Where every HostSpica secret lives: the Android Keystore key hierarchy
SHORT ANSWER
Where do HostSpica apps keep their encryption keys?
In the Android Keystore, which keeps key material in secure hardware where the phone has it and never hands the raw key to the app. There is one AES key for Authenticator secrets, a separate one for the Vault, and one signing key per passkey. Backup keys are not stored: they are derived from your password when needed.
Key takeaways
- Keystore stops a key from being copied out. It does not stop code that runs as the app from asking Keystore to use it.
- Authenticator and Vault keys are separate, so neither can unlock the other's data.
- Each passkey has its own hardware-backed signing key that needs a fresh biometric check for every signature.
- Some labels, such as account names and Vault titles, are stored unencrypted so search works. We list exactly which.
What Android Keystore gives an app
Android Keystore lets an app create a key and then ask the system to use it, without the app ever holding the key bytes. On phones with a trusted execution environment, or a dedicated secure chip called StrongBox, the key lives inside that hardware, and even a compromised Android cannot read it out. Apps use handles, not keys. The apps ask for StrongBox first and fall back to the regular Keystore on phones that do not have it.
The keys
| Key | Type | Protects | Notes |
|---|---|---|---|
| Authenticator key | AES-256-GCM, one key, alias `hostspica_secret_key` | Every 2FA secret | Encrypt and decrypt only; random nonce per secret |
| Vault key | AES-256-GCM, one key, alias `hostspica_vault_key` | Vault passwords and notes | A different key from the Authenticator's, so they never share a failure |
| Passkey keys | EC P-256 signing key, one per passkey | The passkey's signatures | Sign-only, SHA-256, needs user authentication for each signature; StrongBox first, then a regular hardware key |
| Backup key | AES-256-GCM, derived from your password | Backup files | Never stored; recomputed from the password with PBKDF2 (see [backups](/research/how-hostspica-backups-are-encrypted-formats-and-limits)) |
What is encrypted, and what is not
| Data | Stored how |
|---|---|
| 2FA secret | Encrypted (AES-256-GCM) |
| 2FA account label, issuer, algorithm, digits, period, counter, favourite, group | Plain, in the app's private database |
| Vault password and notes | Encrypted together as one payload |
| Vault title, username, site, type, favourite flag, timestamps | Plain, so search and Autofill matching work without decrypting |
| Passkey private key | Never leaves Keystore; not in the database |
| Passkey site, user handle, credential ID, public key, signature counter, label | Plain, in the app's private database |
The private database is protected by Android's app sandbox: on a phone that is not rooted, other apps cannot read it. It is not encrypted at rest, which is why the secret fields themselves are. Android's automatic cloud backup is turned off for HostSpica Identity, so the database is not copied off the phone behind your back.
What Keystore protects against, and what it does not
What happens on delete and uninstall
Deleting a passkey also deletes its Keystore key, so no orphaned key is left behind. Uninstalling the app removes its keys and its database. Backup files you made are not touched, because they are yours.
Frequently asked questions
Is my 2FA secret safe if someone copies the app's database?
The secret is stored as ciphertext. Without the Keystore key, which cannot be copied out, the copy is useless. Account names and issuers are readable, though.
Do the Authenticator and Vault share a key?
No. Each has its own Keystore key, so a problem with one cannot unlock or damage the other.
What is StrongBox?
A separate tamper-resistant secure chip on some phones that can hold keys and perform crypto operations on its own, apart from the main processor. The apps use it when the phone has it.
References
Review status
Last technical self-review by the author on 3 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED