Install the signed APK
Enable installation from your chosen file source, install the APK and verify its SHA-256 hash against the published checksums.
Platforms / Android
Android 7.0 (API 24) and newer are supported with a signed release APK: the same local-first vault, with hardware-backed biometric unlock and Android screen-capture protection.
The Android app is a full KalderaShield: all five record types, folders, tags, search, encrypted backups and attachments. Release builds are signed, built with R8 shrinking and verified by release-hardening scans that check for debuggable flags, backup exposure and cleartext traffic.
Biometric unlock is hardware-bound: the wrapping key lives in AndroidKeyStore as an auth-bound, non-exportable key that is invalidated when biometric enrollment changes. Unlock goes through BiometricPrompt with a CryptoObject, so the OS auth token is bound to the key's crypto operation.
Android sets FLAG_SECURE on the main activity, keeping the app out of screenshots, screen recordings and the recents preview. Import and export go through the system document picker, so every read and write location is one you explicitly chose.
Enable installation from your chosen file source, install the APK and verify its SHA-256 hash against the published checksums.
The same Argon2id parameters as desktop — 64 MiB, 4 iterations, 2 lanes — and the same 24-word BIP-39 recovery key to store safely.
Use BiometricPrompt to wrap daily access with the device's secure hardware. The master password remains the only root of the vault.
Android biometric behaviour varies across OEM builds. The public release gating therefore requires explicit device-matrix evidence (Pixel, Samsung, Xiaomi, Android 12–15) before production biometric claims are made, and this page makes none beyond what the platform contract guarantees. The Android Credential Provider passkey filling remains outside the current release boundary.
Auth-bound, non-exportable key with setUserAuthenticationRequired; invalidated automatically when biometrics are re-enrolled.
The main activity is excluded from screenshots, screen recording and the recents preview by the OS.
Import, export and download flows use the system picker bridge; the app never gains broad storage permissions.
Android 7.0 (API 24) and newer, targeted at API 35. Devices without a biometric sensor still work with the master password alone.
The AndroidKeyStore wrapping key is invalidated by design when biometric enrollment changes. You unlock with the master password and re-enroll platform unlock — vault access is never affected.
Yes. Export an encrypted .ks backup through the document picker, move it however you like, and restore it on the desktop with the master password.