User Manual
Starting, register/sign-in, local Resident/Site-side/OTP/SSH browsing, trusted prompts, recovery, and erase.
Download PDFDocumentation shelf
Printable PDFs for owners and reviewers, plus live Markdown for threat models and protocols. The repository remains authoritative.
Raw Markdown and the complete tree live on GitHub.
Starting, register/sign-in, local Resident/Site-side/OTP/SSH browsing, trusted prompts, recovery, and erase.
Download PDFNative companion: Passkeys, SSH, Files, Activity, RTC, Device settings, firmware/recovery, and erase.
Download PDFWhat OpenPGP is on csiPass, the companion's pages and the glass with screenshots, setting GnuPG up, a card from empty to working on the command line, SSH, Git signing, and everyday use.
Download PDFThe four PIV slots and their PIN rules, setup and the administration key backup, the companion's pages and the glass with screenshots, the command-line tools, OpenSC administration, Windows logon, and key history.
Download PDFThreat model, trust boundaries, and what the companion must never see.
Download PDFCTAP, OpenPGP Card and PIV coverage clause by clause (U2F is lab-only), and how each item was checked.
Download PDFFull markdown export. Prefer the live open scale for current status.
Download PDFBest read from tracked source; they move faster than printable PDFs.
Overall threat model and security posture.
Read sourceCTAPHID, CTAP 2.1, and lab U2F surfaces.
Read sourceUV gate and authenticator PIN policy.
Read sourceCredential kinds, hmac-secret, attestation.
Read sourceUSB management wire, paging, Files, firmware, RTC, Activity.
Read sourceAuthority, sessions, and management-surface threats.
Read sourceToken, session, evaluation order, teardown.
Read sourceWhat each management command class exposes and changes.
Read sourceRuntime layers, trust boundaries, storage bands.
Read sourceJoint CCID plan, contracts, commissioning, lifecycle journal, and the evidence register.
Browse folder