Hardware-Enforced Cloud Governance
Hardware-Enforced Cloud Governance
For enterprises and VCs underwriting the current AI wave, the greatest existential threat is a catastrophic identity failure, a ransomware lockout, or a rogue administrator hijacking the core infrastructure.
Cryptosign establishes a Break-Glass Root of Trust, providing hardware-enforced governance over your most critical digital IP.
Deployment Protocols by Infrastructure
Objective: To establish a zero-trust, mathematically derived physical failsafe for the highest-privilege root account within a Microsoft Azure (Entra ID) cloud environment using pre-engraved cryptographic shares.
Architectural Context: In day-to-day operations, the enterprise utilizes a strictly keyless architecture (biometrics, YubiKeys, ephemeral tokens). To prevent permanent IP lockout if the Identity Provider fails or an insider threat goes rogue, this protocol establishes the Break-Glass Root of Trust. Utilizing the Cryptosign Keyless Kit, the founders extract a mathematically flawless master password from pre-engraved hardware shares, apply it to the Azure failsafe account, and distribute the physical shares to an investor/founder quorum.
- Machine A (Online): The standard work computer used by the CEO or Lead Architect to access the Azure portal.
- Machine B (Air-Gapped): A dedicated, offline computer. Ideally, a machine booted from a temporary live operating system (e.g., Tails OS or Ubuntu on a USB) with all networking hardware physically disabled.
- The Cryptosign Keyless Kit: 5 Pre-Engraved Cryptosign shares, 5 serialized tamper-evident security bags, and the Cryptosign Secure SD Card (containing the audited offline SSS extraction engine).
- Destruction Materials: A cross-cut shredder or fire-safe incineration bowl.
- Isolate the Environment: Boot Machine B (Air-Gapped) and physically verify that all networking capabilities are disabled. Ensure no smartphones or smart speakers are active in the room.
- Break the Seal: Open the tamper-evident Cryptosign kit and extract the secure SD card.
- Load the Engine: Insert the SD card directly into Machine B.
- Execute Locally: Launch the provided `.html` file in the machine's local offline web browser.
- Activate Keyless Mode: On the offline tool's home screen, click the "Activate Keyless" button. The tool automatically configures itself for Unencrypted Recovery mode.
- Set Threshold: Confirm the required threshold matches your physical cards (e.g., enter `3` for a 3-of-5 kit).
- Input the Shares: Pick up any 3 of the 5 pre-engraved plates. Type the exact alphanumeric strings engraved on the plates into the offline tool.
- Extract the Password: Click "Recover Secret". The engine will mathematically combine the shares and output a highly entropic, 64-character string. This is your Azure Break-Glass Password.
- The Temporary Air-Bridge: Write this extracted password down on a physical piece of paper. Do not photograph it or copy it to a digital clipboard.
- Login to Azure: The Lead Architect logs into the Microsoft Entra admin center using standard daily keyless credentials.
- Create the Emergency User: Navigate to Users > All users > New user. Set the User Principal Name to a distinct, non-human identifier (e.g., `emergency.root@startup.onmicrosoft.com`).
- Assign God Privileges: Assign both the Global Administrator and Privileged Role Administrator roles.
- Exclude from Keyless/Conditional Access: Navigate to Protection > Conditional Access. Explicitly exclude the new emergency account so it can log in via password alone in a crisis.
- Apply the Extracted Password: Manually type the 64-character password from your physical piece of paper into the Azure portal. Confirm it and finalize the creation of the user.
- Destroy the Paper Air-Bridge: Take the temporary piece of paper containing the master password and completely incinerate or cross-cut shred it.
- Wipe the Air-Gap: Power down Machine B entirely and remove the SD card to flush the RAM. The extracted password is now eradicated from the digital realm.
- Secure the Plates: Place each of the 5 pre-engraved Cryptosign shares into its own serialized, tamper-evident bag. Seal them permanently.
- Log the Manifest: Create an official corporate governance memo logging the bag serial numbers to their assigned holders (e.g., CEO, CTO, Lead VC Partner, Corporate Counsel, Bank Vault).
- Physical Dispersal: Hand the sealed bags to the respective quorum members for storage.
Executed only during a catastrophic event. The current kit is considered "burnt" once used.
At least 3 members of the quorum physically convene and inspect the tamper-evident bags containing their physical Cryptosign shares to ensure they have not been compromised.
Using a fresh air-gapped computer and the Cryptosign SD card, the quorum launches the "Activate Keyless" mode, inputs 3 shares, and extracts the 64-character Break-Glass Password.
The CEO moves to a secure terminal, navigates to portal.azure.com, logs in using the Break-Glass UPN, and enters the 64-character password. This bypasses any broken SSO providers or compromised biometric requirements.
Once authenticated as Global Administrator, the user must immediately:
- Revoke Rogue Access: Navigate to Microsoft Entra ID > Users. Locate rogue accounts, click Revoke sessions, and disable their sign-in capabilities.
