Security

Local-first. No backend. Your keys never leave your phone.

Architecture

Untaxed runs entirely on your device. There are no hosted wallets, accounts or backend databases. Everything critical happens locally:

Key encryption

  1. Password derivation: your password runs through PBKDF2 with 100,000 iterations and a random salt.
  2. Encryption: keys are encrypted with AES-256-GCM using the derived key and a random IV.
  3. Storage: the encrypted blob, salt and IV are stored on the device. The password is never stored.
  4. Decryption: unlocking re-derives the key from your password. A wrong password fails decryption.
Why PBKDF2 with 100K iterations? It makes brute-force password guessing computationally expensive even if the encrypted data were ever extracted from a device.

Biometrics & PIN

Biometric unlock (Face ID or Touch ID on iOS, fingerprint or face unlock on Android) uses the device's own authentication. Biometric data stays in the phone's secure hardware and is never available to Untaxed. They gate access to the already-encrypted keys; they do not replace the password that encrypts them.

Memory management

Auto-lock

Configurable inactivity timeout, default 15 minutes. When triggered:

  1. All decrypted keys are deleted from memory.
  2. The app shows the lock screen.
  3. Nothing can be signed until you authenticate again.

Transaction signing

  1. The app builds the transaction for a swap, send or order.
  2. It is signed with the decrypted key held in memory.
  3. Only the signed transaction leaves the device, via your selected engine.
  4. Private keys never leave the app process.

Network communication

No private keys or seed phrases are ever sent to any external service. No analytics or telemetry is sent anywhere.

Best practices