🔒 Security & Code Review

Our commitment to security, transparency, and continuous improvement.

Security-First Development

TAK Can is designed for sensitive operations — military exercises, search and rescue, law enforcement, and disaster response. Security is not an afterthought; it is a core design principle applied at every layer of the application.

Code Review Process

TAK Can undergoes regular internal code reviews covering:

Latest Review Summary

DateApril 2026
Scope17 source files — communications, data layer, UI, services, Watch app
Findings22 findings identified (5 critical, 4 high, 5 medium, 8 security)
Resolved19 findings fixed, 3 deferred (low risk)
False positives4 initial findings corrected after verification

Security Measures in Place

LayerProtection
Server connectionsTLS 1.2+ with mutual certificate authentication
MultipeerConnectivity meshDTLS encryption (Apple framework)
BLE meshAES-256-GCM with pre-shared key
Data at restCore Data + log files encrypted via iOS file protection
CredentialsiOS Keychain with ThisDeviceOnly — no iCloud sync
Mesh bridgeOnly server-authenticated peers forwarded
BLE advertisingGeneric device name — callsign not exposed

Vulnerability Disclosure

If you discover a security vulnerability in TAK Can, please report it responsibly:

Detailed Review Available

The full code review report — including specific findings, proposed fixes, and verification results — is available upon request for authorized parties (government agencies, military organizations, and enterprise customers evaluating TAK Can for deployment).

To request the report, use the Support page contact form with your organization details.

Continuous Improvement

Security is an ongoing process. Each release includes:

View detailed security architecture →

← Back to Home