Security model

Gatebridge is built on one rule: the relay server is untrusted. Secrets stay inside your phone, and everything in transit is encrypted before it leaves either device.

Threat model

What we defend against:

  • A curious or compromised relay server. It only sees encrypted traffic, never plaintext.
  • Network attackers. All data is encrypted end to end, with a fresh key for every session.
  • A lost or stolen phone. Every sign-in needs a fingerprint or face, and the signing secret never leaves the phone's security chip.
  • A malicious operator on the server. They can request signatures, but they never get the secret itself.

What is out of scope:

  • A fully compromised phone operating system. The hardware chip helps, but no software fix is perfect.
  • A compromised website you are signing in to.
  • Physical attacks on the phone's security chip.

Encryption in transit

  • Cipher: Noise Protocol (Noise_IK_25519_AESGCM_SHA256), an open standard for authenticated encryption.
  • Session keys: Freshly derived for every connection, so past sessions cannot be unlocked later.
  • Relay visibility: None. The relay only forwards opaque encrypted messages.
  • Failure handling: If a message fails its integrity check (replay, tamper), the connection drops immediately.

Where secrets live

  • Signing secrets are created and stored in your phone's built-in security chip, a tamper-resistant area of the processor that Android uses for keys and biometrics.
  • Every signature requires biometric authentication enforced at the hardware level. There is no software-only fallback.
  • Nothing is ever uploaded to a server or cloud service.

Pairing and trust

  • Pairing uses a special link (shown as a QR code) that identifies both your phone and the server.
  • The server records your phone's public key the first time you pair. Later sign-in attempts from a different phone are rejected until an admin explicitly re-pairs.

Full technical specification

The complete message formats, pairing link structure, encryption details, and error codes are specified inPROTOCOL.mdin the repository. Both the server program and the Android app follow that specification exactly.

Reporting a vulnerability

If you believe you have found a security issue, emailsecurity@gatebridge.app. Do not open a public GitHub issue for security vulnerabilities.

Get notified at launch

Gatebridge is not out yet. Leave your email and we will let you know the moment it ships. Early subscribers get a free period when we launch.