Android
AuraScore 83/100

Financial App Biometric Keystore Audit Notification

Formal audit email detailing Android KeyStore cryptographic verification and biometric security sign-off for banking release.

Use this template when certifying Android Keymaster hardware-backed encryption and StrongBox compliance before a banking build release. It produces a comprehensive executive sign-off email for engineering leadership.

Template

Role: Principal Android Security Architect specializing in cryptographic hardware modules and Tier-1 banking mobile security.

Context

  • Application Name: {{app_name}}
  • Target SDK Level: {{target_api_level}}
  • Cryptographic Protocol: {{crypto_scheme}}
  • Penetration and Audit Observations: {{audit_findings}}
  • Authorizing Architect: {{lead_architect}}
  • Target Deployment Cutoff: {{release_deadline}}

Task

Draft a high-stakes engineering email to the VP of Engineering detailing the security audit evaluation of the Android KeyStore and BiometricPrompt implementations for {{app_name}}, establishing whether the build meets regulatory and hardware-backed cryptographic compliance.

Method

  1. Establish the current security posture by summarizing {{app_name}} against Android CDD hardware security requirements.
  2. Evaluate KeyGenParameterSpec configurations, specifically setUserAuthenticationRequired and setInvalidatedByBiometricEnrollment parameters under {{crypto_scheme}}.
  3. Analyze StrongBox Keymaster vs TEE isolation levels across target OEM profiles relevant to {{target_api_level}}.
  4. Correlate critical vulnerabilities identified in {{audit_findings}} with potential transaction spoofing and key leakage vectors.
  5. Classify the risks of biometric fallback mechanisms, explicitly assessing BIOMETRIC_STRONG versus device credentials.
  6. Detail mandatory remediation patches required prior to {{release_deadline}}.
  7. Provide an explicit sign-off verdict (Approved, Conditional, or Blocked) attributed to {{lead_architect}}.

Constraints

  • MUST cite specific Android KeyStore API classes and cryptographic flags.
  • MUST evaluate hardware-backed isolation (TEE/StrongBox) mechanisms explicitly.
  • MUST NOT provide ambiguous pass/fail declarations; assign a definite status.
  • Tone must remain strictly authoritative, technical, and risk-oriented.
  • Maintain an email structure with clear executive scanning anchors.

Output format

An email deliverable structured as follows:

  1. Subject Line: High-priority tagged subject referencing compliance status and {{app_name}}.
  2. Executive Verdict: Direct sign-off determination and risk rating.
  3. Cryptographic & Hardware Analysis: Structured technical breakdown of KeyStore and biometric flags.
  4. Vulnerability & Findings Table: Assessment of {{audit_findings}} with severity rankings.
  5. Required Action Items: Numbered remediation items with assigned owners ahead of {{release_deadline}}.
  6. Formal Sign-off Signature: Attributed to {{lead_architect}}.

Self-review

  • Ensure all variables ({{app_name}}, {{target_api_level}}, {{crypto_scheme}}, {{audit_findings}}, {{lead_architect}}, {{release_deadline}}) are logically integrated.
  • Verify that StrongBox and biometric enrollment invalidation are thoroughly analyzed.
  • Confirm the email length is concise yet comprehensive (under 500 words).
AuraScore breakdown
83/100Provisional
Instruction clarity15/15 · Strong

Explicit role, a named task, and discrete steps the model can follow.

Context architecture12/12 · Strong

Background, inputs and variables the model needs before it starts.

Constraint engineering12/12 · Strong

Hard boundaries — what the model must and must not do.

Output specification6/14 · Thin

A named, field-level shape for the response.

Reasoning structure10/10 · Strong

Ordered work items that force analysis before an answer.

Model compatibility10/10 · Strong

Length and structure that travel across frontier models.

Token efficiency5/10 · Thin

Signal density — instruction weight without padding.

Reusability7/7 · Strong

Documented variables so the scaffold adapts to new inputs.

Robustness5/5 · Strong

Quality bar, assumptions and behaviour when inputs are thin.

Observed performance1/5 · Thin

How much real usage the template has behind it.

developers
developers-android
financial-services
android
security
fintech