Security Concern: Direct Access to Unencrypted Preloaded Data in KoboCollect

Hello Community,

We have a security concern regarding how preloaded data is stored in KoboCollect.

In our workflow, data lists are downloaded to the user’s device to support pull data functionality. This means the user can potentially access the underlying files and data stored locally on the device.

Is there any recommended solution to encrypt and restrict access to locally stored KoboCollect data?

For sensitive data, use Android device encryption and strong screen locks, and avoid storing more data locally than necessary. Also check with KoboToolbox support whether app-level encryption for KoboCollect’s local files is currently supported.

@hoseinnematolahi Sorry but please ignore my earlier post. This function can only be used to verify the ed25519 digital signature prefix portion of the input string, not actually unencrypt the data itself.