Security & compliance

Don't trust the binary — verify it. How Burein is built, escrowed, signed, attested, and independently reproducible — and why your regulator is going to be okay with it.

Supply chain

Every release is verifiable.

Reproducible builds

Every Burein release builds bit-for-bit identical across machines and CI runs. Customers can independently rebuild and diff.

SLSA Level 3

Every artifact carries provenance attesting the build environment, source revision, and inputs.

Cosign + sigstore

Signed releases. Public verification keys. Revocation possible.

CycloneDX SBOM

Full SBOM with every release. No surprise transitive dependencies. Zero non-vendor native deps on mobile is the target.

Source escrow + readable source

Source-code escrow with an independent agent is a standard commitment, not a contract you fight for. Your security team reads exactly what executes on your customers' devices — no opaque binary, no blind trust.

Public CI + per-customer builds

We publish our CI test results, and each bank gets its own dedicated build. You can prove the binary you ship matches the source you audited — and verify it independently.

Compliance

Regulatory posture is downstream of architecture.

Signal classes

Four privacy classes. Three of them are off until you turn them on.

Class 0

Purely computed / derived. No PII. Always on.

Class 1

Device characteristics. No direct identifiers. On by default.

Class 2

Quasi-identifiers (WebRTC IPs, ad-ID, MAC). Opt-in.

Class 3

Restricted (IMEI, MSISDN). Opt-in + matching platform permission.

Want to go deeper?

Talk to us about your fraud and integrity goals — we'll show you the signals that matter for your stack.