- Restore Founder Access: Locate legitimate CEO/CTO accounts, reset passwords, and require re-registration of hardware keys.
- Audit Conditional Access: Disable or bypass faulty policies that caused the lockout.
- Secure the Core IP: Verify the integrity of the Azure Managed HSM and ensure proprietary AI model weights or vaults have not been tampered with.
Once daily operations are restored, the emergency account's password must be randomized/reset. A brand new Cryptosign Keyless Kit must be ordered to establish a new physical quorum.
Objective: To establish a zero-trust, mathematically derived physical failsafe for the highest-privilege Break-Glass Administrator account within an Amazon Web Services (AWS) cloud environment using pre-engraved cryptographic shares.
Architectural Context: To prevent permanent IP lockout if the Identity Provider fails or an insider threat goes rogue, this protocol establishes the Break-Glass Root of Trust. The founders extract a master password from pre-engraved hardware shares, apply it to a dedicated AWS IAM failsafe account, and distribute the physical shares to an investor/founder quorum.
- Machine A (Online): The standard work computer used to access the AWS Management Console.
- Machine B (Air-Gapped): A dedicated, offline computer with all networking hardware physically disabled.
- The Cryptosign Keyless Kit: 5 Pre-Engraved shares, 5 tamper-evident bags, and the Cryptosign Secure SD Card.
- Destruction Materials: A cross-cut shredder or fire-safe incineration bowl.
- Boot Machine B (Air-Gapped) and physically verify that networking is disabled.
- Extract the secure SD card from the tamper-evident kit.
- Insert the SD card into Machine B and launch the `.html` file.
- Activate Keyless Mode: Click "Activate Keyless" on the tool's home screen.
- Set Threshold: Confirm the required threshold (e.g., `3`).
- Input the Shares: Type the alphanumeric strings from 3 pre-engraved plates.
- Extract the Password: Click "Recover Secret" to generate the 64-character AWS Break-Glass Password.
- The Temporary Air-Bridge: Write this extracted password down on a physical piece of paper. Do not photograph it.
- Login to AWS: The Lead Architect logs into the AWS Management Console.
- Create the Emergency User: Navigate to IAM > Users > Add users. Set the username (e.g., `emergency.root.failsafe`).
- Console Access: Select Provide user access to the AWS Management Console and choose Custom password.
- Apply the Extracted Password: Manually type the 64-character password. Uncheck "User must create a new password at next sign-in."
- Assign God Privileges: Under Permissions, select Attach policies directly and assign the `AdministratorAccess` managed policy.
- Exclude from MFA / SCPs: Ensure this IAM user is explicitly excluded from any AWS Organizations Service Control Policies (SCPs) or IAM boundary policies that mandate MFA. Record the 12-digit AWS Account ID on your temporary paper.
- Destroy the Paper Air-Bridge: Incinerate or shred the paper containing the password and Account ID.
- Wipe the Air-Gap: Power down Machine B entirely to flush the RAM.
- Secure the Plates: Place the shares into serialized, tamper-evident bags.
- Log the Manifest & Disperse: Record bag serial numbers and hand them to the quorum members (CEO, CTO, VC, Counsel, Vault).
At least 3 members of the quorum convene and inspect the tamper-evident bags.
Using a fresh air-gapped computer, the quorum inputs 3 shares into the "Activate Keyless" tool to extract the 64-character Break-Glass Password.
The CEO navigates to the account-specific AWS sign-in URL (`https://[12-digit-account-id].signin.aws.amazon.com/console`), logs in as `emergency.root.failsafe`, and enters the password. This bypasses broken SSO/STS providers.
Once authenticated with `AdministratorAccess`, the user must immediately:
- Revoke Rogue Access: Navigate to IAM (or IAM Identity Center). Delete rogue Access Keys, invalidate active STS sessions, and remove unauthorized policies.
- Restore Founder Access: Reset legitimate founder passwords and require re-registration of hardware keys.
- Secure the Core IP: Navigate to AWS KMS and Amazon S3. Verify Customer Managed Keys (CMKs) and review S3 Bucket Policies to ensure proprietary datasets are secure and not exposed to `allUsers` or cross-account access.
Reset the emergency account password and deploy a brand new Cryptosign Keyless Kit to establish a new quorum.
Objective: To establish a zero-trust, mathematically derived physical failsafe for the highest-privilege Break-Glass Administrator (Super Admin) account within a Google Cloud Platform (GCP) and Cloud Identity environment.
Architectural Context: To prevent permanent IP lockout if the Identity Provider fails, this protocol extracts a master password from pre-engraved hardware shares, applies it to a dedicated Google Cloud failsafe account, and distributes the physical shares to a quorum.
- Machine A (Online): The standard work computer used to access the Google Cloud Console and Workspace Admin Console.
- Machine B (Air-Gapped): A dedicated, offline computer with all networking hardware physically disabled.
