Help CenterSecurity & EncryptionHow Pair2FA encrypts 2FA secrets at rest (AES-256-GCM)
Security & Encryption

How Pair2FA encrypts 2FA secrets at rest (AES-256-GCM)

Pair2FA Cryptography Lead
·
Updated 1 week ago
·
4 min read
Deep dive into cryptographic key derivation, initialization vectors, and vault protection.

Authenticated Encryption Specification

Pair2FA utilizes AES-256-GCM (Galois/Counter Mode) authenticated encryption for all stored TOTP secret seeds.

Security Guarantee Details

- Unique Initialization Vectors (IVs): Every secret seed is encrypted with a unique 96-bit IV and 128-bit authentication tag. - RAM-only Ephemeral Passcodes: Passcodes are calculated dynamically in server RAM and are never written to disk logs. - Transport Layer Security: All API traffic requires TLS 1.3 with strict HSTS preloading.

Was this article helpful?

Let us know how we can improve our documentation.

STILL NEED HELP?

Have questions?

Our support team is online 24/7 to help you configure 2FA for your organization.

Contact support
PAIR2FA

Stronger teams
start here.

Share 2FA access. Save time. Stay secure.

2 min setup

Be up and running

Built for teams

Simple permissions

No long-term contracts

Cancel anytime

TRUSTED BY MODERN TEAMS