How entries are protected

Team2FA encrypts account metadata and authenticator secrets with separate entry keys. Those keys are wrapped under organization derived keys from a deployment root key. The app retrieves a current code when an authorized user asks for it.

Trust boundary

This is managed encryption rather than end to end encryption: the application process can decrypt entries. Protect the hosting environment and root key, establish database backups and restore drills, and restrict operational access.

Make a deployment decision

A managed key service, audited key rotation, independent security assessment and availability drills are future hardening work. Review these limits before placing high value production credentials in the system.