Skip to content

Commit 9032c66

Browse files
authored
Update README.md
1 parent 320f50b commit 9032c66

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

README.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,20 @@ CleanSlate requires the following permissions for full functionality:
4444
CleanSlate ensures your data is securely erased and inaccessible to unauthorized users. It does not store or share user data without consent.
4545
https://cleanslate.mobi/privacy
4646

47+
## 🔒 Security Features
48+
49+
| Feature | Status |
50+
|--------|--------|
51+
| **Implement a wipe token**: Each user should generate a local-only encrypted token during setup, used to validate remote wipe requests. This token is never stored on your server. | ✅ Complete |
52+
| **Strip debug metadata before production** (`minifyEnabled true` and remove `DebugProbesKt.bin`). | ✅ Complete |
53+
| **Make remote wipe command decryptable only by the app (client-side).** | ✅ Complete |
54+
| **Show clear user onboarding before enabling Device Admin, explaining its impact.** | ✅ Complete |
55+
| **Disable Firebase Analytics and tracking features in production.** <br> _Replaced with secure WebSocket._ | ✅ Complete |
56+
| **Provide an activity log within the app to show received remote commands.** | ✅ Complete |
57+
| **Use self-hosted FCM alternatives (like ntfy.sh) or open-source push systems if needed.** <br> _Replaced with secure WebSocket._ | ✅ Complete |
58+
| **Ensure app cannot silently wipe without visible confirmation unless explicitly set by user.** | ✅ Complete |
59+
60+
4761
## Contributing
4862

4963
Contributions are welcome! Follow these steps to contribute:

0 commit comments

Comments
 (0)