Get Started
Everyone reaches tiCrypt the same way: install the Connect Application, register an account, then log in with the key file registration gives you. Which account you register decides what you can do, not how you get in.
Account types
Identify yours before you start.
| Account type | Who registers | What it does |
|---|---|---|
| User | Researchers, analysts, and general users | Works with files and virtual machines inside the secure enclave |
| Admin | Administrators who manage the deployment | Not a separate registration. Register as a user; an existing admin then assigns the Admin role and a permission profile |
| Site-key admin | One designated security administrator per deployment | Signs escrow certificates. Operates outside tiCrypt with its own login |
| Escrow user | Members of escrow groups responsible for key recovery | Holds one escrow group's key part of the recovery key |
If your administrator told you to create a tiCrypt account, you want a User account. Follow this page straight through.
1. Install the Connect Application
You can only get the installer from your host institution or from Tera Insights.
Minimum requirements
- Processor: 8 cores
- Memory: 32 GB RAM
- Operating system: macOS or Windows; Red Hat Enterprise Linux 7 or 8, or an equivalent such as CentOS or Springdale
- App storage: 44.1 MB
- Machine storage and graphics: based on intended use
- Network: fiber-optic internet connection
- Browsers: Google Chrome or Mozilla Firefox
The Connect Application does not run on mobile devices or tablets, or on any Linux distribution other than those listed below.
macOS
- Open the Connect Application.dmg installer.
- Click Continue.
- Review the storage requirement and click Install.
- Enter your password when prompted, then click OK to allow access.
- Click Close.
Windows
- Open the Connect Application.exe installer.
- Click Next, then I Agree.
- Review the storage requirement and click Next.
- Select a Start menu folder and click Install.
- Click Finish.
Linux
Fedora 40+
dnf install <URL_TO_RPM>
Ubuntu 24+
wget <URL_TO_DEB>
dpkg -i <DOWNLOADED_FILE>
2. Register your account
Registration generates a private key, stored in a key file on your device. That key encrypts and decrypts all your data.
- Download the key file and back it up in more than one secure location.
- Never share it with anyone, including administrators.
- Changing your password generates a new key file and invalidates the old one.
If you lose both your password and your key file, your data cannot be recovered unless your deployment has key escrow configured.
Start the same way whichever account you are creating:
- Open the Connect Application.
- Select your deployment card.
- In the login window, select your account category.
- Click the create account button in the center.
The category and button differ by account type, and so does what happens at the end:
| Account type | Category | Button | Activated by |
|---|---|---|---|
| User | tiCrypt | Create new user account | An administrator |
| Escrow user | Escrow | Create new escrow account | The site-key administrator |
| Site-key admin | Site-key | Create new site key | Tera Insights, by counter-signing |
Then work through the wizard. It is the same wizard in all three cases:
- Enter your account details.
- Click Continue to password and enter your password twice.
- Click Continue to optional information and fill in whatever applies.
- Click Review account, then click any field you want to change and Return to review.
- Click Finish registration.
- Choose a folder for your key pair and click Save. This is the file you must back up.
- Wait for your account to be activated by whoever is listed in the table above.
Three differences are worth knowing before you start:
- Users click Register with MFA first, and enter a login ID (usually your university email) with your first and last name. After logging in for the first time, you complete an MFA prompt.
- Escrow users must select their escrow group before entering any account details. Ask your administrator which group you belong to before you begin, because it is the first thing the wizard asks. There is no MFA step.
- Site-key admins skip the name and email step entirely, going straight from the start of the wizard to setting a password.
tiCrypt assigns your key a unique color and icon on the login page. It is generated automatically and cannot be changed. It exists so you can tell multiple keys apart.
3. Log in
Once your account is active:
- Open the Connect Application.
- Select your deployment card.
- Click Load key and open your key file, named
your-user-name(mm-dd-yy).key. - Click the dropdown next to the user name and select yourself.
- Enter your private key password.
- Click the Login button.
Users complete an MFA prompt on first login.
Where to go next
| If you are a | Go to |
|---|---|
| Researcher or analyst | Research for files, virtual machines, and drives |
| Administrator | Governance for users, teams, projects, and key custody |
| Escrow user | Escrow Users |
| Site-key admin | Site Key |
| System administrator | Deploy & Operate |
Managing more than one key or deployment, or checking which version you are running, is covered in Connect Application and Private Keys. If something goes wrong during any of the three steps above, see Troubleshooting.