Docs
Key Management Design
How secrets are created, stored, unlocked and destroyed.
Generation
- BIP-39 entropy from the OS CSPRNG (128/256 bits)
- BIP-32/44 derivation; SLIP-10 for ed25519
Storage
- iOS: vault key in Keychain, wrapped by Secure Enclave key, biometry-bound (NATIVE)
- Android: vault key in Keystore/StrongBox, user-auth required (NATIVE)
- Web: AES-256-GCM vault, key from PIN via PBKDF2-SHA256 310k, random salt + IV
Unlock & use
- PIN (and biometric where enabled) unlocks for a session
- Auto-lock: immediately, 1, 5, 15, 30 min
- Secret decrypted only for the signing call, then dropped
PIN change
Every vault is decrypted with the old PIN and re-encrypted with the new one in a single operation.
Never
- Send secrets to any server
- Log secrets
- Include secrets in push, analytics or crash reports
Items marked NATIVE must be implemented as audited native code (Swift, Kotlin, Rust or C++), not in the web app.

