(from the site:)
> Can I see the source code?
> Sure! Bulwark Passkey is built on top of an open source core called Virtual FIDO, which contains the USB emulation and FIDO protocol code, as well as the credential encryption and formatting. You can view the safety critical parts of the code, as well as easily decrypt and transfer your credentials out of the system.
So... it... isn't? It sounds like it isn't.
Like, maybe I'm just paranoid at this point, but regardless of how exciting this is in concept, I'm not too keen on using an (unaudited) virtual replacement for a hardware security token when I can neither audit the app I'm actually running, nor (preferably) build it from source; More generally, how would I even tell that the library in use by the app as-built is the same as the source on github?