← Projects

Assent Finance AI Agent & App Check Hardening

Assent Finance pairs a native iOS client with an AI agent and secure Firestore architecture. A production case study in diagnosing and resolving five connected failure modes across App Check attestation, Firebase Auth, Firestore security rules, and UIKit/SwiftUI constraints without compromising security controls.

AI, iOS, Security, Finance

iOS, SwiftUI, UIKit, Firebase App Check, Firebase Authentication, Cloud Functions, Cloud Firestore, Google Gemini, Google Cloud Platform

ai · agents

Assent Finance | AI Agent & App Check Hardening — 1

Assent Finance pairs a native iOS client with an AI agent and Firestore database for user insights, actions, budgets, recurring items, and connected accounts.

The Challenge

A multi-layered financial architecture surfaced 5 interrelated failure modes across app attestation, authentication, database rules, and native UI, leading to misleading re-login prompts and universal permission denials.

What We Fixed

  • App Check Attestation vs. Auth Separation: Isolated App Check token validation from session expiry, preventing valid user sessions from being prompted to re-login when attestation failed.
  • Gateway App Check Enforcement: Properly registered iOS App ID credentials and debug providers at the project gateway to allow verified Firestore streams.
  • Environment Placeholder Sanitization: Built a startup sanitizer that purges unexpanded build placeholders, guaranteeing clean token exchange fallbacks in development.
  • Deterministic Firestore Authorization: Replaced broad collection wildcards with explicit subcollection access rules (insights, actions, recurring, budgets, connectors).
  • Native UIKit Contract: Resolved AutoLayout constraint solver failure by constraining ASAuthorizationAppleIDButton to Apple's native 375pt maximum width specification.

Results

100% attestation reliability, zero permission false-positives, and seamless native iOS experience while keeping all enterprise security controls active.