Docs

Key Management Design

How secrets are created, stored, unlocked and destroyed.

Generation

  • BIP-39 entropy from the OS CSPRNG (128/256 bits)
  • BIP-32/44 derivation; SLIP-10 for ed25519

Storage

  • iOS: vault key in Keychain, wrapped by Secure Enclave key, biometry-bound (NATIVE)
  • Android: vault key in Keystore/StrongBox, user-auth required (NATIVE)
  • Web: AES-256-GCM vault, key from PIN via PBKDF2-SHA256 310k, random salt + IV

Unlock & use

  • PIN (and biometric where enabled) unlocks for a session
  • Auto-lock: immediately, 1, 5, 15, 30 min
  • Secret decrypted only for the signing call, then dropped

PIN change

Every vault is decrypted with the old PIN and re-encrypted with the new one in a single operation.

Never

  • Send secrets to any server
  • Log secrets
  • Include secrets in push, analytics or crash reports

Items marked NATIVE must be implemented as audited native code (Swift, Kotlin, Rust or C++), not in the web app.