Security explainer

Why macOS asks for Keychain access

HNS Investments v0.1.4 added support for optional encrypted cloud-sync credentials. macOS may display a system dialog for an item named “hns-investments-companion Safe Storage.”

This is not a request for your Bob wallet password. The item is an app-specific encryption key managed by macOS for HNS Investments. It does not contain a seed phrase, private key, wallet password, or authority to sign a transaction.

What changed

Optional cloud security

Version 0.1.4 introduced secure storage support for a future or configured cloud pairing token. Earlier versions did not initialize this macOS Safe Storage feature.

What it protects

Only app credentials

Safe Storage encrypts HNS Investments device or pairing credentials on this Mac if you choose to connect cloud sync. macOS controls access to that app-specific key.

What stays separate

Your Bob wallet

HNS Investments remains read-only. Bob retains transaction signing, wallet encryption, private keys, seed phrases, and passwords. The Keychain permission does not cross that boundary.

What should I click?

Choose based on whether you use cloud sync

Not using Cloud Sync

Choose Deny. Your local portfolio, balances, domains, exports, and Bob bridge can continue working. No cloud data is uploaded merely because the dialog appeared.

Intentionally connecting Cloud Sync

Choose Allow for this session or Always Allow to avoid repeated prompts. Only do this when you opened the official signed HNS Investments app and expected to connect or use sync.

Version 0.1.4 checks Safe Storage too early, so the prompt can appear even when cloud sync is not configured or selected. That is a usability bug—not evidence that wallet secrets were requested. A follow-up app change will defer the check until secure storage is actually needed.

Safety checklist

How to recognize the expected prompt

  • The requesting app says HNS Investments.
  • The item says hns-investments-companion Safe Storage.
  • You downloaded the Developer ID signed and Apple-notarized build from the official GitHub release.
  • If the app name or Keychain item is different, choose Deny and verify the download before continuing.