Zero-Trust Integrity

Enterprise Security Architecture

Cryptographic anti-tamper controls protect license entitlements and weighing data integrity.

🔒

Zero Plaintext Key Storage

License keys are salted and hashed using HMAC-SHA256 with a dedicated server pepper. Plaintext keys are shown once to the administrator and never stored or logged.

⏱

Authoritative Server UTC Clocks

Client devices cannot bypass expiration dates by rewinding local Android system clocks. Every activation and validation response is measured against UTC server time.

📱

Strict Hardware Identity Binding

Licenses are permanently tied to the device's cryptographic installation ID. Secondary activation attempts trigger immediate DEVICE_MISMATCH security alarms.

🌐

CIDR & IP Network Enforcement

Optional network rules restrict license operations to specific depot Wi-Fi subnets (e.g. 192.168.1.0/24), blocking unauthorized off-site usage.