Home / Security

Architecture, not a badge

Security

Not a certification logo — the actual mechanisms, because there's no cloud infrastructure here to certify in the first place.

Two separate encryption paths, for two different jobs

Little Greenhouse uses two genuinely different encryption systems, on purpose — one for locking the app on your own device, a different one for anything meant to leave it.

App Lock (PIN / biometric)

Backed by the AndroidKeyStore, using AES/GCM/NoPadding. The key is generated inside the device's secure hardware and never leaves it — it isn't derived from your PIN or fingerprint, and it isn't exportable, even by the app itself. This is specifically why App Lock can't double as a backup password: the key behind it is tied to this one device, permanently.

Backups & Partner Sharing

A password you choose derives a 256-bit AES-GCM key via PBKDF2-SHA256 at 150,000 iterations. A random salt and IV are generated per backup or export, so the same password never produces identical ciphertext twice. Unlike App Lock, this key is portable — it's derived from something you know, not something bound to one device, which is exactly what makes a backup restorable on a different phone, or a Partner View file openable on someone else's.

What this means in practice

  • We cannot recover a forgotten backup password — we never have it to begin with, on any server, because there's no server.
  • Losing your phone without a recent backup means losing data since that backup, with no remote copy to fall back on — the tradeoff of nothing being stored centrally.
  • App Lock and your backup passphrase are deliberately different systems with different keys — resetting one never resets the other.

Why no certification badge

Formal certifications like ISO 27001 exist to audit an organization's infrastructure — servers, access controls, data-handling processes. Little Greenhouse doesn't have that infrastructure to certify, because tracked data never reaches a server in the first place. The claim here isn't "audited and compliant" — it's that there's nothing centralized to audit.