Secure shared ledgers15-day trial with 150 coinsRead-only access at zero coins
Security & privacy

Protection is part of the ledger, not an afterthought.

Tizori uses layered controls for credentials, stored ledger content, connected approvals and user privacy choices.

Argon2id passwordsEncrypted dataApproval controls
Protection layers

Concrete safeguards for the most important parts of Tizori.

Security claims below describe the current Tizori application architecture and should be kept aligned with production deployments.

Salted password hashing

Passwords are protected with Argon2id using a unique random salt. Password verification uses fixed-time comparison.

Encrypted ledger payloads

Ledger content is stored in encrypted data envelopes using AES-based encryption and keys derived for the account.

Approval before acceptance

A connected transaction does not become an accepted shared record until the other user approves it.

Encrypted transport

Production web and API traffic should use HTTPS/TLS so credentials and records are protected while travelling between device and server.

Permission minimisation

The camera is requested only when a user chooses QR scanning. Tizori does not require location or microphone access for core ledger functions.

Account deletion controls

Users can initiate deletion inside the application. A public web deletion route remains available for Google Play account-deletion requirements and support.

User-visible security

Clear states reduce silent mistakes.

Security is not only cryptography. Tizori makes the origin and status of important records visible.

  • Party identityEvery ledger is tied to a connected username or a clearly labelled private party.
  • Action ownershipUsers can see who needs to accept, reject or cancel a pending request.
  • Traceable exportsExcel reports include dates, statuses, starting balances and rejection details.

Good account hygiene

No online service can remove every risk. Protect your Tizori account by following these basics.

  1. 1Use a unique password that is not reused on another service.
  2. 2Keep your verified email accessible for account recovery.
  3. 3Review party, date, amount and narration before accepting an entry.
  4. 4Sign out of devices you no longer control and keep the operating system updated.
Report a security concern

Found something that could put users at risk?

Send a clear description to privacy@tizori.app. Do not include passwords, recovery codes or unnecessary personal data.

Contact Tizori