- What happens if I lose my phone?
- The backup export is an encrypted file protected by a passphrase you set. Restore it on a new device and your accounts are back. If you did not create a backup before losing the device, the accounts are gone — there is no server-side copy and no recovery path. That is not a deficiency; it is how the security model works.
- How do I add or restore accounts?
- Scan the QR code supplied by the service or enter its setup details manually. To restore Attomus Signet accounts, open an encrypted .attomusauth backup and enter its passphrase. Provisioning and restore are performed on your device.
- Does it work with my service?
- If a service supports TOTP or HOTP — which is any service that shows a QR code when setting up two-factor authentication — Attomus Signet works with it. That includes GitHub, AWS, Cloudflare, Microsoft, Google Workspace, Stripe, and any other service using the standard otpauth:// format.
- How do I know the cryptography is correct?
- The TOTP and HOTP implementation is in AttomusOTP, a standalone open-source library published in full on GitHub. The implementation is hand-rolled against RFC 6238 and RFC 4226 with no third-party cryptographic dependencies. You can read every line of it.
- What does "biometric-gated" actually mean?
- Biometrics open a session. When you authenticate, Attomus Signet loads your secret keys into memory and begins computing codes — that is what makes the live countdown display possible. Your keys remain in memory for the duration of the session, which has a configurable timeout. When the session expires or the app moves to the background, keys are cleared and the app returns to a locked state. A biometric-enrolment change also locks the session and requires authentication again; it does not destroy your keys.
- Who built this and why should I trust it?
- Attomus Signet is built by Attomus, a cybersecurity firm that works with the UK Home Office, Ministry of Defence, and major defence contractors. We built it because we needed an authenticator we could recommend to clients and use ourselves — one with no third-party trust chain, no telemetry, auditable cryptography, and documentation that is honest about the security model. It is free to download. The cryptographic library that powers it is open source.