Security

How Phonekit is built

Phonekit holds verification codes for other people’s accounts. This is how that is handled.

Signing in

Passkeys only. There is no password to phish, reuse or leak, and we never see one.

Add a second passkey on a second device so you always have a way in.

You also get ten single-use recovery codes when you set up your account. If you lose every device with a passkey, one of those signs you in and walks you through creating a new one.

Who can reach what

  • OrganizationsA number is held by one organization. Belonging to one organization gives you nothing in another, even with the same email address.
  • MembersSee the numbers shared with everyone, plus the ones granted to them specifically. Nothing else.
  • Owners and adminsCan open every number in their organization, including restricted ones. The number itself says so.
  • API keysRead only explicitly selected numbers in the organization. Shown once, revocable, and recorded when created or revoked.

What is recorded

Messages opened, codes copied, numbers claimed and released, access granted and removed, and API keys created and revoked. Each entry records who, what and when, in Settings → History.

A recorded copy means someone pressed Copy code. Where a code goes after that is not recorded.

Storage and email

Messages are encrypted at rest. Email notifications tell you that something arrived and where to read it. They never contain the message text or the code.

Security questions

If you need specific security commitments before you can use Phonekit, tell us when you join the interest list and we will answer directly.