Sealed privacy hardening summary
Published: 2026-09-24
Type: Engineering / product public summary (Buzzio)
Not: A third-party independent audit attestation
This page is the public summary home for sealed-privacy work shipped and prepared as of this date. A formal Scope A+B+C firm report will replace or sit alongside this entry when commissioned and remediated.
One-sentence result
Buzzio sealed surfaces keep content keys on device; as of 2026-09-24 the client adds hardware-backed AES wrap for the mnemonic and private keys, Lock Database defaults for new app locks, and a ready independent-audit data room — while Hardened Whisper stays Preview and no third-party audit PDF has been published yet.
What shipped (custody)
| Item | Status |
|---|---|
| Hardware-backed wrap of mnemonic / master / private keys | Shipped (Android StrongBox→TEE; iOS Keychain device-bound) |
| Vault / backup recovery key wrap | Shipped |
Silent migrate on update (hw_wrap_v1) |
Shipped |
| Lock Database default for new custom app locks | Shipped |
| One-time Lock Database recommend for existing users | Shipped |
Honest claim: “Hardware-backed key custody.”
Forbidden claim: “Secure Enclave / StrongBox signs messages” or “hardware ECDH” — protocol crypto remains software secp256k1.
Details: Cryptography overview · Privacy guarantees · Hardware-backed key custody
Independent audit status
| Item | Status |
|---|---|
| Third-party Scope A+B+C report | Not published yet |
| Eng data room + SOW | Ready (internal pack; firm not yet commissioned) |
| Whisper network external audit | Blocked on device Tor/PCAP gates + separate SOW |
| Bug bounty | Not offered — Security disclosure |
When a firm engagement completes, findings counts and a PDF link will appear under Independent security audit#published-reports.
Whisper (Hardened Preview)
| Item | Status |
|---|---|
| Product label | Hardened Whisper Preview (not GA) |
| Android release Arti | Default ON in release builds |
| Device PCAP / Arti boot PASS | Pending (manual device evidence) |
| Public “untraceable” / Session-class claims | Forbidden until GA |
Residuals (unchanged honesty)
- Compromised unlocked phone / malware can still see decrypted chat after keys unwrap.
- Sealed 1:1 still has Firebase/FCM metadata ceilings (cert at deliver; “R at T” wakes).
- Shared rooms (Communities / OHG / Broadcast) remain operator-readable by design.
- Educational crypto OSS ≠ store binary unless a future audit report says so.
Full adversary list: Threat model · What Buzzio can see
Report issues
security@buzzio.dev — see Security disclosure.
Do not email mnemonics, recovery keys, or session tokens.