About Attomus

Open Source Acknowledgements

Attomus Signet is built on open-source components. This page lists the third-party libraries used in Signet for iOS and Android, with their licences.

Open Source Acknowledgements

Attomus Signet is built on open-source software. We are grateful to the authors and contributors of the following libraries.


Signet for iOS

AttomusOTP Swift library implementing TOTP (RFC 6238) and HOTP (RFC 4226). Copyright © 2026 Attomus Ltd. MIT Licence — source

Argon2Kit Swift wrapper for the Argon2 password hashing function. Used for backup passphrase key derivation. Copyright © Tommaso Madonia. MIT Licence — source

zxcvbn-swift Password strength estimation library, ported from Dropbox’s zxcvbn. Used to validate backup passphrase strength. Copyright © Watanabe Toshinori. MIT Licence — source


Signet for Android

AttomusOTP for Android Kotlin library implementing TOTP (RFC 6238) and HOTP (RFC 4226). Copyright © 2026 Attomus Ltd. MIT Licence — source

Bouncy Castle (bcprov-jdk18on) Cryptographic library. Used for Argon2id key derivation during backup encryption. Copyright © The Legion of the Bouncy Castle Inc. MIT Licence — source

zxcvbn4j Password strength estimation library. Used to validate backup passphrase strength. Copyright © Nulab Inc. MIT Licence — source

ZXing Core Barcode image processing library. Used for QR code scanning during account provisioning. Copyright © ZXing authors. Apache Licence 2.0 — source


Licence texts

Full licence texts are available within the application bundles and at the links above. If you have a question about any of the licences listed here, contact hello@attomus.com.