OverviewSignetSemaForeCuriousLee
Attomus Signet

Assurance

Inspect Attomus Signet's security commitments, assessment history, engineering decisions and coordinated vulnerability-disclosure policy.

Attomus Signet is designed to make strong security claims checkable. This record sets out the commitments, evidence and known limits behind the product.

The Signet Covenant

  1. Your codes are yours. Export is free and unrestricted, and always will be. No feature that moves your data out of Signet will ever sit behind a payment.
  2. No accounts, no cloud, no telemetry. Signet’s OTP generation, storage, backup and restore make no network connections. The Android app does not request the INTERNET permission — inspect the APK and see for yourself.
  3. No third-party SDKs, no trackers, no ads. Our release pipeline scans every build for analytics and advertising SDKs and fails if it finds one.
  4. The cryptographic core is permanently open source (AttomusOTP, Apache 2.0). The code that generates your codes is public and will remain so.
  5. These commitments survive us. If Signet ever changes hands, we will bind these terms into that transaction; if we ever cannot honour them, we will say so plainly and give every user a full-export window before anything changes.

Verify it yourself

Android permissions

Download the APK, install Android build tools, and run:

aapt dump permissions signet.apk

The relevant permission output is:

android.permission.CAMERA
android.permission.USE_BIOMETRIC
android.permission.USE_FINGERPRINT
com.attomus.signet.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

The biometric permissions are supplied by AndroidX. The final permission is generated by Android tooling and scoped to Attomus Signet. There is no network permission of any kind: android.permission.INTERNET is absent.

No Exodus Privacy report is linked here because a public report has not yet been verified. We will add one when an analysis for the production package is available.

Store declarations

The live iOS App Privacy label states Data Not Collected. The Google Play data-safety declaration states No data shared and No data collected. iOS has no equivalent install-time network permission to inspect. Its App Privacy declaration is therefore supported by release-pipeline scanning of the application binary and its dependencies. Store declarations are statements rather than proof, so they should be read alongside the permission check, binary scanning and engineering record on this page.

Assurance history

Attomus Signet has been assessed against CREST-style methodology. This is a record of the work and its findings, not a claim of certification.

Date Review Result
12 April 2026 iOS release gate Passed.
16 April 2026 CREST-style review Conditional fail after three high-severity supply-chain findings. All three were fixed the same day.
17 April 2026 Re-test Clear.
May 2026 iOS remediation cycle Review findings were tracked through remediation and re-test.
13 May 2026 Android local CREST-style review Seven findings recorded and taken into remediation.
July 2026 Release-gate review A release-blocking issue was identified during the store-submission process. The release was withdrawn before any user installs.

The July review demonstrates the purpose of the release gate: the issue was identified before distribution, and the release did not proceed.

Engineering evidence

Architecture decisions

The architecture record contains 33 decisions. Four decisions that directly govern shipped security boundaries are published here:

The third record is published for the shipped encrypted-backup input path. Material concerning an unreleased migration input remains withheld until that capability ships.

Fuzzing and open cryptography

Dedicated Gradle lanes exercise fuzz harnesses for the secret-blob codec and backup parser. A completed four-hour Jazzer soak ran 2,691,560,179 executions with zero crashes. This is evidence from a completed run, not a claim that a scheduled campaign exists.

AttomusOTP is the open-source Swift and Kotlin implementation of RFC 6238 TOTP and RFC 4226 HOTP used by Attomus Signet. It is published under Apache 2.0.

The AttomusOTP release process produces a software bill of materials for tagged releases. Mobile-app SBOM publication remains in the assurance backlog; dependency evidence for the application builds can be requested through the disclosure contact below.

Coordinated vulnerability disclosure

Report a suspected vulnerability privately to security@attomus.com. We will acknowledge receipt within 48 hours, in line with Attomus’s disclosure policy.

Scope

Reports concerning Attomus Signet for iOS or Android, AttomusOTP, the backup format, release artefacts, or this published assurance record are in scope. Include a clear description, the affected platform or artefact, reproduction steps or proof of concept, and a suggested mitigation if known.

Safe harbour

Attomus will not pursue legal action against good-faith security research that avoids privacy violations, service disruption, data destruction and access beyond what is necessary to demonstrate the issue. Give us a reasonable opportunity to investigate and remediate before public disclosure.

We will coordinate remediation and publish an advisory for a confirmed vulnerability when disclosure helps users understand their exposure or required action. Security fixes ship in the latest release on each store. We support the current release; update to stay covered.

This disclosure route, the advisory process and the release evidence described above form Attomus Signet’s public readiness posture for the EU Cyber Resilience Act’s vulnerability-reporting obligations. In practical terms, they identify where to report a flaw, how Attomus responds, what evidence is retained, and how users receive a fix.