๐ Hash Integrity
ร1
Initiator structureA's response has all required fields
ร1
Initiator hashSHA-256(canonical(a.payload)) matches stored hash
ร1
Collaborator structureB's response has all required fields
ร1
Collaborator hashSHA-256(canonical(b.payload)) matches stored hash
๐งฒ Cross-Session Binding
ร1
A binds to HELLOA's response references the correct HELLO hash โ prevents substitution attacks
ร1
B binds to HELLOB's response references the same HELLO hash
ร1
A binds to offerA's response references the offer payload hash
ร1
B binds to offerB's response references the same offer hash
๐ Secure Enclave, Bio-metrics & Face Capture v5 planned ยท all optional ยท Settings only
ร1
Hardware-backed key (Secure Enclave)Key in device TEE โ never extractable, even on rooted device. Replaces localStorage.
ร1
Bio-metric unlockFingerprint / Face ID gates the signing key โ proves device owner was physically present
ร1
A witnessed B's faceAt scan time, A's camera captured B's face + B's QR. Hash signed into A's payload. B cannot deny presence.
ร1
B witnessed A's faceAt scan time, B's camera captured A's face + A's QR. Hash signed into B's payload. Mutual witness โ neither photographs themselves.
All four checks off by default. User enables in Settings. Never prompted during handshake. 100% score without these is valid for all everyday use โ maximum score reserved for extraordinary verification.