Attomus Signet is designed to make strong security claims checkable. This record sets out the commitments, evidence and known limits behind the product.
The Signet Covenant
- Your codes are yours. Export is free and unrestricted, and always will be. No feature that moves your data out of Signet will ever sit behind a payment.
- No accounts, no cloud, no telemetry. Signet’s OTP generation, storage, backup and restore make no network connections. The Android app does not request the INTERNET permission — inspect the APK and see for yourself.
- No third-party SDKs, no trackers, no ads. Our release pipeline scans every build for analytics and advertising SDKs and fails if it finds one.
- The cryptographic core is permanently open source (AttomusOTP, Apache 2.0). The code that generates your codes is public and will remain so.
- These commitments survive us. If Signet ever changes hands, we will bind these terms into that transaction; if we ever cannot honour them, we will say so plainly and give every user a full-export window before anything changes.
Verify it yourself
Android permissions
Download the APK, install Android build tools, and run:
aapt dump permissions signet.apk
The relevant permission output is:
android.permission.CAMERA
android.permission.USE_BIOMETRIC
android.permission.USE_FINGERPRINT
com.attomus.signet.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
The biometric permissions are supplied by AndroidX. The final permission is generated by Android tooling and scoped to Attomus Signet. There is no network permission of any kind: android.permission.INTERNET is absent.
No Exodus Privacy report is linked here because a public report has not yet been verified. We will add one when an analysis for the production package is available.
Store declarations
The live iOS App Privacy label states Data Not Collected. The Google Play data-safety declaration states No data shared and No data collected. iOS has no equivalent install-time network permission to inspect. Its App Privacy declaration is therefore supported by release-pipeline scanning of the application binary and its dependencies. Store declarations are statements rather than proof, so they should be read alongside the permission check, binary scanning and engineering record on this page.
Assurance history
Attomus Signet has been assessed against CREST-style methodology. This is a record of the work and its findings, not a claim of certification.
| Date | Review | Result |
|---|---|---|
| 12 April 2026 | iOS release gate | Passed. |
| 16 April 2026 | CREST-style review | Conditional fail after three high-severity supply-chain findings. All three were fixed the same day. |
| 17 April 2026 | Re-test | Clear. |
| May 2026 | iOS remediation cycle | Review findings were tracked through remediation and re-test. |
| 13 May 2026 | Android local CREST-style review | Seven findings recorded and taken into remediation. |
| July 2026 | Release-gate review | A release-blocking issue was identified during the store-submission process. The release was withdrawn before any user installs. |
The July review demonstrates the purpose of the release gate: the issue was identified before distribution, and the release did not proceed.
Engineering evidence
Architecture decisions
The architecture record contains 33 decisions. Four decisions that directly govern shipped security boundaries are published here:
- AUTH-ADR-0027: Backup file format
- AUTH-ADR-0031: Explicit security UI state
- AUTH-ADR-0032: Hostile file input
- AUTH-ADR-0033: Biometric enrolment session model
The third record is published for the shipped encrypted-backup input path. Material concerning an unreleased migration input remains withheld until that capability ships.
Fuzzing and open cryptography
Dedicated Gradle lanes exercise fuzz harnesses for the secret-blob codec and backup parser. A completed four-hour Jazzer soak ran 2,691,560,179 executions with zero crashes. This is evidence from a completed run, not a claim that a scheduled campaign exists.
AttomusOTP is the open-source Swift and Kotlin implementation of RFC 6238 TOTP and RFC 4226 HOTP used by Attomus Signet. It is published under Apache 2.0.
The AttomusOTP release process produces a software bill of materials for tagged releases. Mobile-app SBOM publication remains in the assurance backlog; dependency evidence for the application builds can be requested through the disclosure contact below.
Coordinated vulnerability disclosure
Report a suspected vulnerability privately to security@attomus.com. We will acknowledge receipt within 48 hours, in line with Attomus’s disclosure policy.
Scope
Reports concerning Attomus Signet for iOS or Android, AttomusOTP, the backup format, release artefacts, or this published assurance record are in scope. Include a clear description, the affected platform or artefact, reproduction steps or proof of concept, and a suggested mitigation if known.
Safe harbour
Attomus will not pursue legal action against good-faith security research that avoids privacy violations, service disruption, data destruction and access beyond what is necessary to demonstrate the issue. Give us a reasonable opportunity to investigate and remediate before public disclosure.
We will coordinate remediation and publish an advisory for a confirmed vulnerability when disclosure helps users understand their exposure or required action. Security fixes ship in the latest release on each store. We support the current release; update to stay covered.
This disclosure route, the advisory process and the release evidence described above form Attomus Signet’s public readiness posture for the EU Cyber Resilience Act’s vulnerability-reporting obligations. In practical terms, they identify where to report a flaw, how Attomus responds, what evidence is retained, and how users receive a fix.