Security
Simple for families. Secure underneath.
FamVerify is designed to confirm that a trusted phone completed a fresh check. It is not designed to judge a request, detect a deepfake or make impersonation and coercion impossible.
Security architecture updated: 3 September 2026
What the security result proves
A successful result means a registered trusted device for that Circle member signed one exact, short-lived request after the phone completed local authentication. The server verifies the signature, device, account, Circle relationship, expiry and one-time use before showing success.
The default result is displayed as current for five minutes and cannot be configured beyond ten minutes. After that, start a new check rather than relying on the old result.
A key protected by your phone
Your trusted phone creates its own P-256 signing key. On a physical supported iPhone, it is held by Secure Enclave and Keychain. On Android, FamVerify requests StrongBox where available and otherwise uses the Android Keystore security available on that device.
- The private key is non-exportable and never sent to FamVerify.
- The server stores the corresponding public key and fingerprint.
- Face ID, Touch ID, fingerprint or passcode checks stay inside iOS or Android.
- A new phone creates a new key; a revoked key cannot silently move to somebody else.
Fresh, one-use checks
Verification challenges are random, tied to the two people, the request and one trusted device, expire within two minutes and are consumed once. A replay or a signature from the wrong device fails.
Access credentials are short-lived. Refresh tokens rotate and are stored as digests by the server; the usable refresh token is kept in this-device-only secure storage. The API rechecks that the account, session and device remain active on authenticated requests.
Circle membership is deliberate
Invitation links contain a random one-use secret and expire. The server stores a digest rather than the usable token. Claiming a link only creates a pending request; it does not establish trust.
Only the active Circle owner can create an invitation. After it is claimed, an active owner or admin must recognise the person and either approve the join with a new trusted-device signature or reject it. Rejections are audited and shown in Circle activity. Device and membership permissions are checked again when a verification response arrives.
A signed response from everyone in a Circle
Circle Check-in lets an active member ask everyone in the Circle whether they are OK or need help. The participant list is fixed when the check-in starts, and the check-in expires after one hour. Each response is signed by that person's current trusted phone using a one-time challenge, just like an identity verification.
- The person who starts the check-in must send their own signed response too.
- A person can correct their response while the check-in remains active; the replacement must carry a fresh signature.
- Removing somebody from the Circle prevents a new response, while preserving an accurate historical participant list.
- An owner or authorised admin can acknowledge that help is being handled and resolve the check-in.
- I need help is a clear safety signal, not an emergency-service alert. Circle members still decide what action to take.
Protecting data and notifications
- Production mobile and API traffic requires HTTPS.
- Push delivery tokens are encrypted before database storage.
- Action notifications may identify the requester, Circle or affected member so the recipient can recognise a verification, join decision or recovery warning.
- Notification data is limited to the event, opaque routing identifiers and the small amount of display context needed for that alert. It never contains a signing challenge, invitation token, recovery pairing details, contact details or message contents.
- On supported iPhones, verification and Circle Check-in progress can appear in privacy-aware Live Activities. Android can show an ongoing check-in notification. Tapping either returns through FamVerify’s app lock, and remote delivery remains best-effort.
- One-use secrets and session tokens are stored as digests where the server does not need the original value.
- Database constraints, object-level authorisation, parameterised queries, rate limits and append-only security events support the application controls.
- Private invitation URLs are excluded from website analytics.
Limits you should understand
- A person under pressure can still authenticate; a signature cannot prove free intent.
- A stolen unlocked phone, sufficiently privileged malware or an operating-system flaw remains a risk.
- A real Circle member can lie or make an unsafe request even though they cannot sign as somebody else.
- The service can read necessary relationship metadata and is not end-to-end encrypted.
- Live checks depend on the API and push delivery is best-effort.
- No security system is unhackable, anonymous or guaranteed to prevent fraud.
If a result conflicts with what you know, stop and contact the person another way. Never let urgency turn an identity check into automatic approval of a request.
Recovery Guardian and a lost phone
FamVerify links an identity to one trusted phone. You can nominate one person from a shared Circle as your Recovery Guardian. They must accept through their own protected trusted-phone check before the recovery relationship becomes ready.
If your phone is lost or replaced, the accepted Guardian can start recovery and give you one-time pairing details. Your replacement phone creates a new protected key and waits through a 24-hour safety window before becoming your only trusted phone. The old phone is detached; your existing Circles and subscription remain with your identity.
- A Guardian can start recovery but cannot approve identity checks as you.
- Either participant can cancel an open recovery.
- Losing the shared Circle or removing the Guardian ends that recovery relationship.
- Email, telephone access and support alone cannot bypass the trusted recovery process.
Unexpected or suspicious activity
Tell the relevant Circle members and do not approve another request while you investigate. A notification is only an alert; open FamVerify and review the current request and Circle before acting.
Contact support if you see activity you do not recognise. Support can help secure and investigate the account, but cannot bypass trusted-phone or Recovery Guardian safeguards simply because a request feels urgent.
Report a security vulnerability
Send a private report to hello@andrewtech.co.uk with the subject “FamVerify security report”. Include the affected area, steps to reproduce and likely impact. We acknowledge genuine security reports as quickly as possible and normally within two business days.
- Do not publish an unresolved issue or include secrets and private user data in a public issue.
- Do not access another person’s account, degrade the service, use social engineering or retain data you encounter.
- Use test accounts and the minimum proof needed to explain the issue.
Automated security contact information is also available at /.well-known/security.txt.
How we maintain security
FamVerify maintains a documented threat model, automated security tests, restricted production access, dependency review, retention controls and an incident-response process. We review the controls as the product and the threats around it change.
This page explains the design in plain English. It is not a claim that FamVerify is independently certified or that any system can remove every security risk.
Read the Privacy page for the current data-handling position or use the Contact page for an account concern.