Quickstart & First Secure Vault
Step-by-step setup guide for dewDrive. Initialize your first Secure Vault, configure AES-256 zero-knowledge encryption, connect AWS S3 / Wasabi / Backblaze B2, and schedule automated snapshots.
Welcome to dewDrive. This guide walks you through downloading the native desktop client, initializing your first zero-knowledge encrypted Secure Vault, and setting up continuous automated snapshots.
1. System Requirements & Downloads
The currently published desktop package is a macOS Apple Silicon preview, version 0.1.0. See the Download Center for the available files and SHA-256 checksums. Production installers for the other target platforms have not yet been published.
| Target platform | Architecture | Download status | Available formats |
|---|---|---|---|
| macOS | Apple Silicon (arm64) | v0.1.0 preview available | .dmg, .zip |
| macOS | Intel (x64) | Planned; no verified installer published | — |
| Windows | x86_64 | Planned; no verified installer published | — |
| Linux | x86_64 | Planned; no verified installer published | — |
On macOS, dewDrive requires Full Disk Access (FDA) permissions under System Settings > Privacy & Security so the background backup daemon can read user profile directories (~/Documents, ~/Library, etc.) without OS permission dialogs interrupting background jobs.
2. Step 1: Install the Desktop Cockpit
- On a Mac with Apple Silicon, download the preview from the Download Center and verify its checksum.
- Open the disk image or extract the app archive, then drag
dewDrive.appinto/Applications. - On first launch, grant Full Disk Access when requested under System Settings > Privacy & Security.
Installation instructions for Intel Macs, Windows, and Linux will be added when verified packages are published. The Windows architecture includes an elevated helper for Volume Shadow Copy (VSS); its installer registration will be validated as part of that release.
3. Step 2: Initialize a Secure Vault
A Secure Vault is an immutable, client-side encrypted repository where deduplicated snapshot chunks are stored.
- Launch dewDrive and open the Secure Vaults tab.
- Click Create New Vault.
- Select your target backend:
Option A: Local Storage or NAS Mount
- Select Local Drive / Network Share.
- Specify the destination directory (e.g.,
/Volumes/BackupDrive/dewdrive-vaultorD:\Vaults\Primary). - Network paths mounted via SMB or NFS can also be selected.
Option B: Cloud Object Storage (S3 / Wasabi / Backblaze B2)
- Select Amazon S3 Compatible.
- Provide your cloud credentials:
- Endpoint URL: e.g.,
https://s3.us-east-1.amazonaws.com,https://s3.wasabisys.com, orhttps://s3.us-west-004.backblazeb2.com - Bucket Name: Your pre-created S3 bucket (e.g.,
my-company-backup-vault) - Access Key ID: IAM Access Key with Read/Write/List permissions
- Secret Access Key: Secret key
- Endpoint URL: e.g.,
If your bucket has S3 Object Lock enabled in Compliance or Governance mode, dewDrive automatically coordinates with S3 retention policies to guarantee that ransomware cannot purge historical snapshots.
4. Step 3: Configure Zero-Knowledge Encryption
During vault creation, you must specify a Master Vault Password:
Master Encryption Scheme: AES-256-CTR + Poly1305 / Argon2id KDF
Key Derivation Iterations: 65,536 Rounds
Zero-Knowledge Guarantee: Your master password is never transmitted to dewDrive cloud servers or stored in any cloud database. It derives the master encryption key purely inside your local device memory. If you lose this password, your encrypted data cannot be decrypted by anyone. Ensure you store a copy in a secure password manager.
5. Step 4: Add Backup Folders & Start Ingestion
- Switch to the Backup Locations tab in the desktop cockpit.
- Click Add Folder and select the directories you want to protect (e.g.,
/Users/j7/Documents,/Users/j7/Projects). - Toggle Automated Continuous Backup:
- Interval: Choose between Continuous (every 15 minutes), Hourly, or Daily.
- Governor Mode: Select AC Standard (runs at full speed when plugged into power) or Battery Eco (throttles CPU and pauses hashing when on battery power).
- Click Start Ingestion Now.
dewDrive will perform Content-Defined Chunking (CDC), calculate SHA-256 block hashes, deduplicate against existing chunks in the vault, compress with Zstandard, and upload the encrypted blocks to your Secure Vault.
6. Verifying Snapshot Health
Once ingestion completes, click View Snapshots to inspect the committed Merkle tree:
- Each snapshot is assigned a unique cryptographic snapshot ID.
- Check the integrity of stored blocks at any time by running Verify Vault Integrity from the cockpit tools menu.