Secure Storage of Sensitive Data
Risk: Seedphrases or sensitive data (e.g., JSON files with keys) may be inadvertently exposed if not securely stored or if backed up to cloud storage.
Control:
Sensitive data (e.g., seedphrases, JSON files) is stored using the secure storage features of each mobile OS, ensuring encrypted, protected storage of secrets on the device.
Auto-backup for secure storage is explicitly disabled to prevent cloud backups, mitigating the risk of third-party data leakage.
References:
NIST CSF Alignment:
FCA Compliance:
FG 16/5: Secure storage of sensitive customer information, prevent backups to untrusted locations
Last updated