Skip to the page
EDEN Kesef EICCIO Advisors

Security

Last updated: 11 September 2026

Three things protect your records today. They never leave the phone, the books sit behind the fingerprint, and the record itself is encrypted on the device.

One thing is still true and worth saying plainly: encryption protects the record from somebody who reaches the storage, and it cannot protect you from somebody watching you unlock it. This page says which is which, because the difference is what anybody deciding what to put in actually needs to know.

1. What protects your records today

They never leave the phone

There is no server, no account and no synchronisation service, so there is no database of merchants to break into and no password of yours to steal. The most common way records like these are lost is that somebody else was holding them. Nobody else is holding these.

Inside the application there is no code that reaches the network at all: no request, no beacon, no socket, no tracking pixel. The policy the browser enforces is default-src 'self', so the app may load its own files and nothing else, from anywhere else.

The screen at rest shows nothing

The counter shows no takings, no totals, no history and no customer names. A phone passed across a counter, glanced at over a shoulder or taken out of a hand shows a number pad. There is no way to reach the books by accident: it takes a deliberate press and hold, and it is not on a menu.

The books sit behind the fingerprint

Opening the books asks for the fingerprint the handset already carries. If the fingerprint has been set up and the sensor does not confirm, the books stay shut and say so.

One honest qualification. If nothing has ever been enrolled on the phone, there is no fingerprint to ask for, and the books open. The app does not pretend to have a lock it has not been given.

There is no export-everything button

Every export is deliberate, scoped to what it carries, dated, named for a purpose, and recorded where you can see it afterwards. A complete takings record is valuable to more people than a lender, and building the honest version of this product means building the ability not to show it.

2. What the encryption does, and what it cannot do

The record is encrypted where it sits. The key is not kept with it: it is locked with a number only you know.

This changed on 11 September 2026, and this page said the opposite until then. Before that the records were written to the phone’s storage in the clear, and anybody who could reach that storage could read who owed you money, how much, and since when. That is no longer the case. Records written before the change are re-sealed on the device the first time you set your number, so the old ones are covered too.

What it protects you from: a handset passed on or sold without being wiped, somebody who picks up the phone and knows where to look, and an examination of the device’s storage. Without the number, what is on the disk is noise.

What it cannot protect you from, and this is the part worth reading. It cannot help once the till is open in front of you, so a phone handed over unlocked is a phone with the books open. It cannot survive a number nobody remembers: that is what the recovery pieces are for, and if the number and the pieces are both gone, the record is gone with them. Nobody can unlock it for you, and that is the same property that stops anybody else unlocking it either.

One vault of the two specified is built. The second one holds anything you choose to export to a server, and it is not built because there is no server and nothing is sent to one. It gets built the day something is, rather than guessed at now.

The ordinary advice still applies and always will: put a screen lock on the phone, and do not leave the handset where somebody can pick it up unlocked.

We would rather tell you this than let you assume the fingerprint is doing more than it does.

3. Backups, and the one thing to know before you send one

A backup is compressed, not locked. Whoever receives it can read it.

The backup travels through the phone’s own sharing sheet as a compressed file. Compression is not encryption. If you send it through a messaging app, the book arrives readable, and it contains the names and the amounts. If you save it to the phone’s shared storage instead, other apps on the phone can read it there.

Send a backup to your own other phone, and nowhere else. The product carries that warning at the moment you send, not only here.

4. Splitting your key between people you trust

There is a recovery option that splits a key into pieces, so that several trusted people each hold one and a set number of them together can rebuild it. It uses the browser’s cryptographic random source and refuses to run where no such source exists, rather than quietly falling back to a weaker one.

Each piece carries how many pieces are needed and which split it belongs to, and the rebuilt key is checked against a fingerprint of the original before it is handed back. Too few pieces, or pieces from two different splits, are refused with the reason. It will not return a plausible wrong key and call it right, which is the failure that would strand somebody standing in a shop holding two pieces of paper.

Read this before you choose a split. If any two pieces can rebuild the key, then any two of those holders can rebuild it without you. That is the same property that lets them help you when your phone is gone. Choose the split, and the holders, with both directions in mind.

5. Losing the phone

If the phone is lost, stolen, reset or cleared, and no backup exists, the records are gone. Nobody can restore them, because nobody else has a copy. There is no support route that recovers them and we will not imply there is one.

Clearing the browser’s site data for edenkesef.app has the same effect as losing the phone. It is not an unlikely event: it is what happens when somebody tidies up a browser.

The app asks the browser to mark its storage as worth keeping, so it is not quietly cleared when the phone runs low on space. The browser may say yes or no. The books report which answer was given, in those terms, and never assume it was yes.

6. How the app itself is delivered

7. The camera

Camera frames are handed to the phone’s own barcode and label reader and to nothing else. They are never captured to an image, encoded, written to storage or transmitted. What is kept is the result, not the picture.

8. How we find and fix this sort of thing

Security findings are written up beside the code, with what was wrong, what changed, what is still open and who it is waiting on. Every fix carries a test that was first run against the old code and watched to pass wrongly, because a check that cannot fail is not a check.

The open items are not hidden in that file and they are not hidden on this page. Section 2 is the largest of them.

9. Telling us about a problem

If you think you have found a weakness, please tell us before telling anybody else, and give us a reasonable chance to fix it. Write to EICCIO Advisors, Lot 55, Public Road, La Grange, West Bank Demerara, Region 3, Guyana.

Please do not include real merchant records, real customer names or real phone numbers in a report. A description of the route is enough, and it avoids making the problem worse in the course of reporting it.

EDEN Kesef is owned and operated by EICCIO Advisors. EICCIO Technologies LLC is licensed to distribute it through the app stores; ownership does not pass. This page describes how the product works and is written for transparency. It is not legal advice.
Back to EDEN Kesef · Privacy · Cookies and storage · Terms of use