Skip to content
CatSuite

Language

Choose whether the site follows your browser or always uses Brazilian Portuguese or English.

Get it free

Security

Security, vault and data protection

Extension isolation, PUBLIC, PROTECTED and SECRET levels, biometric vault, Ed25519 signatures, the CATSEAL2 envelope, backups and recovery.

3 min read

Isolation #

Extensions run on QuickJS inside a separate Android service, with their own process and UID. Every extension has limited environment, memory and time, plus exclusive SQLite data. Workflow analyses use another isolated service. Engine failures suspend extensions and keep the proxy’s current decisions.

Protection levels #

In build 1.5.0+102, workflows run while the app is in the foreground. Leaving pauses execution; resuming is explicit and does not automatically repeat operations with an unknown outcome.

LevelWhen leaving the foreground
PUBLICpauses and preserves confirmed progress for explicit resume
PROTECTEDpauses, saves encrypted progress and releases analysis environments
SECRETalso unloads environments and wipes controlled keys and buffers

PROTECTED and SECRET require biometrics and an explicit resume. Protection is inherited by derived results and cannot be lowered by an extension. Credential references and operational authentication headers require SECRET, and private content leaves the interface when locking.

Biometric vault #

The vault requires compatible strong biometrics, Android Keystore and a CryptoObject. The authenticated master key wraps a random key per extension or workflow. Code, settings, SQLite, logs, findings and derived results are encrypted. Enabling protection migrates existing data with a transaction and a recovery journal.

Integrity and signatures #

  • hashes covers every package resource with SHA-256.
  • The Ed25519 signature covers canonical JSON: sorted keys, preserved arrays and normalized decimal numbers; the signature itself is excluded from the signed input.
  • The manifest stores signature.algorithm, publicKey and value in Base64.
  • A valid signature proves integrity and key identity, not trust in the author. Recognizing the author is a separate decision.
  • Invalid signatures are rejected. Legacy unsigned files go to review; approving them creates a locally signed revision that keeps the unverified origin.

Password-protected files #

When exporting with a password, the CATSEAL2 envelope uses Argon2id with 64 MiB, three operations and one lane, libsodium 1.0.22 and AES-256-GCM.

PartDetail
Header48 bytes: magic, version and parameters, a 16-byte salt and a 12-byte nonce
Authenticationheader authenticated as AAD and a 16-byte tag
Contenteverything encrypted, including names and metadata
Passwordat least 12 characters, up to 1,024 UTF-8 bytes, never stored

Different parameters are rejected before key derivation. Portable data files and backups support up to 64 MiB.

Backups and recovery #

Create a backup after authenticating. It includes the package, settings, storage, complete findings, logs, traffic audit and related workflows with their histories and artifacts. Registered credentials and pairing certificates are left out.

Restoring is a confirmed, transactional replacement: extensions and workflows come back disabled, with classification and encryption preserved and new local keys. A password backup allows recovering content when the previous biometric key was invalidated. Without a backup, a lost key cannot be rebuilt.

Traffic audit #

Logs → Traffic changes shows the original message, the extension’s output and the message after manual editing. The audit keeps the last 50 records per extension, with previews of up to 4 KiB and hashes.

Responsible use #

CatSuite is designed for your own environments, learning, CTFs and explicitly authorized testing. Nothing is sent without your action, and every new capability goes through your approval.