Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
SECURITY
One page for HostSpica Authenticator, Passkey and Identity. What each app does, how you can check it, and the limits. Last reviewed 3 October 2026.
SHORT ANSWER
How do HostSpica apps protect my data?
They keep everything on your phone and cannot send it anywhere, because none of them declares the internet permission. Secrets are encrypted with keys held in Android Keystore, and the apps ask for your fingerprint, face or screen lock before opening, filling or signing. They have not had an independent audit yet.
| Authenticator | Passkey | Identity | |
|---|---|---|---|
| Network access | No INTERNET permission declared | No INTERNET permission declared | No INTERNET permission declared (checked on the 1.0.0 release build) |
| Where secrets live | 2FA seeds encrypted with AES-256-GCM; the key is generated in Android Keystore and is not exportable | Private keys generated inside Android Keystore (StrongBox where the phone has it); not exportable | Vault passwords and notes encrypted with AES-256-GCM under a Keystore key; 2FA seeds the same way |
| What is gated by fingerprint, face or screen lock | Opening the app, exporting a backup, deleting an account | Every passkey signature: the biometric prompt is bound to the key that signs | Opening the app, each Autofill fill, exporting a backup; optional re-check before revealing a password |
| Backups | Password-protected file: PBKDF2-HMAC-SHA256 (600,000 rounds) then AES-GCM | None. Passkey keys cannot leave the phone by design | One password-protected file for Authenticator accounts and Vault; passkeys excluded |
| On-screen exposure | Screenshots and screen recording blocked; copied codes cleared from the clipboard after 30 seconds | Inside HostSpica Identity, screenshots and screen recording are blocked | Screenshots and screen recording blocked; copied passwords marked sensitive and cleared after 30 seconds |
| Rooted-device handling | Warning banner, never a hard block | Warning banner, never a hard block | Warning banner in the Authenticator and Passkey tabs |
HostSpica Identity contains the Authenticator, Passkey, AirAuth and Vault as tabs. Facts on this page describe the builds we have tested; they can change between versions.
Everything on this page is our own design and testing. We have not had a third party audit the apps. Until we have, treat the claims as ours, not as verified by someone else.
The passkey code follows the WebAuthn standard and works with large sites, but HostSpica Passkey is not certified by the FIDO Alliance. Our own Bluetooth cross-device sign-in is an experimental protocol, not a FIDO transport.
A rooted phone with malware, a malicious keyboard or accessibility service, or someone watching your screen can see what the app shows. Screenshot blocking does not stop a camera pointed at the screen.
Vault entries keep their title, username and site as plain labels in the app's private database so search works. Passwords and notes are encrypted. Other apps cannot read that database on an unrooted phone, but it is not encrypted at rest.
We cannot reset a backup password or recover a lost vault, because we never hold the keys. Lose the phone and the backup password and the data is gone. Passkeys are never backed up, so keep another way to sign in to each site.
You can check network access yourself in a minute. Checking the encryption design yourself needs the source code, which is not public yet. We plan to publish the formats and test vectors.
The network claim is the easiest to verify. Our guide shows the exact commands and the permission list we found.
How to check that an Android app has no internet permissionIt encrypts passwords with a key held in Android Keystore, locks behind your fingerprint, face or screen lock, and has no network access. It has not had an independent audit, and it cannot protect you on a compromised phone. Read the limits above before relying on it.
No. The apps declare no internet permission, have no account system and include no analytics or advertising SDKs.
Write to [email protected]. The disclosure policy explains what to include and what to expect.