/GitLab CI/AWS CodeDeploy builds Docker, pushes to KubernetesCloudflare Pages (zero config, free)
VersioningSemantic versioning: v1.0.0, v1.1.0, v2.0.0Same — tracked in GitHub Releases
RollbackRe-deploy previous container imageCloudflare Pages → Deployments → click previous build → Rollback
MonitoringDatadog, Sentry, PagerDutyCloudflare Analytics (free, auto)
SecretsAWS Secrets Manager, Vault by HashiCorpNo server = no secrets needed
🌿 Branch Map
main PRODUCTION
→ vaults.codes
Only updated by the promote workflow. Never push directly. Protected.
dev STAGING
→ dev.vaults.codes
This is where all development happens. Push here after every feature or fix. I push here automatically.
feature/xxx OPTIONAL
→ no auto deploy
For big experimental features. Branch off dev, develop, merge back into dev when done. Not required for small changes.
📦 Versioning (how to name releases)
VersionWhen to useExamples
v1.0.0 → v1.0.1Patch — bug fix onlyFix progress bar sticking, fix crash on large files
v1.0.0 → v1.1.0Minor — new feature, backward compatibleAdd gallery type filter, add swipe gestures
v1.0.0 → v2.0.0Major — breaking changeVault format change, encryption algorithm change
⚠ StealthVault vault format changed in v6. All files encrypted with v6 format (MAGIC bytes 53564C540006) are always compatible.
📐 Binary Layout
┌─────────────────────────────────────────────────────┐ │ COVER IMAGE BYTES ← arbitrary length (any JPEG) ├─────────────────────────────────────────────────────┤ │ PAYLOAD HEADER: │ MAGIC [8 bytes] = 53 56 4C 54 00 06 00 00 │ SALT [16 bytes] = random, per-file │ CHUNK_SIZE [4 bytes] = uint32 LE ← stored at encrypt time │ FILE_COUNT [4 bytes] = uint32 LE │ For each file: │ META_ENC_LEN [4 bytes] = uint32 LE │ META_ENC [N bytes] = AES-GCM(IV[12] + JSON + tag[16]) │ JSON = { name, size, mime, nChunks, chunkSz } ├─────────────────────────────────────────────────────┤ │ PAYLOAD DATA: │ For each file, for each chunk: │ CHUNK_ENC_LEN [4 bytes] = uint32 LE │ CHUNK_ENC [N bytes] = AES-GCM(IV[12] + data + tag[16]) ├─────────────────────────────────────────────────────┤ │ TRAILER (last 20 bytes, always at end of file): │ COVER_SIZE [8 bytes] = uint64 LE (bytes of cover image) │ HEADER_SIZE [4 bytes] = uint32 LE (bytes of payload header) │ END_MARKER [8 bytes] = DE AD 56 36 00 00 DE AD └─────────────────────────────────────────────────────┘
🔐 Key Derivation
ParameterValue
AlgorithmPBKDF2-SHA-256
Iterations310,000 rounds
Salt16 bytes random per vault file
Output256-bit AES key
EncryptionAES-256-GCM (authenticated)
IV per chunk12 bytes random
Auth tag16 bytes (included in CHUNK_ENC)
StandardWeb Crypto API (SubtleCrypto) — browser-native, no dependencies
🔍 How to identify a vault file

The file looks like a normal JPEG. To verify it's a StealthVault v6 file:

  1. Open the file in a hex editor
  2. Read the last 8 bytes → must be DE AD 56 36 00 00 DE AD
  3. Read bytes at [fileSize - 20] for 8 bytes → COVER_SIZE
  4. Read bytes at [fileSize - 12] for 4 bytes → HEADER_SIZE
  5. Jump to [COVER_SIZE] and read 8 bytes → must be 53 56 4C 54 00 06 00 00

If all checks pass: it's a StealthVault v6 file. The cover image is bytes 0 to COVER_SIZE-1.

⚠️ What you need to decrypt a vault
🖼️
The vault image file(s)
The JPEG/PNG images you encrypted. Without these, nothing can be done.
🔑
Your passphrase
The password you used at encryption time. Cannot be reset or recovered.
🌐
A web browser
Chrome 89+, Edge 89+, Firefox 90+, Safari 15+. No internet needed if you have the files.
🆘 If vaults.codes is down
Option 1 — Use the GitHub source directly:
Download from: github.com/Mohan454522/stealthvault
→ Download ZIP → Extract → Open index.html in browser
Option 2 — Cloudflare Pages backup URL:
stealthvault-[hash].pages.dev (check Cloudflare dashboard for the exact URL)
Option 3 — Run locally:
Open index.html directly in Chrome/Edge. File:// URLs work fine.
📌 What to save (keep this somewhere safe)
Save this in a note app, printed paper, or USB drive:
  1. Your vault images (the encrypted JPEG files)
  2. Your passphrase(s) — written down or in a password manager
  3. This URL: github.com/Mohan454522/stealthvault
  4. Note: "Open index.html in Chrome. File picker → select vault image → enter passphrase → Unlock."
⚠ The encryption key is derived ONLY from your passphrase + the salt stored in the file. There is no recovery key, no backdoor, no server. If you forget your passphrase, the files are gone.