BeckonSign in

Security

A tool that tells you when a terminal job needs you, and lets you answer from your phone, has to be built so that a mistake or a breach on our side cannot reach your machine. This page is the plain-language version of SECURITY.md, which has the details and the tests behind each claim.

What we assume

An attacker who controls our server and database completely: reading every row, injecting messages, and serving any key they like.

What they can still do

What they cannot do

How an answer is checked, on your machine

Before typing anything the helper verifies the signature and the device, that the prompt is still waiting, that you have not already typed an answer yourself, that nobody answered it first, that the answer is fresh and not replayed, and that it names an offered option. Any failure types nothing.

Notifications

A push contains a generic line and some IDs. The message text is decrypted on your phone by the app's service worker, and only if its signature checks out. Once shown, it sits in your phone's notification history; set lock-screen previews to "never" if that matters to you. Push services (Google, Apple, Mozilla, Microsoft) learn that a push happened, when, and its size.

The helper and its installer

On the service

Known limits

Found a problem? Email security@beckoncli.com. See also the FAQ.