Skip to main content
Last updated: September 14, 2026tiCrypt 2.17.9

Get Started

Everyone reaches tiCrypt the same way: install the Connect Application, register an account, then log in with the key file registration gives you. Which account you register decides what you can do, not how you get in.

Account types

Identify yours before you start.

Account typeWho registersWhat it does
UserResearchers, analysts, and general usersWorks with files and virtual machines inside the secure enclave
AdminAdministrators who manage the deploymentNot a separate registration. Register as a user; an existing admin then assigns the Admin role and a permission profile
Site-key adminOne designated security administrator per deploymentSigns escrow certificates. Operates outside tiCrypt with its own login
Escrow userMembers of escrow groups responsible for key recoveryHolds one escrow group's key part of the recovery key
Most people start here

If your administrator told you to create a tiCrypt account, you want a User account. Follow this page straight through.


1. Install the Connect Application

You can only get the installer from your host institution or from Tera Insights.

Minimum requirements
  • Processor: 8 cores
  • Memory: 32 GB RAM
  • Operating system: macOS or Windows; Red Hat Enterprise Linux 7 or 8, or an equivalent such as CentOS or Springdale
  • App storage: 44.1 MB
  • Machine storage and graphics: based on intended use
  • Network: fiber-optic internet connection
  • Browsers: Google Chrome or Mozilla Firefox
caution

The Connect Application does not run on mobile devices or tablets, or on any Linux distribution other than those listed below.

macOS

  1. Open the Connect Application.dmg installer.
  2. Click Continue.
  3. Review the storage requirement and click Install.
  4. Enter your password when prompted, then click OK to allow access.
  5. Click Close.

Windows

  1. Open the Connect Application.exe installer.
  2. Click Next, then I Agree.
  3. Review the storage requirement and click Next.
  4. Select a Start menu folder and click Install.
  5. Click Finish.

Linux

Fedora 40+

dnf install <URL_TO_RPM>

Ubuntu 24+

wget <URL_TO_DEB>
dpkg -i <DOWNLOADED_FILE>

2. Register your account

Your private key is your identity

Registration generates a private key, stored in a key file on your device. That key encrypts and decrypts all your data.

  • Download the key file and back it up in more than one secure location.
  • Never share it with anyone, including administrators.
  • Changing your password generates a new key file and invalidates the old one.

If you lose both your password and your key file, your data cannot be recovered unless your deployment has key escrow configured.

Start the same way whichever account you are creating:

  1. Open the Connect Application.
  2. Select your deployment card.
  3. In the login window, select your account category.
  4. Click the create account button in the center.

The category and button differ by account type, and so does what happens at the end:

Account typeCategoryButtonActivated by
UsertiCryptCreate new user accountAn administrator
Escrow userEscrowCreate new escrow accountThe site-key administrator
Site-key adminSite-keyCreate new site keyTera Insights, by counter-signing

Then work through the wizard. It is the same wizard in all three cases:

  1. Enter your account details.
  2. Click Continue to password and enter your password twice.
  3. Click Continue to optional information and fill in whatever applies.
  4. Click Review account, then click any field you want to change and Return to review.
  5. Click Finish registration.
  6. Choose a folder for your key pair and click Save. This is the file you must back up.
  7. Wait for your account to be activated by whoever is listed in the table above.

Three differences are worth knowing before you start:

  • Users click Register with MFA first, and enter a login ID (usually your university email) with your first and last name. After logging in for the first time, you complete an MFA prompt.
  • Escrow users must select their escrow group before entering any account details. Ask your administrator which group you belong to before you begin, because it is the first thing the wizard asks. There is no MFA step.
  • Site-key admins skip the name and email step entirely, going straight from the start of the wizard to setting a password.
note

tiCrypt assigns your key a unique color and icon on the login page. It is generated automatically and cannot be changed. It exists so you can tell multiple keys apart.


3. Log in

Once your account is active:

  1. Open the Connect Application.
  2. Select your deployment card.
  3. Click Load key and open your key file, named your-user-name(mm-dd-yy).key.
  4. Click the dropdown next to the user name and select yourself.
  5. Enter your private key password.
  6. Click the Login button.

Users complete an MFA prompt on first login.


Where to go next

If you are aGo to
Researcher or analystResearch for files, virtual machines, and drives
AdministratorGovernance for users, teams, projects, and key custody
Escrow userEscrow Users
Site-key adminSite Key
System administratorDeploy & Operate

Managing more than one key or deployment, or checking which version you are running, is covered in Connect Application and Private Keys. If something goes wrong during any of the three steps above, see Troubleshooting.