Platforms / macOS

KalderaShield on macOS

macOS ships as a universal build: one .dmg that installs on Apple Silicon and Intel Macs, built on macOS itself as the platform requires.

What you get

One universal build

The .dmg contains a universal application: it runs natively on Apple Silicon and Intel without Rosetta. The bundle is built on macOS, because macOS packages cannot be produced correctly on other platforms.

macOS-specific protections are active: Touch ID wraps the convenience-unlock payload with a Secure Enclave-backed WebAuthn PRF platform authenticator, and PRF-capable FIDO2 security keys such as a YubiKey 5 can serve as the wrapping authenticator instead.

Everything else is the same design as every other platform: per-record AES-256-GCM encryption, Argon2id with 64 MiB / 4 iterations / 2 lanes, the air-gap network policy and portable encrypted backups.

Getting started on macOS

Download and verify

Fetch the .dmg from the download page and compare its SHA-256 hash with SHA256SUMS.txt before mounting it.

Create the vault

Choose the master password and store the 24-word BIP-39 recovery key outside the application, in a place you control.

Optionally add Touch ID

Enroll platform unlock so daily access is a fingerprint, backed by the Secure Enclave. The master password remains the root of the vault and the only full recovery path.

Security Architecture

macOS specifics you should know

Signing and Gatekeeper

The application does not carry a Developer ID signature yet, and it is not notarized: the release pipeline blocks macOS artifacts from public release until real Developer ID signing is configured. Until then, a build you obtain outside the pipeline is subject to Gatekeeper's unsigned-application checks — verify the SHA-256 hash against the published checksums, and right-click → Open is the local override for a file you have verified yourself.

Universal

Apple Silicon + Intel

One .dmg serves both architectures natively. Built on macOS, as the platform's own packaging rules require.

Secure Enclave

Touch ID unlock

The PRF-derived wrapping key never leaves the secure hardware. Re-enrollment or device replacement degrades convenience only, never vault access.

FIDO2 / YubiKey

Key-based unlock

PRF-capable security keys (YubiKey 5, firmware 5.3+) can wrap the unlock payload; unlocking then requires the physical key.

Frequently Asked Questions

macOS questions

Does the universal build run on both M-series and Intel Macs?

Yes. The application is compiled for both architectures and macOS picks the right slice automatically. No Rosetta translation is involved.

Why does macOS warn about the application?

Because it is not signed with a Developer ID certificate or notarized yet. Verify the SHA-256 hash against the published checksums first; the verification page explains the whole story.

If I lose my Mac, do I lose my vault?

No. The vault file is never hardware-sealed. Restore an encrypted backup on any other device with the master password — Touch ID wraps convenience, not access.

Related pages

Download Installer