- The Cryptosign Keyless Kit: 5 Pre-Engraved shares, 5 tamper-evident bags, and the Cryptosign Secure SD Card.
- Boot Machine B (Air-Gapped) and physically verify that networking is disabled.
- Load the Cryptosign SD Card and launch the offline `.html` file.
- Activate Keyless Mode: Click "Activate Keyless" and confirm your threshold.
- Input the Shares: Type the alphanumeric strings from 3 pre-engraved plates.
- Extract the Password: Click "Recover Secret" to generate the 64-character Google Cloud Break-Glass Password.
- The Temporary Air-Bridge: Write this password down on a piece of paper.
- Login to Google Workspace: Log into the Admin Console (`admin.google.com`).
- Create the Emergency User: Navigate to Directory > Users > Add new user (e.g., `emergency.root.failsafe@startup.com`).
- Apply the Extracted Password: Manually type the 64-character password. Explicitly uncheck "Ask for a password change at the next sign-in."
- Assign God Privileges: In Workspace, assign the Super Admin role. In the Google Cloud Console (`console.cloud.google.com`), assign the Organization Administrator and Owner roles at the top Organization node.
- Exclude from SSO / 2SV: Navigate to Security > Authentication. Place this user in an Exception Configuration Group that bypasses third-party SSO (SAML) routing and exempts it from enforced 2-Step Verification (2SV).
- Destroy the Paper Air-Bridge.
- Power down Machine B to wipe the RAM.
- Secure the plates in tamper-evident bags and distribute to the quorum.
At least 3 members of the quorum convene, inspect the bags, and use an air-gapped machine to extract the 64-character Break-Glass Password via the offline engine.
Navigate to `admin.google.com` or `console.cloud.google.com`. Log in using the emergency email and extracted password. The native Google login will succeed immediately, bypassing broken SSO.
Once authenticated as Super Admin / Organization Administrator, immediately execute:
- Revoke Rogue Access: In Workspace, locate rogue accounts. Click Reset sign-in cookies to kill active sessions, revoke OAuth tokens, and suspend accounts.
- Restore Founder Access: Reset legitimate founder passwords and generate backup codes.
- Audit IAM & Policies: In the GCP Console, remove unauthorized Service Accounts/IAM bindings and check Organization Policies for malicious guardrails.
- Secure the Core IP: Navigate to Google Cloud KMS and Cloud Storage. Verify encryption keys and ensure proprietary AI model buckets haven't been made public (`allUsers`).
Reset the emergency account password and deploy a brand new Cryptosign Keyless Kit to establish a new quorum.
Objective: To establish a zero-trust, mathematically derived physical failsafe for the highest-privilege Break-Glass Administrator (Organization Owner) account within an Enterprise AI Platform.
Architectural Context: Regardless of the foundational model (OpenAI Enterprise, Anthropic Console, Google Vertex AI, or Grok infrastructure), the existential threat is losing control of the top-level account governing fine-tuning datasets, proprietary weights, and API gateways. This protocol extracts a master password from hardware shares and applies it to a dedicated AI Platform failsafe account.
- Activate Keyless Mode: On the offline tool's home screen, click "Activate Keyless".
- Input the Shares: Type the alphanumeric strings from 3 pre-engraved plates.
- Extract the Password: Click "Recover Secret" to output a highly entropic, 64-character string. Write this down on a temporary paper air-bridge.
- Login to the AI Console: Log into the Enterprise AI Admin Dashboard using standard credentials.
- Create the Emergency User: Navigate to Users / Team Management > Add User. Set the email (e.g., `emergency.root.failsafe@startup.com`).
- Apply the Extracted Password: Manually type the 64-character password. (Accept any invites in an incognito window to set the password).
- Assign God Privileges: Assign the highest tier of access available (e.g., Organization Owner, Super Admin, or Primary Billing Admin).
- Exclude from SSO / Enforced MFA: Configure your identity layer to explicitly bypass central SSO routing (like Okta) for this specific emergency address. It must log in natively via password.
Incinerate the paper air-bridge, wipe the air-gap machine, seal the 5 hardware shares in tamper-evident bags, and distribute them to your founder/VC quorum.
During a catastrophic event, at least 3 quorum members convene, inspect the bags, and use the air-gapped Cryptosign SD card tool to extract the 64-character password.
The CEO logs into the native AI Platform portal using the emergency email and password. Once authenticated as the Organization Owner, immediately execute:
- Revoke Rogue Access: In User Management, downgrade rogue administrative accounts, revoke active sessions, or delete them entirely.
- Secure the API Gateways: In API Keys / Developer Settings, instantly revoke any production API keys compromised by the rogue actor to prevent billing spikes or rate-limit exhaustion.
- Audit Proprietary Data: Check Fine-Tuning, Files, and Model Management sections. Verify training datasets and custom-trained model weights have not been deleted or maliciously altered.
Reset the emergency account password and deploy a brand new Cryptosign Keyless Kit.