Your 2FA secrets should not be copied to someone else's cloud.
Attomus Signet is a private, offline authenticator for security professionals and teams that want hard boundaries around authentication secrets.
No account.
No cloud sync.
No server copy.
No telemetry.
No analytics SDKs.
Signet generates TOTP and HOTP codes on your Android device. Secrets stay local, protected by Android Keystore and device security controls. Hardware-backed key storage is used where the device supports it, and access is gated by biometrics or your device credential.
Encrypted backups are local files, not a cloud recovery service. Export to an Argon2id + AES-256-GCM encrypted .attomusauth file, choose your own passphrase, and save it where you decide. Attomus cannot read it, sync it, reset it, or recover it.
Built for security-conscious users:
- TOTP and HOTP
- Standard otpauth:// QR codes
- Android Keystore protection
- Hardware-backed key status where supported
- Biometric or device credential gating
- Encrypted local backup export and import
- Secure-screen protection for app previews and screenshots
- Open source OTP core implementing RFC 4226 and RFC 6238
- No registration
- No advertising SDKs
- No Firebase or tracking SDKs
- No network requests for OTP generation, storage, export, or import
Signet is for people who do not want their authenticator to become another account, another sync service, or another third party in the trust chain.
Your codes. Your device. Your boundary.
Our Play data safety section says: no data collected, no data shared. Check it.
Offline 2FA. No account, no cloud, no telemetry. Encrypted local backups.