Testnet phase optitor runs on public testnets today. Mainnet follows an independent cryptography audit. Where we are

Co-signer app · iOS & Android

Approvals no server can fake, on the phone you already carry.

The optitor co-signer app makes your phone an approver device for your organization's custody. It shows you exactly what you are approving, checks it independently, and signs with a key that never leaves the phone's secure hardware.

Illustration of the optitor co-signer app showing a policy change for review: the rule being added, a digest the phone recomputed itself, and an Approve with Face ID button.
Illustrative

Getting started

Paired in a minute. Trusted only after your admins say so.

The app is for people who approve inside an organization that runs optitor. You will need an account in your organization's console — your administrator sets that up.

  1. 01

    An admin shows a pairing QR

    In the console, under Users & Devices, an owner or admin creates a one-time pairing code for you. It expires after ten minutes and works once.

  2. 02

    You scan it in the app

    The phone creates its approval key inside secure hardware and enrolls with your organization’s deployment. No password, no typing.

  3. 03

    Your admins activate the phone

    A paired phone approves nothing until it is activated in the console — a quorum-gated step. You will see it switch to Approver active.

What it does

Sign what you see — and nothing else.

When your admin quorum needs to publish a new transaction policy, each member reviews the rules on their phone. The app recomputes the fingerprint of those exact rules itself and refuses to sign if anything differs from what the server says.

  • A key that cannot leave

    Generated in the Secure Enclave on iPhone, or in StrongBox where available on Android. It cannot be exported or backed up.

  • You, every time

    Each approval needs Face ID, Touch ID or a fingerprint. If your enrolled biometrics change, the key stops working and the phone must be paired again.

  • Independent check

    The phone rebuilds what it signs from the rules it displays, so a compromised server cannot show you one thing and get a signature for another.

  • No credentials on the phone

    Pairing uses a one-time, ten-minute code from the console. The phone never holds a password or a console session.

Today and next

Approver today, signing party after the audit.

In the current release the app is an approver device: it signs policy changes for your admin quorum. The design also lets a phone hold one share of a vault key and take part in signing as an MPC party; that mode stays switched off in production until the independent cryptography audit signs it off.

Privacy

No ads, no analytics, no tracking.

The app talks only to your organization's optitor deployment. The camera is used only to scan pairing codes. Your biometrics never leave the operating system. Read the privacy policy.

Requirements

iPhone with iOS 16+, or Android 11+.

A phone with Face ID, Touch ID or a fingerprint sensor, and an account in an organization that runs optitor. Lost your phone? Ask an admin to revoke it in the console, then pair a new one.

Rolling out approvals to your team?

We can walk your administrators through pairing, activation and the quorum setup — and show the policy review on a real phone.