Security Architecture Whitepaper - Findrr

Effective Date: October 24, 2026

1. Encryption Architecture

  • Cipher: AES-256-GCM (Advanced Encryption Standard in Galois/Counter Mode) providing confidentiality and data authenticity verification.
  • Nonce Generation: Cryptographically secure 128-bit random IVs generated via java.security.SecureRandom for every backup payload.

2. Key Derivation Function (KDF)

  • Master Keys are derived on-device using PBKDF2WithHmacSHA256 with 10,000 iterations and a unique user salt (FindrrVaultSalt_<user_id>).
  • Keys remain strictly in RAM on your phone and are NEVER sent to our servers.

3. Server Exposure & Threat Model

  • Cloud Database (Supabase) receives only unreadable Base64 ciphertext payloads.
  • In the event of a database compromise, an attacker sees only scrambled ciphertext.

4. Data Recovery & Local Rolling Snapshots

Findrr maintains up to 5 time-stamped rolling restore points locally on your phone for 1-tap data recovery.