Security & Encryption
How Pair2FA encrypts 2FA secrets at rest (AES-256-GCM)
Pair2FA Cryptography Lead
·Updated 1 week ago
·4 min read
Deep dive into cryptographic key derivation, initialization vectors, and vault protection.
Authenticated Encryption Specification
Pair2FA utilizes AES-256-GCM (Galois/Counter Mode) authenticated encryption for all stored TOTP secret seeds.
Security Guarantee Details
- Unique Initialization Vectors (IVs): Every secret seed is encrypted with a unique 96-bit IV and 128-bit authentication tag.
- RAM-only Ephemeral Passcodes: Passcodes are calculated dynamically in server RAM and are never written to disk logs.
- Transport Layer Security: All API traffic requires TLS 1.3 with strict HSTS preloading.
Was this article helpful?
Let us know how we can improve our documentation.
RELATED ARTICLES IN THIS TOPIC
Understanding real-time audit logs & access history
Track every passcode copy, team invitation, and role change with immutable timestamps.
Read article
Why Pair2FA operates without browser extension risks
Reducing the attack surface of DOM scraping malware and malicious extension updates.
Read article
Enforcing mandatory two-factor authentication for team
Require all team members to secure their Pair2FA accounts with hardware keys or 2FA.
Read article
STILL NEED HELP?
Have questions?
Our support team is online 24/7 to help you configure 2FA for your organization.
Contact support