ZJX 1.27 CIPHERGLASS: The Archive Is More Than Its Contents
Paid Chronicle · Public Preview
ZJX 1.27 CIPHERGLASS: The Archive Is More Than Its Contents
Current recordhistoricalPreview updated
The encrypted-archive architecture behind ZJX 1.27: protected names, explicit trust boundaries, and the evidence required before qualification.
The limits belong in the public record. Qualification covers Linux. Unlocking is sequential across the whole archive; private temporary files may contain plaintext; outer size and header information remain visible. Passphrases cannot be recovered. Authentication does not establish the sender's identity. Review was internal and bounded, not an external professional cryptographic audit. Development-machine timings did not become release performance claims.
The architectural change was larger than adding a password prompt. An encrypted archive needs a clear answer to when its contents become trusted, where temporary plaintext may exist, and what happens when resources run out or publication fails.
CIPHERGLASS authenticates the complete encrypted envelope before interpreting the inner archive. Authentication and native archive integrity are reported separately. Plain creation refuses to overwrite an encrypted archive, preserving the user's existing protection. These are useful questions to ask of any protected archival workflow: what is concealed, what is verified, and what can an operation change?
The limits belong in the public record. Qualification covers Linux. Unlocking is sequential across the whole archive; private temporary files may contain plaintext; outer size and header information remain visible. Passphrases cannot be recovered. Authentication does not establish the sender's identity. Review was internal and bounded, not an external professional cryptographic audit. Development-machine timings did not become release performance claims.
The public release boundary
Qualification
CIPHERGLASS qualified on September 5, 2026.
Distribution
Its first public distribution is inside 1.28.0 LOCKWIRE, released September 6, 2026.
Public proof
Product facts, historical qualification counts, and limitations remain free in the source note.
CIPHERGLASS in context
ZJX 1.27 CIPHERGLASS
ZJX 1.27 CIPHERGLASS added native passphrase-protected archives, including encrypted internal filenames and metadata. It qualified on September 5, 2026, and reached users for the first time inside 1.28.0 LOCKWIRE on September 6. There was no separate public 1.27 distribution. Current release record.
The architectural change was larger than adding a password prompt. An encrypted archive needs a clear answer to when its contents become trusted, where temporary plaintext may exist, and what happens when resources run out or publication fails.
CIPHERGLASS authenticates the complete encrypted envelope before interpreting the inner archive. Authentication and native archive integrity are reported separately. Plain creation refuses to overwrite an encrypted archive, preserving the user's existing protection. These are useful questions to ask of any protected archival workflow: what is concealed, what is verified, and what can an operation change? Product contract.
The limits belong in the public record. Qualification covers Linux. Unlocking is sequential across the whole archive; private temporary files may contain plaintext; outer size and header information remain visible. Passphrases cannot be recovered. Authentication does not establish the sender's identity. Review was internal and bounded, not an external professional cryptographic audit. Development-machine timings did not become release performance claims.
The full engineering edition follows the evidence that turned those promises into a qualified product: independent format cross-reading, separate resource and publication decisions, the difference between a reviewed path and a directly tested one, and a reusable qualification matrix. It builds on 1.26 RELICWIRE, with the analysis grounded in the CIPHERGLASS record rather than a generic encryption checklist.
Edition
Encrypted-archive engineering edition 1.0
Published
Sep 6, 2026
Preview updated
Sep 6, 2026
Reading time
7 minutes
Full edition
1,681 words
Status
current
Who this is for
Archive and storage engineers evaluating the confidentiality and restoration contract.
Builders designing qualification gates for protected data workflows.
Not for
Readers seeking source code, an external cryptographic audit, or release-qualified throughput measurements.
Detailed contents
01
Make the protected object complete
02
Two answers behind a successful check
03
The disk is inside the operating contract
04
A smaller budget must not buy weaker protection
05
Preserve the user's existing decision
06
The gate that successful local tests could not close
07
A qualification matrix another builder can use
08
What CIPHERGLASS made possible
Named artifacts
Qualification matrix
Six decisions, their retained evidence, and the conclusions each cannot establish alone.
Independent format cross-reading analysis
The in-article evidence progression from passing local tests to reference/native cross-reading, including the shared cryptographic-library limit.
Resource and publication decision framework
The in-article analysis of fixed-cost admission, temporary plaintext, publication, durability and cleanup as separate operating decisions.
Evidence and method
historical: Synthesis of the retained CIPHERGLASS qualification record and current public product and release documentation. Article preparation did not rerun historical product tests.
The limits belong in the public record. Qualification covers Linux. Unlocking is sequential across the whole archive; private temporary files may contain plaintext; outer size and header information remain visible. Passphrases cannot be recovered. Authentication does not establish the sender's identity. Review was internal and bounded, not an external professional cryptographic audit. Development-machine timings did not become release performance claims.
Access and updates
Purchase includes lifetime read access to this edition, email-based recovery, and revisions published to the same edition.