Skip to main content

FIT-PI-01 — General platform interaction requirements

Minimum permissions. Input validation/sanitization. No data export via custom URL schemes unless justified. Secure browser components (no JavaScript by default, HTTPS only). Block vulnerable native methods. No local resource access from browser components. Safe object deserialization. Screen overlay protection. Third-party keyboard prevention for sensitive input. No sensitive data in notifications. Mutual auth for proximity presentations.

PropertyValue
Section5.6.1 General Requirements for Platform Interaction
Ownerplatform

Mapped Controls

ControlTitle
SID-HARD-02Input Validation and Injection Prevention
SID-HARD-08Sensitive Data UI Protection
SID-HARD-05Browser Security Controls

Source: Nordic EUDIW Certification System – Wallet Instance FitCEM PP Appendix