Military-Grade Cloud Vault
for Two-Factor Authentication
Self-hosted, end-to-end encrypted TOTP & HOTP authentication infrastructure. Engineered with client-side master key isolation, hardware-backed Android KeyStore, and strict APK attestation.
Zero-Knowledge Architecture
Encryption keys are derived locally on your device via PBKDF2 (100,000 iterations). The server only stores ciphertext blobs; nobody—not even server administrators—can access your OTP keys.
APK Attestation & HMAC-SHA256
All API communication is cryptographically signed using a private application key and anti-replay timestamps. Arbitrary browser requests, bots, or third-party crawlers are completely blocked from accessing your vault.
100% Offline Capability
Generates RFC 6238 TOTP and RFC 4226 HOTP codes completely offline without requiring internet access. Cloud backup is entirely optional and seamless.