One part on your phone
Stored in the app's encrypted database. The encryption key is kept in the Android Keystore, hardware-backed where your phone supports it.
A card is only useful if nobody can forge it, change it or use it in your name. Here is how Bisotun makes sure of that, what happens if something goes wrong, and where the limits are.
Every card is digitally signed by its issuer: a mathematical seal made with a secret key that only the issuer's system holds. Anyone can check the seal with the issuer's public key; nobody can recreate it without the secret key.
Your wallet's secret key, which ties every card to you, is split in two:
Stored in the app's encrypted database. The encryption key is kept in the Android Keystore, hardware-backed where your phone supports it.
Bisotun's keyshare server holds the other part and only takes part in a proof after it has checked your PIN.
Neither part is enough on its own. That is why a copied card file is useless, and why a stolen phone does not give a thief your cards.
Your PIN never leaves your phone in readable form. The phone sends a salted fingerprint (hash) of it; the server stores that check value inside an encrypted record and never learns the PIN itself.
After 3 wrong PINs your wallet is locked for 1 minute, then 2 minutes, 4 minutes and so on, doubling each time. Because the server enforces this, wiping the app, copying it to another phone or restoring an old copy does not give an attacker extra attempts.
Also on your phone:
| If someone… | What happens |
|---|---|
| steals your phone but not your PIN | They cannot share or receive cards. PIN guessing is throttled by our server. |
| copies the files of your wallet | Useless without the server's part of the key, which needs your PIN. |
| edits a card to change a value | The issuer's signature no longer matches; every service rejects it. |
| creates a fake card | It has no valid issuer signature; it is rejected. |
| replaces the list of issuers | The list must carry Bisotun's signature; a tampered list is rejected. |
| reuses an old request | Requests older than 5 minutes are refused. |
| sets up a look-alike website that asks for your data | Your wallet shows its web address and marks it as not known to Bisotun. You decide; always check the address. |
Your cards are protected by your PIN and the server-side limits above. There is no copy of your cards anywhere else: on a new phone, you set up the wallet again and get your cards again from their issuers.
We would rather tell you than have you find out:
Found a security issue? Please tell us at security@bisotun.app. For anything else, write to support@bisotun.app.
See the protections at work.