Attomus Signet is built on open-source software. We are grateful to the authors and contributors of the following libraries.
Signet for iOS
AttomusOTP Swift library implementing TOTP (RFC 6238) and HOTP (RFC 4226). Copyright © 2026 Attomus Ltd. MIT Licence — source
Argon2Kit Swift wrapper for the Argon2 password hashing function. Used for backup passphrase key derivation. Copyright © Tommaso Madonia. MIT Licence — source
zxcvbn-swift Password strength estimation library, ported from Dropbox’s zxcvbn. Used to validate backup passphrase strength. Copyright © Watanabe Toshinori. MIT Licence — source
Signet for Android
AttomusOTP for Android Kotlin library implementing TOTP (RFC 6238) and HOTP (RFC 4226). Copyright © 2026 Attomus Ltd. MIT Licence — source
Bouncy Castle (bcprov-jdk18on)
Cryptographic library. Used for Argon2id key derivation during backup encryption.
Copyright © The Legion of the Bouncy Castle Inc.
MIT Licence — source
zxcvbn4j Password strength estimation library. Used to validate backup passphrase strength. Copyright © Nulab Inc. MIT Licence — source
ZXing Core Barcode image processing library. Used for QR code scanning during account provisioning. Copyright © ZXing authors. Apache Licence 2.0 — source
Licence texts
Full licence texts are available within the application bundles and at the links above. If you have a question about any of the licences listed here, contact hello@attomus.com.