Security and privacy
This page describes how BioTrack protects attendance data on the PC and in transit to the cloud. It is for IT and security staff reviewing a BioTrack installation. BioTrack does not claim any certification or compliance standard; use this page as input to your own assessment.
Encrypted local database
Section titled “Encrypted local database”- Attendance, employees and settings live in one SQLite database encrypted with SQLCipher-compatible settings and a random 256-bit key.
- The key is stored in its own file, protected with machine-scoped Windows DPAPI.
- The database, key and service folders grant access only to SYSTEM, the Administrators group and the collector service account. The signed-in Windows user has no access to the database or key.
- BitLocker is not required, and setup does not inspect or change disk encryption.
- Daily backups are encrypted with the same key. Portable backups use a separate key derived from a recovery passphrase with Argon2id. See Backup and recovery.
- Terminal credentials are encrypted with machine-scoped DPAPI before they are saved. The app only ever shows whether a password is saved, never the password itself.
Collector service identity
Section titled “Collector service identity”The BioTrack Collector runs as a Windows service named BioTrackCollector under the passwordless virtual account NT SERVICE\BioTrackCollector. It has no password to steal or rotate, and its rights are limited to the BioTrack data folder. Windows restarts it automatically if it stops unexpectedly.
The collector accepts terminal callbacks only from the terminal chosen during setup, on the listener port approved during setup. A Windows firewall rule, created with administrator approval, allows only that terminal address. The collector checks the approved address and port again before it opens the listener.
Authenticated local channel
Section titled “Authenticated local channel”The desktop window never opens the database and never receives the database key. It talks to the collector service over a local named pipe:
- The pipe has an exact access list: the Windows user who was set up for BioTrack, the collector service, SYSTEM and Administrators. The collector reads the list back and refuses to start if it does not match.
- Every request and response is authenticated with HMAC-SHA-256 using a 256-bit secret that only that user and the service can read.
- Messages older than 30 seconds are rejected, and a message cannot be replayed.
- Only validated summaries cross the channel. Raw terminal payloads never reach the window.
BioTrack accounts and sessions
Section titled “BioTrack accounts and sessions”- BioTrack has its own local accounts with two roles: administrator and operator. Settings that change the terminal, backups, cloud reporting or logs are administrator-only.
- Passwords are hashed with Argon2id.
- After four failed sign-ins for an account, each further attempt is delayed, doubling from 5 seconds up to 15 minutes.
- Sessions end after 30 minutes without activity, and after 12 hours at most.
- Changing a password requires the current password and ends that user’s sessions.
- Restoring a backup requires the administrator’s password, the backup passphrase and typing
RESTORE, and signs everyone out afterwards. - There is no master password and no cloud account recovery. See Accounts and sign-in.
Audited corrections
Section titled “Audited corrections”Attendance corrections and leave changes record who made them, when, a written reason, and the values before and after. Revoked leave keeps its revocation reason. See Calendar, leave and corrections.
Signed installer and publisher trust
Section titled “Signed installer and publisher trust”The installer, application and commissioning scripts are code-signed with a private BioTrack publisher certificate and timestamped. Before installing, verify the certificate fingerprint through a separate trusted channel from your supplier. Setup only trusts the publisher if you tick Trust the BioTrack publisher on this PC, and checks the installer signature again afterwards. The commissioning scripts refuse to run if any signature is invalid or from a different publisher. See Install BioTrack.
Cloud reporting
Section titled “Cloud reporting”Cloud reporting is optional and off until an administrator connects it.
- Each installation has its own Ed25519 signing key pair. The private key is protected by the operating system, stays inside the collector service, and is never shown by the app, placed in a support bundle or included in a portable backup.
- Every batch is sent over HTTPS with a fresh timestamp, nonce, body digest and Ed25519 signature.
- An administrator can select Rotate signing key in Settings → Cloud reporting. The new key is confirmed with the cloud before the old one is retired.
- The organisation’s cloud administrator can revoke an installation. Revocation is permanent; after it, the cloud rejects everything signed by that installation. Local collection continues.
What is never uploaded
Section titled “What is never uploaded”The upload uses a fixed allowlist of fields. BioTrack never sends terminal credentials, BioTrack passwords or password hashes, sessions, recovery passphrases, biometric templates or images, or raw terminal requests. The cloud service independently rejects unknown fields and credential or biometric field names. See Data and retention.
Support data
Section titled “Support data”The support bundle contains no employee names, raw scans, credentials or log contents. Desktop logs can contain employee names and should be shared only through approved channels. See Logs and support.
Outside the threat boundary
Section titled “Outside the threat boundary”Losing the database key file makes the database and daily backups unreadable. Keep a current portable backup and its passphrase stored separately.