Security, in plain words

A card is only useful if nobody can forge it, change it or use it in your name. Here is how Bisotun makes sure of that, what happens if something goes wrong, and where the limits are.

Privacy and selective disclosureReport a security issue

Cards that cannot be forged or changed

Every card is digitally signed by its issuer: a mathematical seal made with a secret key that only the issuer's system holds. Anyone can check the seal with the issuer's public key; nobody can recreate it without the secret key.

  • Change one character on a card, and the seal no longer fits. The check fails.
  • Invent a card, and there is no valid seal. The check fails.
  • Use a key nobody knows, and the check fails too: the public keys of all issuers are published in Bisotun's signed list of issuers and card types. The wallet and the servers accept only a list carrying Bisotun's signature, and reject a tampered copy.

A key in two halves

Your wallet's secret key, which ties every card to you, is split in two:

One part on your phone

Stored in the app's encrypted database. The encryption key is kept in the Android Keystore, hardware-backed where your phone supports it.

One part on our keyshare server

Bisotun's keyshare server holds the other part and only takes part in a proof after it has checked your PIN.

Neither part is enough on its own. That is why a copied card file is useless, and why a stolen phone does not give a thief your cards.

Your PIN never leaves your phone in readable form. The phone sends a salted fingerprint (hash) of it; the server stores that check value inside an encrypted record and never learns the PIN itself.

PIN guessing is limited by the server

After 3 wrong PINs your wallet is locked for 1 minute, then 2 minutes, 4 minutes and so on, doubling each time. Because the server enforces this, wiping the app, copying it to another phone or restoring an old copy does not give an attacker extra attempts.

Also on your phone:

  • The app locks when you open it and after 5 minutes of inactivity.
  • Biometric unlock is optional and only opens the app screen; sharing and receiving cards still need your PIN.
  • Screens are hidden from screenshots and the app switcher by default.
  • The app warns you if your phone appears to be rooted, which weakens its protections.

Requests you can trust

  • Only registered services can start requests, each signed with the service's own key. Bisotun gives each service permission for specific items only; anything else is refused.
  • Old requests are refused. A request signed more than 5 minutes ago cannot be replayed.
  • A pairing code stops someone else from using a QR code that was meant for you. When asked, your wallet shows a short code that you type into the website, which links your wallet to that browser session only.
  • Results are signed. The session server signs the result it sends to the service, so the service can check that it is authentic.

What an attacker can and cannot do

If someone… What happens
steals your phone but not your PIN They cannot share or receive cards. PIN guessing is throttled by our server.
copies the files of your wallet Useless without the server's part of the key, which needs your PIN.
edits a card to change a value The issuer's signature no longer matches; every service rejects it.
creates a fake card It has no valid issuer signature; it is rejected.
replaces the list of issuers The list must carry Bisotun's signature; a tampered list is rejected.
reuses an old request Requests older than 5 minutes are refused.
sets up a look-alike website that asks for your data Your wallet shows its web address and marks it as not known to Bisotun. You decide; always check the address.

If you lose your phone

Your cards are protected by your PIN and the server-side limits above. There is no copy of your cards anywhere else: on a new phone, you set up the wallet again and get your cards again from their issuers.

Honest limits

We would rather tell you than have you find out:

  • Our servers must be reachable. Every card you add or share needs the keyshare server and the session server. If they are down, the wallet cannot be used.
  • The keyshare server knows when you use your wallet, and records your PIN checks, but not what you share or with whom.
  • The session server handles shared values for a few minutes to verify them for the service. It keeps them in memory only and keeps no record.
  • Bisotun can block a wallet account, for example after long inactivity or at your request.
  • Organization names are not verified yet, so a look-alike site can ask for data. The app warns you, but the decision is yours.
  • Cards cannot be withdrawn early by their issuer; they stay valid until they expire.
  • No backup. Losing your phone or forgetting your PIN means getting your cards again.
  • No certification claims. We do not claim audits or certifications that we do not have.

Report a problem

Found a security issue? Please tell us at security@bisotun.app. For anything else, write to support@bisotun.app.

See the protections at work.

Download for AndroidHow it works