WestwyrdWestwyrd/products/umbra
Products/Umbra
Deep Cold Architecture

UMBRA
Shadow Protocol

The protocol of absolute silence.

UMBRA protects what must survive an adversary who holds every advantage — physical possession of the hardware, effectively unlimited computation, and the legal authority to compel your cooperation. It keeps assets in absolute operational silence: no network traffic, no disk activity, no power signature, no electromagnetic emission. There is nothing to intercept, nothing a subpoena can turn into access, and nothing that proves the vault holds anything at all. Absence itself is the defense.

System Manifest
Operational SignalNone emitted
StorageEncrypted NVMe · AES-256 + ChaCha20
ShieldingTEMPEST-rated Faraday
PowerIsolated flat-discharge
Custody Split3-of-5 threshold shards
Shard ColocationNever permitted
Time-Lock72 hr hardware minimum
AttestationMerkle proof, no access
Deterministic · extreme isolation
Fig.01 · Shielded Infrastructure
Umbra Diagram
Core Capabilities

Six protocols, absolute silence.

01

Signal Elimination

Faraday Containment · Zero Emission
On sealing, the vault disconnects from every bus and interface, discharges to a flat power profile, and rests inside a shielded enclosure. It emits no network traffic, no disk activity, no power draw, and no electromagnetic signature — indistinguishable from inert, powered-off equipment. An adversary cannot attack what they cannot detect.
0.00dB Signature
02

Distributed Custody

Shamir Secret Sharing · MPC
Authority over the vault is split across independent custodian shards that are never permitted to exist in one location at one time. No single custodian — and no single raid, warrant, or act of coercion — can reconstruct control. Recovery demands the deliberate, physical convergence of a threshold of holders.
3-of-5 Threshold
03

Compelled-Cooperation Resistance

Asymmetric Legal Defense
UMBRA assumes an adversary who can lawfully compel cooperation — and makes cooperation insufficient. With shards separated and the vault silent, a compelled custodian cannot alone open it, cannot prove what it contains, and cannot even confirm that assets are present. The protection is structural, not a promise.
Structurally Resistant
04

Hardware Time-Lock

Immutable Hardware Clock
A mandatory delay is enforced by a hardware timer that no software can override, so access is never immediate. Coercion under duress buys an adversary nothing but a waiting period in which the attempt stands exposed — the vault simply cannot be opened on demand.
72hr Mandatory Delay
05

Custody Proof Without Access

Merkle Root Attestation
Any custodian can prove an asset is held by computing a Merkle proof against the distributed state root — inclusion confirmed without opening the vault, revealing its contents, or disclosing its location. Reserves stay attestable while remaining, in every operational sense, invisible.
Zero-Knowledge Proof
06

Unsealing Ceremony

Biometric Multisig · Hash Chaining
Opening the vault requires the physical presence of a threshold of custodians at a designated facility under multi-factor biometric verification. The ceremony is documented and hash-chained, producing an evidentiary record of exactly who opened what, when, and under whose authority.
Cryptographic Audit Trail
Architecture

Built for the adversary
who holds every advantage.

UMBRA is designed around the worst-case adversary — one with physical possession of the vault hardware, effectively unlimited computational power, and the legal authority to compel the people who hold it. Against that adversary the secrecy of a password is not enough, so UMBRA removes the signals, separates the authority, and enforces the delays that make possession and compulsion insufficient. Even in complete physical control of the device, an adversary cannot determine whether assets exist, what they are, or when they were placed there — without assembling a threshold of separated custodian shards.

Total signal removal — on sealing, all network, USB, wireless, and power-analysis surfaces go dark, so there is no channel left to observe or attack.

Ciphertext at rest — volatile memory is wiped during sealing and only encrypted material remains, so seizing the storage medium yields nothing usable.

Separated authority — custodian shards are held apart and never colocated, so no single location, person, or order can reconstruct control.

Enforced delay — a hardware time-lock guarantees access is never instantaneous, defeating coercion that depends on immediacy.

Applications

What it does, in the field.

01

Deterministic Cold Storage

Treasury reserves and strategic assets held in absolute silence, under an authority you control and no one else can reconstruct. No custodian, exchange, or third party can move, pledge, or even observe the holdings.

assets → off-grid vault → physical isolation
Outcome
Custody no one else can touch
02

Air-Gapped Key Material

Master keys, signer shards, and recovery seeds sealed behind no live interface of any kind. The material cannot be exfiltrated remotely because there is no remote surface that reaches it — retrieval requires physical unsealing.

key generation → physical seal → network isolation
Outcome
Keys with no remote attack surface
03

Catastrophic-Scenario Survivability

Assets structured to outlast the failure of any single site, custodian, or jurisdiction. Because authority is separated and never colocated, the loss of one location or holder neither compromises the vault nor loses it.

shard distribution → geographic isolation → redundancy
Outcome
Survives loss of any one point
API Library

Technical Interfaces

POST/api/v1/umbra/attest

Generates a zero-knowledge Merkle proof of reserve inclusion for a specific asset without revealing vault contents, unlocking, or breaking silence.

{
  "asset_id": "btc-utxo-8819",
  "state_root": "0x4a9b2...",
  "requester_pubkey": "03a1b..."
}
POST/api/v1/umbra/ceremony/init

Initializes the unsealing ceremony, requiring physical multisig inputs from at least 3-of-5 authorized shard holders to begin the time-lock countdown.

{
  "ceremony_id": "crm-7731",
  "shard_signatures": ["sig1...", "sig2...", "sig3..."],
  "intent_hash": "0x88f1..."
}
Institutional Access

Architect absolute silence.

UMBRA vaults are physically independent units with no shared infrastructure, each operating in complete isolation and answering the worst-case adversary with absence rather than trust. Contact our custody operations team to scope a vault provisioning.