How entries are protected
Team2FA encrypts account metadata and authenticator secrets with separate entry keys. Those keys are wrapped under organization derived keys from a deployment root key. The app retrieves a current code when an authorized user asks for it.
Trust boundary
This is managed encryption rather than end to end encryption: the application process can decrypt entries. Protect the hosting environment and root key, establish database backups and restore drills, and restrict operational access.
Make a deployment decision
A managed key service, audited key rotation, independent security assessment and availability drills are future hardening work. Review these limits before placing high value production credentials in the system.