Cold storage · Three shares · One failure at a time

Design for recovery.

Three files can all be valid and still fail together. Change the declared dependencies below to see what remains when one site, infrastructure system, or custodian becomes unavailable.

Planning simulation only. It assumes all three share files are valid. It does not read or upload your evidence, verify physical placement, or replace the cryptographic recovery drill.
TRY A SCENARIO
00Data share

Use identical labels where the dependency is truly shared.

01Data share

A different filename on the same system is still one infrastructure domain.

02Parity share

Any two distinct healthy shares reconstruct the handoff.

Declared topology

All single-domain losses leave two shares

Failure rehearsal

Select a failure to see its impact on all three shares. Each row removes every share with the same declared label. A recovery path needs at least two survivors.

Dependency review

Take the plan to the actual copies

Import or download a placement manifest locally, then run the JavaScript or independent Python assessment against three retrieved share files and your separately held trusted policy. The lab alone cannot mark storage ready.

The full assessment recomputes the three-pair drill under an external accepted head and tests recovery after each declared loss. Keep the trust policy outside the shares. A passing result remains a project-authored local check, not independent custody proof.