ZUPT
ZUPTPOST-QUANTUM BACKUP
zupt 5.2.9 (ZUPT)

Post-Quantum Key Generation

Generate a quantum-resistant hybrid or full post-quantum keypair.

Hybrid (recommended): ML-KEM-768 + X25519 with a domain-separated SHA3-512 combiner. Use with --pq.

Full PQ: ML-KEM-768 only — no classical layer. Use with --pq-only.

Each produces a private key (keep secret — decrypts archives) and a public key (share freely — encrypts archives). Native ML-KEM follows FIPS 203; X25519 follows RFC 7748.

Compress & Optionally Encrypt

Upload a file — receive a compressed .zupt archive, optionally encrypted.

File
Codec
Level (1–9)
Password (optional)
PQ Public Key — hybrid --pq
PQ Public Key — full PQ --pq-only

Extract & Decrypt

Upload a .zupt archive — receive the original files.

Archive
Password (if encrypted)
PQ Private Key — hybrid --pq
PQ Private Key — full PQ --pq-only
Upgrading from 5.2.1? Argon2id password and --pq-sdk archives require the retired SDK reader from that release. Recover them there and re-encrypt with a native mode; see MIGRATION.md.

Verify Archive Integrity

Validate every block's XXH64 checksum without extracting — confirm your backup is intact.

Archive
Password (if encrypted)
PQ Private Key — hybrid --pq
PQ Private Key — full PQ --pq-only

Inspect Archive Header

Read unauthenticated framing metadata without a password or key — format and trailer type, UUID, flags, encryption mode, sizes, and block count. Use Verify when integrity matters.

Archive
ZUPT CLI
5.2.9

Pure C11 backup utility with native hybrid and full post-quantum encryption, hardware-adaptive codecs, authenticated integrity trailers, block deduplication, and full-disk backup. Version 5.2.2 restored the original ZUPT name; the .zupt format remains v1.6.

© 2026 Cristian Cezar Moisés — AGPL-3.0-or-later

VaptVupt codec
2.65.11

Embedded LZ77 + entropy codec with portable SIMD and scalar paths. Version 2.65.11 adds stricter input-span, truncated-stream, output-capacity, frame-metadata, and XXH64 tail validation while preserving ZUPT archive compatibility.

© 2026 Cristian Cezar Moisés — GPL-3.0-or-later

Cryptographic Stack
ML-KEM-768FIPS 203Post-Quantum KEM
X25519RFC 7748Elliptic Curve DH
AES-256-CTRFIPS 197Symmetric Cipher
HMAC-SHA256RFC 2104Authentication
PBKDF2-SHA256RFC 8018Password KDF
SHA3 / SHAKEFIPS 202Hash / XOF