Platforms / Windows

KalderaShield on Windows

Windows 10 and 11 on x64 are supported with three install shapes: a standard NSIS setup wizard, an MSI package for managed deployment, and a portable executable that runs without installation.

What you get

Three ways to install

The setup.exe wizard installs per-user or per-machine, adds Start-menu shortcuts and its own uninstaller. The MSI package exists for environments where software deployment expects that format. The portable executable needs none of that: unpack it and run.

All three build the same application. The vault file, encrypted backups and settings are portable between them, and the SHA-256 checksums are published for every artifact so you can verify the exact file you install.

Windows-specific protections are active: windows are requested with WDA_EXCLUDEFROMCAPTURE, which keeps the app out of ordinary screenshots, screen recordings and the task-switcher preview, and Windows Hello wraps the convenience-unlock payload with a TPM 2.0-backed platform authenticator.

Getting started on Windows

Download and verify

Fetch the installer from the download page, then compare its SHA-256 hash with the matching line in SHA256SUMS.txt before running it.

Create the vault

Choose a master password — Argon2id with 64 MiB, 4 iterations and 2 lanes stretches it into the vault key — and store the 24-word BIP-39 recovery key somewhere outside the app.

Optionally add Windows Hello

Enroll platform unlock so daily access is a glance or a PIN, backed by TPM 2.0. The master password always remains the real root of the vault.

Security Architecture

Windows specifics you should know

Signatures and SmartScreen

Windows installers are published as an unsigned preview and carry no Authenticode signature. There is no signing certificate: the release pipeline treats an unsigned desktop release as a failure, so the preview is marked as a pre-release and latest does not point at it. Unsigned files trigger the Windows SmartScreen "Windows protected your PC" warning, and you must click "More info" → "Run anyway" to run the installer; this is expected. Verify the SHA-256 digest against SHA256SUMS.txt before installing. An application to the SignPath Foundation for free open-source signing has not yet been submitted; once signing is available, subsequent releases will be signed and this warning goes away.

Windows 10 / 11

x64

One download serves both. The application ships as a Tauri desktop app with a WebView-based front end.

TPM 2.0

Windows Hello unlock

The WebAuthn PRF platform authenticator wraps the unlock payload; the wrapping key material never leaves secure hardware.

WDA_EXCLUDEFROMCAPTURE

Capture exclusion

App windows are excluded from ordinary screen capture. Privileged capture software is outside the threat model, as everywhere.

Frequently Asked Questions

Windows questions

Setup.exe, MSI or portable — which should I pick?

For a personal machine, the setup wizard. For managed deployment, the MSI. For a USB stick or a machine where you prefer no installation, the portable executable.

Why does SmartScreen warn about the installer?

Because it is unsigned and has no download reputation. Verify the SHA-256 hash against SHA256SUMS.txt; the verification page explains the full picture, including why this disappears once a signing certificate is in place.

Can I move my vault to another Windows PC?

Yes. Export an encrypted .ks backup, move it, and restore it with the master password. The vault file is portable, not tied to one machine or one install shape.

Related pages

Download Installer