All 2FA seeds are encrypted using AWS Key Management Service with AES-256-GCM before being stored in our database.
Your encryption keys are managed by AWS KMS and never exposed to our application layer.
We employ strict data retention policies and provide comprehensive data export capabilities.
Your authentication seeds are stored in geographically distributed AWS data centers with automatic backups and 99.9% uptime SLA.
Zero-Knowledge Principles: While we use server-side encryption with AWS KMS, your sensitive 2FA seeds
are immediately encrypted upon receipt and only decrypted when you request access with proper authentication.